Highlights
Stars
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
Java 1-21 Parser and Abstract Syntax Tree for Java with advanced analysis functionalities.
A byte code analyzer for finding deserialization gadget chains in Java applications
T.J. Watson Libraries for Analysis, with front ends for Java, Android, and JavaScript, and many common static program analyses.
Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans
Proof of concept exploit, showing how to do bytecode injection through untrusted deserialization with Spring Framework 4.2.4
Code samples for the book "JavaParser: Visited" https://leanpub.com/javaparservisited