ysoserial.net is a payload generator for .NET deserialization, designed to create malicious serialized objects and structured gadget chains. It serves as a tool for generating command execution strings and security testing suites used to assess vulnerabilities in .NET formatters. The tool enables the creation of sequences of object calls that trigger remote code execution during the reconstruction of serialized data. It produces specialized payloads for executing system commands, loading remote libraries, and accessing local file systems. The project includes capabilities for optimizing payl
All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities
W13scan is an automated vulnerability assessment tool designed to identify security flaws in web applications through a modular plugin architecture. It functions as a scanning engine that executes specialized security logic against web endpoints to detect injection flaws, information leaks, and configuration errors. The platform distinguishes itself by combining active probing with passive traffic analysis and out-of-band detection. It utilizes a callback-based service to verify blind vulnerabilities that do not provide immediate feedback, and it operates as a proxy to intercept and inspect l
Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.
Les fonctionnalités principales de bishopfox/gadgetprobe sont : Security Utilities, Deserialization Vulnerabilities, Insecure Deserialization, Web Application Scanning.
Les alternatives open-source à bishopfox/gadgetprobe incluent : federicodotta/java-deserialization-scanner — All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities. pwntester/ysoserial.net — ysoserial.net is a payload generator for .NET deserialization, designed to create malicious serialized objects and… w-digital-scanner/w13scan — W13scan is an automated vulnerability assessment tool designed to identify security flaws in web applications through… allyomalley/dnsobserver. asciimoo/wuzz — Wuzz is an interactive command line HTTP client and request inspector designed for capturing, reviewing, and analyzing… arturss7/tuktuk.