2024-04-03 11:48:27 +08:00
2024-04-03 11:48:27 +08:00
2024-04-02 17:04:39 +08:00
2024-04-02 17:04:39 +08:00
2024-04-02 17:04:39 +08:00
2024-04-02 17:13:49 +08:00
2024-04-02 17:04:39 +08:00
2024-04-02 17:04:39 +08:00
2024-04-03 11:48:27 +08:00
2024-04-03 11:48:27 +08:00
2024-04-02 17:04:39 +08:00

🐦‍⬛JYso

JYso is a tool that can be used as both ysoserial and JNDIExploit. It also has bypass functions of multiple JNDI high versions, WAF, and RASP.

🦜Help!

Please check wiki for specific usage.

You can download the latest version releases from here.

🐲Features

  • JNDI account activation
  • JNDI routing hidden or encrypted
  • JNDI high version Bypass
  • 12 available echo classes
  • 18 available memshell classes, and supports modifying the memshell path, password, authentication HTTP header and value
  • 75 available Gadgets and provide multiple ways to use them
  • Memory horse supports No file landing Agent entry
  • write the memshell to JRE or environment variable to hide
  • Serialized data plus dirty data
  • Serialized data is encoded in UTF-8 corresponding to 3 bytes
  • Secondary deserialization of SignedObject, which can be used to bypass TemplatesImpl blacklist, CC countless groups and blacklists that often appear in CTF, etc.
  • To solve the problem that the Shiro Header header is too long, obtain the value of the specified parameter from the request for class loading.
  • Dynamically generate obfuscated class names
  • MSF/CS online

404StarLink 2.0 - Galaxy

JYso is a part of 404Team 404StarLink 2.0. If you have questions about JYso or want to find a partner to communicate, you can refer to the Starlink group project.

👮免责声明

This tool is only for legally authorized enterprise security construction activities. If you need to test the usability of this tool, please build a target drone environment yourself.

In order to avoid malicious use, all POCs included in this project are theoretical judgments of vulnerabilities. There is no vulnerability exploitation process, and no real attacks or exploits will be launched on the target.

When using this tool for testing, you should ensure that your behavior complies with local laws and regulations and that you have obtained sufficient authorization. Do not scan unauthorized targets.

If you commit any illegal behavior while using this tool, you shall bear the corresponding consequences yourself, and we will not assume any legal and joint liability.

Before installing and using this tool, please be sure to read carefully and fully understand the contents of each clause. Restrictions, disclaimers, or other clauses involving your major rights and interests may be bolded, underlined, etc. to remind you to pay attention. Please do not install and use this tool unless you have fully read, fully understood and accepted all the terms of this agreement. Your usage behavior or your acceptance of this Agreement in any other express or implicit manner shall be deemed to have read and agreed to be bound by this Agreement.

Star History

Star History Chart

📷reference project

S
Description
It can be either a JNDIExploit or a ysoserial.
Readme
108 MiB
Languages
Java 100%