4 tools and resources
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
A deserialization payload generator for .NET formatters
A cheat sheet for pentesters and researchers about deserialization vulnerabilities in various Java (JVM) serialization libraries.
A categorized collection of bug bounty write-ups for various vulnerabilities.