wgpsec/aboutsecurity
deserialization-methodology
不安全反序列化漏洞利用。当发现 Base64 编码的 Cookie/参数、Python pickle 数据、PHP serialized 字符串(O:4:...)、Java serialized 数据(rO0AB...)时使用。可直接获取 RCE
Installation
npx skills add https://github.com/wgpsec/aboutsecurity
Similar popular skills
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
>- Insecure deserialization playbook. Use when Java, PHP, or Python applications deserialize un…
2.9K installsIdentifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .…
215 installsHunt Insecure Deserialization — Java gadget chains (ysoserial), PHP object injection (phpggc), …
136 installsAlso in this package
Other skills from wgpsec/aboutsecurity · top by installs.
npx skills add https://github.com/wgpsec/aboutsecurity
More details
Agent compatibility
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
Repository health
master
History
- First seen on skills.sh
- First recorded snapshot · 23 installs