awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to y4er/ysoserial

Open-source alternatives to Ysoserial

20 open-source projects similar to y4er/ysoserial, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Ysoserial alternative.

  • mbechler/marshalsecmbechler 的头像

    mbechler/marshalsec

    3,691在 GitHub 上查看↗

    Marshalsec is a toolkit designed for generating malicious serialized Java objects to achieve remote code execution during the unmarshalling process. It functions as a Java deserialization exploit tool and a framework for triggering Java Naming and Directory Interface lookups to remote servers. The project provides a JNDI redirector service that intercepts lookups and points targets toward a remote codebase. It includes utilities for crafting payloads that force Java applications to download and execute arbitrary classes from a remote URL. The toolset covers security analysis activities inclu

    Java
    在 GitHub 上查看↗3,691
  • wh1t3p1g/ysomapwh1t3p1g 的头像

    wh1t3p1g/ysomap

    1,240在 GitHub 上查看↗

    A helpful Java Deserialization exploit framework.

    Javaexploitation-frameworkjava-deserialization
    在 GitHub 上查看↗1,240
  • frohoff/ysoserialfrohoff 的头像

    frohoff/ysoserial

    8,750在 GitHub 上查看↗

    ysoserial is a security research tool and payload generator designed to identify and exploit insecure Java deserialization. It functions as a framework for creating malicious serialized objects that can trigger remote code execution on Java virtual machines. The project provides a library of known gadget chains, which are sequences of vulnerable class calls that achieve arbitrary command execution during the deserialization process. It automates the generation of these payloads by leveraging common third-party libraries. The tool covers capabilities for security penetration testing, Java app

    Javadeserializationexploitgadget
    在 GitHub 上查看↗8,750
  • qi4l/jysoqi4L 的头像

    qi4L/JYso

    1,752在 GitHub 上查看↗

    JNDIExploit or a ysoserial.

    Javaattackgadgetjava
    在 GitHub 上查看↗1,752

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Find more with AI search
  • ar3h/utf8-overlong-agentA

    Ar3h/utf8-overlong-agent

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • deepingh0st/ysoserialD

    DeEpinGh0st/ysoserial

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • exp1orer/jndi-inject-exploitE

    exp1orer/JNDI-Inject-Exploit

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • java-chains/web-chainsJ

    Java-Chains/web-chains

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • phith0n/zkarP

    phith0n/zkar

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • rebeyond/jndinjectorR

    rebeyond/JNDInjector

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • vulhub/java-chainsV

    vulhub/java-chains

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • vulhub/jndiexploitV

    vulhub/JNDIExploit

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • welk1n/jndi-injection-exploitwelk1n 的头像

    welk1n/JNDI-Injection-Exploit

    2,814在 GitHub 上查看↗

    JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)

    Java
    在 GitHub 上查看↗2,814
  • whitehsbg/jndiexploitW

    WhiteHSBG/JNDIExploit

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • whoopsunix/pppysoW

    Whoopsunix/PPPYSO

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • 0ofo/deswing0

    0ofo/Deswing

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • 4ra1n/mysql-fake-server4

    4ra1n/mysql-fake-server

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • a-d-team/attackrmiA

    A-D-Team/attackRmi

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • ambionics/phpggcambionics 的头像

    ambionics/phpggc

    3,832在 GitHub 上查看↗

    phpggc is a security assessment utility and command-line tool designed for the automated generation, obfuscation, and wrapping of serialized object chains. It functions as a gadget chain framework used to identify and verify remote code execution vectors by testing for PHP object injection vulnerabilities. The project provides a modular system for constructing complex serialized object sequences and includes a dedicated payload obfuscator to transform byte streams for bypassing web application firewalls and security filters. It also features a generator for wrapping serialized data into archi

    PHP
    在 GitHub 上查看↗3,832
  • yaklang/yakityaklang 的头像

    yaklang/yakit

    7,386在 GitHub 上查看↗

    Yakit is a comprehensive cybersecurity all-in-one platform designed for security assessments. It integrates a suite of core tools including an HTTP interception proxy for real-time traffic modification, an out-of-band interaction detector for verifying remote command execution via TCP, DNSLog, and ICMP, and a reverse shell manager for controlling remote server connections. The platform is distinguished by its dedicated security scripting environment, which allows for the development and execution of custom logic and plugins using a specialized high-performance language. It further extends fun

    TypeScriptblueteamburpsuiteexploit
    在 GitHub 上查看↗7,386