Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.
You must be logged in to block users.
Contact GitHub support about this user’s behavior. Learn more about reporting abuse.
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
Java 4.4k 1.3k
CLI crypto swiss-army knife for performing and composing encoding, decoding, encryption, decryption, hashing, and other various cryptographic operations on streams of data from the command line; mo…
Ruby 95 29
Primitive tool for exploring/querying Java classes via the Tinkerpop Gremlin graph traversal language
Java 88 21
Slide deck from AppSecCali 2015 Talk "Marshalling Pickles: how deserializing objects will ruin your day"
CSS 6 4
Slide deck from OWASP SD Talk "Deserialize My Shorts: Or How I Learned to Start Worrying and Hate Java Object Deserialization"
CSS 4
Seeing something unexpected? Take a look at the GitHub profile guide.