AWAE - OSWE Preparation / Resources
CtrlK
  • TL;DR
  • General
    • Resources
    • POCs
  • By Vulnerability
    • SQL Injection
    • Deserialization
      • By Language
        • PHP
        • JAVA
          • Regex
          • Summary
          • Practice
          • Resources
        • .NET
      • Resources
    • XSS
    • XXE
    • SSTI
    • File Upload Restrictions Bypass
  • REGEX
  • By Language
    • PHP
    • Java
    • NodeJS
  • Random
  • Other Repositories
Powered by GitBook
On this page
  • Cheatsheets
  • Ysoserial Bruteforcer
  • Articles

Was this helpful?

  1. By Vulnerability
  2. Deserialization
  3. By Language
  4. JAVA

Resources

Cheatsheets

LogoPage not found - HackTricksbook.hacktricks.xyz
LogoJava-Deserialization-Cheat-Sheet/README.md at master · GrrrDog/Java-Deserialization-Cheat-SheetGitHub

Ysoserial Bruteforcer

LogoSerialBrute/SerialBrute.py at master · NickstaDB/SerialBruteGitHub

Articles

https://twitter.com/jorge_ctf/status/1285240301620273156twitter.com
LogoExploiting Blind Java Deserialization with Burp and YsoserialCoalfire
LogoTricking blind Java deserialization for a treatSecurity Café
LogoJava Deserialization Attacks with BurpNetSPI
https://www.thedarksource.com/java-deserialization-vulnerability-detection-and-exploitation-burp-suite/www.thedarksource.com

PreviousPracticeNext.NET

Last updated 5 years ago

Was this helpful?