awesome-repositories.com
المدونة
MCP
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعخادم MCPحولكيفية ترتيب النتائجالصحافة
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
joaomatosf avatar

joaomatosf/jexboss

0
View on GitHub↗
2,512 نجوم·642 تفرعات·Python·other·14 مشاهدات

Jexboss

jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit deserialization flaws to achieve remote code execution on target servers. It functions as a suite of tools for delivering payloads and executing system commands on vulnerable remote applications.

The project includes a reverse shell orchestrator to establish and maintain persistent remote command connections from exploited targets back to a listener. It also provides post-exploitation automation for managing remote access and updating software on compromised systems.

The framework covers vulnerability assessment through network scanning across IP ranges and ports, as well as verification of deserialization flaws across various request vectors and endpoints. Its capabilities extend to remote command orchestration and the delivery of payloads via network parameters or admin consoles.

Features

  • Java Deserialization Exploits - Provides a framework to deliver specialized Java deserialization payloads to achieve remote code execution.
  • Vulnerability Scanners - Identifies vulnerable Java services across network ranges and ports to automate target discovery.
  • Active Vulnerability Scanning - Performs intrusive network probing across IP ranges and ports to identify services susceptible to deserialization exploits.
  • Deserialization Vulnerability Testing - Simulates remote code execution attacks to verify if applications properly secure their data deserialization processes.
  • Exploit Frameworks - Functions as a modular platform for scanning and exploiting Java deserialization vulnerabilities.
  • Serialized Payload Execution - Triggers unauthorized command execution by sending serialized data objects to target servers.
  • Network Vulnerability Scanning - Identifies vulnerable services across specified network ranges and ports to automate target discovery.
  • Remote Command Execution Tools - Ships a suite of utilities for delivering payloads and executing system commands on vulnerable applications.
  • Reverse Shells - Establishes a persistent network connection from the compromised target back to a listener for remote terminal access.
  • Remote Command Execution - Executes system-level instructions on a target host immediately following a successful vulnerability exploit.
  • Payload Injection Techniques - Implements techniques to inject exploit strings into network parameters and admin endpoints to bypass security filters.
  • Post-Exploitation Frameworks - Provides automation for managing remote access and updating software on compromised systems.
  • Deserialization Attacks - Testing and exploiting vulnerabilities in Java application servers.
  • Middleware Exploitation - Verification and exploitation tool for JBoss and Java deserialization.
  • Security Tools - Verification and exploitation tool for Java deserialization vulnerabilities

سجل النجوم

مخطط تاريخ النجوم لـ joaomatosf/jexbossمخطط تاريخ النجوم لـ joaomatosf/jexboss

بحث بالذكاء الاصطناعي

استكشف المزيد من المستودعات الرائعة

صف ما تحتاجه بلغة بسيطة — وسيقوم الذكاء الاصطناعي بترتيب آلاف المشاريع مفتوحة المصدر المنسقة حسب الصلة.

Start searching with AI

بدائل مفتوحة المصدر لـ Jexboss

مشاريع مفتوحة المصدر مشابهة، مرتبة حسب عدد الميزات المشتركة مع Jexboss.
  • k8gege/ladonالصورة الرمزية لـ k8gege

    k8gege/Ladon

    5,297عرض على GitHub↗

    Ladon is an internal network penetration scanner and vulnerability assessment tool designed to identify high-risk security flaws and assets across network segments. It operates as a fileless security scanner, executing its engine and modules directly in memory to avoid leaving a disk footprint on target systems. The project is distinguished by its integration as a plugin for command beacons, specifically within the Cobalt Strike framework. This allows for memory-resident network discovery and vulnerability detection. It further supports stealth operations through payload and script obfuscatio

    C#brute-forceexpexploit
    عرض على GitHub↗5,297
  • samratashok/nishangالصورة الرمزية لـ samratashok

    samratashok/nishang

    9,951عرض على GitHub↗

    Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows targets. It functions as a post-exploitation toolkit and payload generator to automate attacks and manage remote targets. The project provides specialized capabilities for bypassing security controls, such as disabling the Antimalware Scan Interface and employing in-memory execution to avoid disk-based detection. It includes a variety of stealthy command and control mechanisms, utilizing non-standard channels like DNS TXT records, ICMP traffic, and webmail for communication a

    PowerShellactivedirectoryhackinginfosec
    عرض على GitHub↗9,951
  • rapid7/metasploit-frameworkالصورة الرمزية لـ rapid7

    rapid7/metasploit-framework

    38,415عرض على GitHub↗

    The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures. The platform distinguishes itself through a modular architecture that supports reflective payload injection, allowing for the execution of code directly in memory without writing to disk. It utilizes an asynchronous event loop to

    Rubyhacktoberfest
    عرض على GitHub↗38,415
  • frohoff/ysoserialالصورة الرمزية لـ frohoff

    frohoff/ysoserial

    8,750عرض على GitHub↗

    ysoserial is a security research tool and payload generator designed to identify and exploit insecure Java deserialization. It functions as a framework for creating malicious serialized objects that can trigger remote code execution on Java virtual machines. The project provides a library of known gadget chains, which are sequences of vulnerable class calls that achieve arbitrary command execution during the deserialization process. It automates the generation of these payloads by leveraging common third-party libraries. The tool covers capabilities for security penetration testing, Java app

    Javadeserializationexploitgadget
    عرض على GitHub↗8,750
عرض جميع البدائل الـ 30 لـ Jexboss→

الأسئلة الشائعة

ما هي وظيفة joaomatosf/jexboss؟

jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit deserialization flaws to achieve remote code execution on target servers. It functions as a suite of tools for delivering payloads and executing system commands on vulnerable remote applications.

ما هي الميزات الرئيسية لـ joaomatosf/jexboss؟

الميزات الرئيسية لـ joaomatosf/jexboss هي: Java Deserialization Exploits, Vulnerability Scanners, Active Vulnerability Scanning, Deserialization Vulnerability Testing, Exploit Frameworks, Serialized Payload Execution, Network Vulnerability Scanning, Remote Command Execution Tools.

ما هي البدائل مفتوحة المصدر لـ joaomatosf/jexboss؟

تشمل البدائل مفتوحة المصدر لـ joaomatosf/jexboss: k8gege/ladon — Ladon is an internal network penetration scanner and vulnerability assessment tool designed to identify high-risk… samratashok/nishang — Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows… rapid7/metasploit-framework — The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of… frohoff/ysoserial — ysoserial is a security research tool and payload generator designed to identify and exploit insecure Java… pentestmonkey/php-reverse-shell — This project consists of PHP-based payloads and scripts designed to establish reverse network connections for remote… reverse-shell/routersploit — RouterSploit is an embedded device exploitation framework and vulnerability scanner designed to identify and exploit…