awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoAcerca deCómo clasificamosPrensaServidor MCP
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
frohoff avatar

frohoff/ysoserial

0
View on GitHub↗
8,750 estrellas·1,852 forks·Java·mit·8 vistasfrohoff.github.io/appseccali-marshalling-pickles↗

Ysoserial

ysoserial is a security research tool and payload generator designed to identify and exploit insecure Java deserialization. It functions as a framework for creating malicious serialized objects that can trigger remote code execution on Java virtual machines.

The project provides a library of known gadget chains, which are sequences of vulnerable class calls that achieve arbitrary command execution during the deserialization process. It automates the generation of these payloads by leveraging common third-party libraries.

The tool covers capabilities for security penetration testing, Java application hardening, and remote code execution research. This includes the ability to generate serialized bytestreams and compose gadget chains to verify if an application's object input validation is correctly implemented.

Features

  • Deserialization Vulnerability Testing - Creates malicious serialized objects to test if a Java application is vulnerable to remote code execution.
  • Payload Generators - A tool for creating malicious serialized objects that trigger remote code execution via gadget chains in Java applications.
  • Malicious Bytestream Generation - Produces binary data representations of object graphs that trigger specific logic when reconstructed by a target JVM.
  • Java Security Research Frameworks - Provides a framework for testing Java applications against deserialization vulnerabilities by automating payload generation.
  • Remote Command Execution Tools - Generates deserialization gadget chains from common libraries to execute remote commands on target systems.
  • Penetration Testing Suites - Generates gadget chains to identify and exploit insecure deserialization flaws during security audits.
  • Gadget Chainers - Identifies and links sequences of existing library method calls to achieve arbitrary code execution.
  • Deserialization Gadget Libraries - Provides a collection of known vulnerable class sequences used to achieve arbitrary code execution during object deserialization.
  • Remote Command Execution - Leverages insecure deserialization to execute system commands on remote Java virtual machines.
  • Application Logic Hardening - Helps verify that object input validation and filtering are correctly implemented to prevent command execution.
  • Remote Code Execution Research - Studies how common Java libraries can be chained together to trigger unintended behavior on a target system.
  • Payload Creation Tools - Provides predefined sequences of method calls for known vulnerable libraries to automate exploit chain creation.
  • Reflection-Based Unmarshallers - Uses Java reflection to instantiate and populate classes dynamically without requiring target source code.
  • Deserialization Attacks - Generating payloads for unsafe Java object deserialization.
  • Deserialization Exploits - Tool for generating Java deserialization payloads.
  • Deserialization Tools - Original Java deserialization exploitation tool.
  • Insecure Deserialization - Generates payloads for exploiting unsafe Java deserialization.
  • Web Exploitation - Generates payloads for Java deserialization attacks.

Historial de estrellas

Gráfico del historial de estrellas de frohoff/ysoserialGráfico del historial de estrellas de frohoff/ysoserial

Búsqueda con IA

Explora más repositorios increíbles

Describe lo que necesitas en lenguaje sencillo: la IA clasifica miles de proyectos open-source curados por relevancia.

Start searching with AI

Preguntas frecuentes

¿Qué hace frohoff/ysoserial?

ysoserial is a security research tool and payload generator designed to identify and exploit insecure Java deserialization. It functions as a framework for creating malicious serialized objects that can trigger remote code execution on Java virtual machines.

¿Cuáles son las características principales de frohoff/ysoserial?

Las características principales de frohoff/ysoserial son: Deserialization Vulnerability Testing, Payload Generators, Malicious Bytestream Generation, Java Security Research Frameworks, Remote Command Execution Tools, Penetration Testing Suites, Gadget Chainers, Deserialization Gadget Libraries.

¿Qué alternativas de código abierto existen para frohoff/ysoserial?

Las alternativas de código abierto para frohoff/ysoserial incluyen: mbechler/marshalsec — Marshalsec is a toolkit designed for generating malicious serialized Java objects to achieve remote code execution… ambionics/phpggc — phpggc is a security assessment utility and command-line tool designed for the automated generation, obfuscation, and… pwntester/ysoserial.net — ysoserial.net is a payload generator for .NET deserialization, designed to create malicious serialized objects and… joaomatosf/jexboss — jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit… empireproject/empire — Empire is a command and control framework and post-exploitation toolkit used for network penetration testing. It… pentestmonkey/php-reverse-shell — This project consists of PHP-based payloads and scripts designed to establish reverse network connections for remote…

Alternativas open-source a Ysoserial

Proyectos open-source similares, clasificados según cuántas características comparten con Ysoserial.
  • mbechler/marshalsecAvatar de mbechler

    mbechler/marshalsec

    3,691Ver en GitHub↗

    Marshalsec is a toolkit designed for generating malicious serialized Java objects to achieve remote code execution during the unmarshalling process. It functions as a Java deserialization exploit tool and a framework for triggering Java Naming and Directory Interface lookups to remote servers. The project provides a JNDI redirector service that intercepts lookups and points targets toward a remote codebase. It includes utilities for crafting payloads that force Java applications to download and execute arbitrary classes from a remote URL. The toolset covers security analysis activities inclu

    Java
    Ver en GitHub↗3,691
  • ambionics/phpggcAvatar de ambionics

    ambionics/phpggc

    3,832Ver en GitHub↗

    phpggc is a security assessment utility and command-line tool designed for the automated generation, obfuscation, and wrapping of serialized object chains. It functions as a gadget chain framework used to identify and verify remote code execution vectors by testing for PHP object injection vulnerabilities. The project provides a modular system for constructing complex serialized object sequences and includes a dedicated payload obfuscator to transform byte streams for bypassing web application firewalls and security filters. It also features a generator for wrapping serialized data into archi

    PHP
    Ver en GitHub↗3,832
  • pwntester/ysoserial.netAvatar de pwntester

    pwntester/ysoserial.net

    3,735Ver en GitHub↗

    ysoserial.net is a payload generator for .NET deserialization, designed to create malicious serialized objects and structured gadget chains. It serves as a tool for generating command execution strings and security testing suites used to assess vulnerabilities in .NET formatters. The tool enables the creation of sequences of object calls that trigger remote code execution during the reconstruction of serialized data. It produces specialized payloads for executing system commands, loading remote libraries, and accessing local file systems. The project includes capabilities for optimizing payl

    C#
    Ver en GitHub↗3,735
  • joaomatosf/jexbossAvatar de joaomatosf

    joaomatosf/jexboss

    2,512Ver en GitHub↗

    jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit deserialization flaws to achieve remote code execution on target servers. It functions as a suite of tools for delivering payloads and executing system commands on vulnerable remote applications. The project includes a reverse shell orchestrator to establish and maintain persistent remote command connections from exploited targets back to a listener. It also provides post-exploitation automation for managing remote access and updating software on compromised systems. The fra

    Pythondeserializationexploitexploiting-vulnerabilities
    Ver en GitHub↗2,512
  • Ver las 30 alternativas a Ysoserial→