awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
frohoff avatar

frohoff/ysoserial

0
View on GitHub↗
8,750 星标·1,852 分支·Java·mit·9 次浏览frohoff.github.io/appseccali-marshalling-pickles↗

Ysoserial

ysoserial is a security research tool and payload generator designed to identify and exploit insecure Java deserialization. It functions as a framework for creating malicious serialized objects that can trigger remote code execution on Java virtual machines.

The project provides a library of known gadget chains, which are sequences of vulnerable class calls that achieve arbitrary command execution during the deserialization process. It automates the generation of these payloads by leveraging common third-party libraries.

The tool covers capabilities for security penetration testing, Java application hardening, and remote code execution research. This includes the ability to generate serialized bytestreams and compose gadget chains to verify if an application's object input validation is correctly implemented.

Features

  • Deserialization Vulnerability Testing - Creates malicious serialized objects to test if a Java application is vulnerable to remote code execution.
  • Payload Generators - A tool for creating malicious serialized objects that trigger remote code execution via gadget chains in Java applications.
  • Malicious Bytestream Generation - Produces binary data representations of object graphs that trigger specific logic when reconstructed by a target JVM.
  • Java Security Research Frameworks - Provides a framework for testing Java applications against deserialization vulnerabilities by automating payload generation.
  • Remote Command Execution Tools - Generates deserialization gadget chains from common libraries to execute remote commands on target systems.
  • Penetration Testing Suites - Generates gadget chains to identify and exploit insecure deserialization flaws during security audits.
  • Gadget Chainers - Identifies and links sequences of existing library method calls to achieve arbitrary code execution.
  • Deserialization Gadget Libraries - Provides a collection of known vulnerable class sequences used to achieve arbitrary code execution during object deserialization.
  • Remote Command Execution - Leverages insecure deserialization to execute system commands on remote Java virtual machines.
  • Application Logic Hardening - Helps verify that object input validation and filtering are correctly implemented to prevent command execution.
  • Remote Code Execution Research - Studies how common Java libraries can be chained together to trigger unintended behavior on a target system.
  • Payload Creation Tools - Provides predefined sequences of method calls for known vulnerable libraries to automate exploit chain creation.
  • Reflection-Based Unmarshallers - Uses Java reflection to instantiate and populate classes dynamically without requiring target source code.
  • Deserialization Attacks - Generating payloads for unsafe Java object deserialization.
  • Deserialization Exploits - Tool for generating Java deserialization payloads.
  • Deserialization Tools - Original Java deserialization exploitation tool.
  • Insecure Deserialization - Generates payloads for exploiting unsafe Java deserialization.
  • Web Exploitation - Generates payloads for Java deserialization attacks.

Star 历史

frohoff/ysoserial 的 Star 历史图表frohoff/ysoserial 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

Ysoserial 的开源替代方案

相似的开源项目,按与 Ysoserial 的功能重合度排序。
  • mbechler/marshalsecmbechler 的头像

    mbechler/marshalsec

    3,691在 GitHub 上查看↗

    Marshalsec is a toolkit designed for generating malicious serialized Java objects to achieve remote code execution during the unmarshalling process. It functions as a Java deserialization exploit tool and a framework for triggering Java Naming and Directory Interface lookups to remote servers. The project provides a JNDI redirector service that intercepts lookups and points targets toward a remote codebase. It includes utilities for crafting payloads that force Java applications to download and execute arbitrary classes from a remote URL. The toolset covers security analysis activities inclu

    Java
    在 GitHub 上查看↗3,691
  • ambionics/phpggcambionics 的头像

    ambionics/phpggc

    3,832在 GitHub 上查看↗

    phpggc is a security assessment utility and command-line tool designed for the automated generation, obfuscation, and wrapping of serialized object chains. It functions as a gadget chain framework used to identify and verify remote code execution vectors by testing for PHP object injection vulnerabilities. The project provides a modular system for constructing complex serialized object sequences and includes a dedicated payload obfuscator to transform byte streams for bypassing web application firewalls and security filters. It also features a generator for wrapping serialized data into archi

    PHP
    在 GitHub 上查看↗3,832
  • pwntester/ysoserial.netpwntester 的头像

    pwntester/ysoserial.net

    3,735在 GitHub 上查看↗

    ysoserial.net is a payload generator for .NET deserialization, designed to create malicious serialized objects and structured gadget chains. It serves as a tool for generating command execution strings and security testing suites used to assess vulnerabilities in .NET formatters. The tool enables the creation of sequences of object calls that trigger remote code execution during the reconstruction of serialized data. It produces specialized payloads for executing system commands, loading remote libraries, and accessing local file systems. The project includes capabilities for optimizing payl

    C#
    在 GitHub 上查看↗3,735
  • joaomatosf/jexbossjoaomatosf 的头像

    joaomatosf/jexboss

    2,512在 GitHub 上查看↗

    jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit deserialization flaws to achieve remote code execution on target servers. It functions as a suite of tools for delivering payloads and executing system commands on vulnerable remote applications. The project includes a reverse shell orchestrator to establish and maintain persistent remote command connections from exploited targets back to a listener. It also provides post-exploitation automation for managing remote access and updating software on compromised systems. The fra

    Pythondeserializationexploitexploiting-vulnerabilities
    在 GitHub 上查看↗2,512
查看 Ysoserial 的所有 30 个替代方案→

常见问题解答

frohoff/ysoserial 是做什么的?

ysoserial is a security research tool and payload generator designed to identify and exploit insecure Java deserialization. It functions as a framework for creating malicious serialized objects that can trigger remote code execution on Java virtual machines.

frohoff/ysoserial 的主要功能有哪些?

frohoff/ysoserial 的主要功能包括:Deserialization Vulnerability Testing, Payload Generators, Malicious Bytestream Generation, Java Security Research Frameworks, Remote Command Execution Tools, Penetration Testing Suites, Gadget Chainers, Deserialization Gadget Libraries。

frohoff/ysoserial 有哪些开源替代品?

frohoff/ysoserial 的开源替代品包括: mbechler/marshalsec — Marshalsec is a toolkit designed for generating malicious serialized Java objects to achieve remote code execution… ambionics/phpggc — phpggc is a security assessment utility and command-line tool designed for the automated generation, obfuscation, and… pwntester/ysoserial.net — ysoserial.net is a payload generator for .NET deserialization, designed to create malicious serialized objects and… joaomatosf/jexboss — jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit… empireproject/empire — Empire is a command and control framework and post-exploitation toolkit used for network penetration testing. It… pentestmonkey/php-reverse-shell — This project consists of PHP-based payloads and scripts designed to establish reverse network connections for remote…