Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[feature request] modules for java deserialization vulnerabilities #44

Open
thesle3p opened this issue Jan 12, 2016 · 3 comments
Open

Comments

@thesle3p
Copy link

Several App servers were found to be vulnerable to java deserialization vulnerabilities The article below details exploitation for several app servers:
http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/

@breenmachine
Copy link
Collaborator

I don't know about those "foxglovesecurity" guys, sounds fishy to me.

@thesle3p
Copy link
Author

It's a pretty well documented vulnerability though.
On Jan 12, 2016 5:53 PM, "Stephen Breen" notifications@github.com wrote:

I don't know about those "foxglovesecurity" guys, sounds fishy to me.


Reply to this email directly or view it on GitHub
#44 (comment).

@hatRiot
Copy link
Owner

hatRiot commented Jan 12, 2016

@breenmachine made the original serialization post; he was being facetious :)

This issue is a duplicate of #42 , but yeah it needs to be added.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants