├── .gitignore ├── BappDescription.html ├── BappManifest.bmf ├── JavaDeserializationScanner.png ├── README.md ├── pom.xml ├── src └── main │ └── java │ └── burp │ ├── BurpExtender.java │ └── CustomScanIssue.java └── test ├── sampleCommonsBeanutils.war ├── sampleCommonsCollections3.war ├── sampleCommonsCollections4.war ├── sampleHibernate5.war ├── sampleJSON.war ├── sampleJavassitWeld.war ├── sampleJbossInterceptos.war ├── sampleMozillaRhino.war ├── sampleRome.war ├── sampleSpring.war ├── sampleVaadin.war └── sampleWithoutVulnerableLibraries.war /.gitignore: -------------------------------------------------------------------------------- 1 | target/ 2 | -------------------------------------------------------------------------------- /BappDescription.html: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/BappDescription.html -------------------------------------------------------------------------------- /BappManifest.bmf: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/BappManifest.bmf -------------------------------------------------------------------------------- /JavaDeserializationScanner.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/JavaDeserializationScanner.png -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/README.md -------------------------------------------------------------------------------- /pom.xml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/pom.xml -------------------------------------------------------------------------------- /src/main/java/burp/BurpExtender.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/src/main/java/burp/BurpExtender.java -------------------------------------------------------------------------------- /src/main/java/burp/CustomScanIssue.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/src/main/java/burp/CustomScanIssue.java -------------------------------------------------------------------------------- /test/sampleCommonsBeanutils.war: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/test/sampleCommonsBeanutils.war -------------------------------------------------------------------------------- /test/sampleCommonsCollections3.war: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/test/sampleCommonsCollections3.war -------------------------------------------------------------------------------- /test/sampleCommonsCollections4.war: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/test/sampleCommonsCollections4.war -------------------------------------------------------------------------------- /test/sampleHibernate5.war: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/test/sampleHibernate5.war -------------------------------------------------------------------------------- /test/sampleJSON.war: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/test/sampleJSON.war -------------------------------------------------------------------------------- /test/sampleJavassitWeld.war: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/test/sampleJavassitWeld.war -------------------------------------------------------------------------------- /test/sampleJbossInterceptos.war: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/test/sampleJbossInterceptos.war -------------------------------------------------------------------------------- /test/sampleMozillaRhino.war: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/test/sampleMozillaRhino.war -------------------------------------------------------------------------------- /test/sampleRome.war: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/test/sampleRome.war -------------------------------------------------------------------------------- /test/sampleSpring.war: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/test/sampleSpring.war -------------------------------------------------------------------------------- /test/sampleVaadin.war: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/test/sampleVaadin.war -------------------------------------------------------------------------------- /test/sampleWithoutVulnerableLibraries.war: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-deserialization-scanner/HEAD/test/sampleWithoutVulnerableLibraries.war --------------------------------------------------------------------------------