Stars
An Open Source Java Decompiler Gui for Procyon
General data-binding package for Jackson: works on streaming API (core) implementation(s)
JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)
jSQL Injection is a Java application for automatic SQL database injection.
a webshell resides in the memory of java web server
Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.
Create a TCP circuit through validly formed HTTP requests
Spring Boot Actuator (jolokia) XXE/RCE
QAQ Just study unserialize vulnerabilities in Java :)
wh1t3p1g / ysoserial
Forked from frohoff/ysoserialforked from frohoff/ysoserial and added my own payloads.
PortSwigger / wsdler
Forked from NetSPI/WsdlerWSDL Parser extension for Burp