| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Name | Name | Last commit date | ||
|---|---|---|---|---|
I am not actively updating this extension. I recommend using either https://github.com/federicodotta/Java-Deserialization-Scanner, https://portswigger.net/bappstore/e20cad259d73403bba5ac4e393a8583f, or https://portswigger.net/bappstore/ae1cce0c6d6c47528b4af35faebc3ab3 for exploiting Java Deserialization
Burp extension to perform Java Deserialization Attacks using the ysoserial payload generator tool.
Blog https://blog.netspi.com/java-deserialization-attacks-burp/
Chris Frohoff's ysoserial (https://github.com/frohoff/ysoserial)
Download from the Releases tab: https://github.com/NetSPI/JavaSerialKiller/releases
Requirements: Java 8
Note: You do not need to re-highlight the serialized Java object if you change the payload or command. It will automatically update the request with the correct serialization in the spot that you highlighted the first time, even if you base64 encode it.
##Examples ###Serialize Request Body
###Serialize Request Body Parameter
| Back | FazBrowse Home | New Git URL |