├── BappDescription.html ├── BappManifest.bmf ├── Payload Generator.png ├── README.md ├── complex command.png ├── inline complex command.png ├── inline-command.png ├── replace with generated.png └── ysoserial ├── .DS_Store ├── .gitignore ├── .travis.yml ├── DISCLAIMER.txt ├── LICENSE.txt ├── README.md ├── pom.xml ├── src ├── burp │ └── BurpExtender.java ├── com │ └── josh │ │ ├── ActionJackson.java │ │ ├── MainMan.java │ │ └── ysoserialFrame.java └── ysoserial │ ├── Deserialize.java │ ├── ExecBlockingSecurityManager.java │ ├── GeneratePayload.java │ ├── RMIRegistryExploit.java │ └── payloads │ ├── CommonsCollections1.java │ ├── CommonsCollections2.java │ ├── Groovy1.java │ ├── ObjectPayload.java │ ├── Spring1.java │ ├── annotation │ └── Dependencies.java │ └── util │ ├── ClassFiles.java │ ├── Gadgets.java │ ├── PayloadRunner.java │ ├── Reflections.java │ └── Serializables.java └── ysoserial.png /BappDescription.html: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/BappDescription.html -------------------------------------------------------------------------------- /BappManifest.bmf: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/BappManifest.bmf -------------------------------------------------------------------------------- /Payload Generator.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/Payload Generator.png -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/README.md -------------------------------------------------------------------------------- /complex command.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/complex command.png -------------------------------------------------------------------------------- /inline complex command.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/inline complex command.png -------------------------------------------------------------------------------- /inline-command.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/inline-command.png -------------------------------------------------------------------------------- /replace with generated.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/replace with generated.png -------------------------------------------------------------------------------- /ysoserial/.DS_Store: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/.DS_Store -------------------------------------------------------------------------------- /ysoserial/.gitignore: -------------------------------------------------------------------------------- 1 | /target 2 | .classpath 3 | .project 4 | .settings/ 5 | pwntest 6 | /bin/ 7 | -------------------------------------------------------------------------------- /ysoserial/.travis.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/.travis.yml -------------------------------------------------------------------------------- /ysoserial/DISCLAIMER.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/DISCLAIMER.txt -------------------------------------------------------------------------------- /ysoserial/LICENSE.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/LICENSE.txt -------------------------------------------------------------------------------- /ysoserial/README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/README.md -------------------------------------------------------------------------------- /ysoserial/pom.xml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/pom.xml -------------------------------------------------------------------------------- /ysoserial/src/burp/BurpExtender.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/burp/BurpExtender.java -------------------------------------------------------------------------------- /ysoserial/src/com/josh/ActionJackson.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/com/josh/ActionJackson.java -------------------------------------------------------------------------------- /ysoserial/src/com/josh/MainMan.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/com/josh/MainMan.java -------------------------------------------------------------------------------- /ysoserial/src/com/josh/ysoserialFrame.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/com/josh/ysoserialFrame.java -------------------------------------------------------------------------------- /ysoserial/src/ysoserial/Deserialize.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/ysoserial/Deserialize.java -------------------------------------------------------------------------------- /ysoserial/src/ysoserial/ExecBlockingSecurityManager.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/ysoserial/ExecBlockingSecurityManager.java -------------------------------------------------------------------------------- /ysoserial/src/ysoserial/GeneratePayload.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/ysoserial/GeneratePayload.java -------------------------------------------------------------------------------- /ysoserial/src/ysoserial/RMIRegistryExploit.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/ysoserial/RMIRegistryExploit.java -------------------------------------------------------------------------------- /ysoserial/src/ysoserial/payloads/CommonsCollections1.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/ysoserial/payloads/CommonsCollections1.java -------------------------------------------------------------------------------- /ysoserial/src/ysoserial/payloads/CommonsCollections2.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/ysoserial/payloads/CommonsCollections2.java -------------------------------------------------------------------------------- /ysoserial/src/ysoserial/payloads/Groovy1.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/ysoserial/payloads/Groovy1.java -------------------------------------------------------------------------------- /ysoserial/src/ysoserial/payloads/ObjectPayload.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/ysoserial/payloads/ObjectPayload.java -------------------------------------------------------------------------------- /ysoserial/src/ysoserial/payloads/Spring1.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/ysoserial/payloads/Spring1.java -------------------------------------------------------------------------------- /ysoserial/src/ysoserial/payloads/annotation/Dependencies.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/ysoserial/payloads/annotation/Dependencies.java -------------------------------------------------------------------------------- /ysoserial/src/ysoserial/payloads/util/ClassFiles.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/ysoserial/payloads/util/ClassFiles.java -------------------------------------------------------------------------------- /ysoserial/src/ysoserial/payloads/util/Gadgets.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/ysoserial/payloads/util/Gadgets.java -------------------------------------------------------------------------------- /ysoserial/src/ysoserial/payloads/util/PayloadRunner.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/ysoserial/payloads/util/PayloadRunner.java -------------------------------------------------------------------------------- /ysoserial/src/ysoserial/payloads/util/Reflections.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/ysoserial/payloads/util/Reflections.java -------------------------------------------------------------------------------- /ysoserial/src/ysoserial/payloads/util/Serializables.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/src/ysoserial/payloads/util/Serializables.java -------------------------------------------------------------------------------- /ysoserial/ysoserial.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PortSwigger/java-serialized-payloads/HEAD/ysoserial/ysoserial.png --------------------------------------------------------------------------------