wgpsec/aboutsecurity
java-deserialization-methodology
Java 反序列化漏洞检测与利用。当目标是 Java 应用(Tomcat/Spring/WebLogic/JBoss/Jenkins)、发现 rO0AB/aced0005 开头的 Base64 数据、HTTP 请求中有 application/x-java-serialized-object…
Installation
npx skills add https://github.com/wgpsec/aboutsecurity
Similar popular skills
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
>- Insecure deserialization playbook. Use when Java, PHP, or Python applications deserialize un…
2.9K installsIdentifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .…
215 installsHunt Insecure Deserialization — Java gadget chains (ysoserial), PHP object injection (phpggc), …
136 installsAlso in this package
Other skills from wgpsec/aboutsecurity · top by installs.
npx skills add https://github.com/wgpsec/aboutsecurity
More details
Agent compatibility
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
Repository health
master
History
- First seen on skills.sh
- First recorded snapshot · 25 installs