Filter
Exclude
Time range
-
Near
21 May 2024
Just completed the "Tony the Tiger" room on @tryhackme! Learned about Java deserialization—new for me. Great experience! 🚀 #TryHackMe #CyberSecurity #JavaDeserialization #CTF #Learn
2
30
More fun content from my fellow Labs researcher Thomas Hendrickson. This is a fun read if you're looking for how to handle some fairly restrictive payload size requirements as part of Java deserialization exploitation. #thornsftp #rce #cve202347174 #javadeserialization #ysoserial
Our researchers were at it again, this time uncovering a Java deserialization vuln that led to unauthenticated RCE in the Thorn SFTP Gateway Admin portal. Check out the blog to learn how they did it: hubs.ly/Q027xtpp0 #rce #vulnerabilityresearch #thornsftp #securityexperts
3
447
30 Oct 2022
Ermir - An Evil Java RMI Registry dlvr.it/Sbxphg #Ermir #java #JavaDeserialization #Wrapper #Ysoserial via KitPloit
1
2
@wabafet1 and I made a exploit for the Vcenter AMF Deserialization . Full #Analysis Available here - @AttackerKb attackerkb.com/topics/5nZX40… #exploit - github.com/dorkerdevil/LongT… #JavaDeserialization

4
5
RMIScout - Wordlist And Bruteforce Strategies To Enumerate Java RMI Functions And Exploit RMI Parameter Unmarshalling Vulnerabilities feedproxy.google.com/~r/Pent… #Bruteforce #BruteforceAttacks #Bruteforcing #Java #JavaDeserialization #JavaRMI

1
2
14 Sep 2018
Just finished the first run of the 4 day training #AdvancedJavaExploitation by @matthias_kaiser of @codewhitesec and learned loads about #ELInjection, #StrutsExploits, #JavaDeserialization and much more! Thanks for the awesome time!
1
6