├── .gitignore ├── DISCLAIMER.txt ├── LICENSE.txt ├── README.md ├── jbossexample.png ├── pom.xml └── src └── main └── java ├── jbossexploit ├── Cli.java ├── HttpFileServer.java ├── Main.java ├── Msfvenom.java └── Stager.java └── ysoserial ├── Deserialize.java ├── ExecBlockingSecurityManager.java ├── GeneratePayload.java └── payloads ├── CommonsCollections1.java ├── CommonsCollections2.java ├── Groovy1.java ├── ObjectPayload.java ├── Spring1.java ├── annotation └── Dependencies.java └── util ├── ClassFiles.java ├── Gadgets.java ├── PayloadRunner.java ├── Reflections.java └── Serializables.java /.gitignore: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/.gitignore -------------------------------------------------------------------------------- /DISCLAIMER.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/DISCLAIMER.txt -------------------------------------------------------------------------------- /LICENSE.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/LICENSE.txt -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/README.md -------------------------------------------------------------------------------- /jbossexample.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/jbossexample.png -------------------------------------------------------------------------------- /pom.xml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/pom.xml -------------------------------------------------------------------------------- /src/main/java/jbossexploit/Cli.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/jbossexploit/Cli.java -------------------------------------------------------------------------------- /src/main/java/jbossexploit/HttpFileServer.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/jbossexploit/HttpFileServer.java -------------------------------------------------------------------------------- /src/main/java/jbossexploit/Main.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/jbossexploit/Main.java -------------------------------------------------------------------------------- /src/main/java/jbossexploit/Msfvenom.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/jbossexploit/Msfvenom.java -------------------------------------------------------------------------------- /src/main/java/jbossexploit/Stager.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/jbossexploit/Stager.java -------------------------------------------------------------------------------- /src/main/java/ysoserial/Deserialize.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/ysoserial/Deserialize.java -------------------------------------------------------------------------------- /src/main/java/ysoserial/ExecBlockingSecurityManager.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/ysoserial/ExecBlockingSecurityManager.java -------------------------------------------------------------------------------- /src/main/java/ysoserial/GeneratePayload.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/ysoserial/GeneratePayload.java -------------------------------------------------------------------------------- /src/main/java/ysoserial/payloads/CommonsCollections1.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/ysoserial/payloads/CommonsCollections1.java -------------------------------------------------------------------------------- /src/main/java/ysoserial/payloads/CommonsCollections2.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/ysoserial/payloads/CommonsCollections2.java -------------------------------------------------------------------------------- /src/main/java/ysoserial/payloads/Groovy1.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/ysoserial/payloads/Groovy1.java -------------------------------------------------------------------------------- /src/main/java/ysoserial/payloads/ObjectPayload.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/ysoserial/payloads/ObjectPayload.java -------------------------------------------------------------------------------- /src/main/java/ysoserial/payloads/Spring1.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/ysoserial/payloads/Spring1.java -------------------------------------------------------------------------------- /src/main/java/ysoserial/payloads/annotation/Dependencies.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/ysoserial/payloads/annotation/Dependencies.java -------------------------------------------------------------------------------- /src/main/java/ysoserial/payloads/util/ClassFiles.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/ysoserial/payloads/util/ClassFiles.java -------------------------------------------------------------------------------- /src/main/java/ysoserial/payloads/util/Gadgets.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/ysoserial/payloads/util/Gadgets.java -------------------------------------------------------------------------------- /src/main/java/ysoserial/payloads/util/PayloadRunner.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/ysoserial/payloads/util/PayloadRunner.java -------------------------------------------------------------------------------- /src/main/java/ysoserial/payloads/util/Reflections.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/ysoserial/payloads/util/Reflections.java -------------------------------------------------------------------------------- /src/main/java/ysoserial/payloads/util/Serializables.java: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/njfox/Java-Deserialization-Exploit/HEAD/src/main/java/ysoserial/payloads/util/Serializables.java --------------------------------------------------------------------------------