johndekroon / serializekiller

Mass scanner for the Java serialize bug
The Unlicense
148 stars 40 forks source link

Question (no issue); new features #14

Open syrius01 opened 6 years ago

syrius01 commented 6 years ago

Hi johndekroon!

I would like to let you know that this is the best tool I've found so far for testing multiple java deserialization bugs :) Since the tool is getting a little old, do you plan to add new features? I have some ideas of other java bugs like JSF/Seam Applications via javax.faces.ViewState.

Thanks,

syrius01

knoxcard commented 6 years ago

@johndekroon I was thinking about porting this over to NodeJS, so all Javascript, it doesn't seem too difficult to do. How are you with Javascript? I will also create a ssh_modules/ folder so you can just put SSH scripts in there, no Javascript necessary I guess. :-)