编程语言
首页 > 编程语言> > Java反序列化梳理

Java反序列化梳理

作者:互联网

0x01 Java反序列化梳理

https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet

序号类型格式说明
01Java Native SerializationBinary通用利用,原生,ysoserial为工具
02XMLEncoderXML
03XStreamXML/JSON/various
04KryoBinary
05Hessian/BurlapBinary/XML
06CastorXML
07json-ioJSON
08JacksonJSON
09FastjsonJSON
10GensonJSON
11FlexjsonJSON
12JoddJSON
13Red5 IO AMFAMF
14Apache Flex BlazeDSAMF
15Flamingo AMFAMF
16GraniteDSAMF
17WebORB for JavaAMF
18SnakeYAMLYAML
19jYAMLYAML
20YamlBeansYAML
21"Safe" deserialization

JAXB

XmlBeans

Jibx

Protobuf

GSON

GWT-RPC

0x02 CVEs总结

https://github.com/PalindromeLabs/Java-Deserialization-CVEs

Java Deserialization CVEs - quantity by year

0xA0 参考

Java-Deserialization-Cheat-Sheet

https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet

Java-Deserialization-CVEs

https://github.com/PalindromeLabs/Java-Deserialization-CVEs

标签:github,Java,Deserialization,https,序列化,com,梳理,CVEs
来源: https://blog.csdn.net/zirandu/article/details/120147585