Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

GadgetProbe: Exploiting Deserialization to Brute-Force the Remote Classpath

Summary

Bishop Fox's GadgetProbe probes Java deserialization endpoints to enumerate classes and library versions on the remote classpath, helping testers build payloads when ysoserial chains fail blind.
Published
Collected

original ↗

Related coverage

back