There are no reviews yet. Be the first to send feedback to the community and the maintainers!
README: This file should be located at the top of the jdk Mercurial repository. See http://openjdk.java.net/ for more information about the OpenJDK. Simple Build Instructions: 1. Download and install a JDK 6 from http://java.sun.com/javase/downloads/index.jsp Set the environment variable ALT_BOOTDIR to the location of this JDK 6. 2. Either download and install the latest JDK7 from http://download.java.net/openjdk/jdk7/, or build your own complete OpenJDK7 by using the top level Makefile in the OpenJDK Mercurial forest. Set the environment variable ALT_JDK_IMPORT_PATH to the location of this latest JDK7 or OpenJDK7 build. 3. Check the sanity of doing a build with the current machine: cd make && gnumake sanity See README-builds.html if you run into problems. 4. Do a partial build of the jdk: cd make && gnumake all 5. Construct the images: cd make && gnumake images The resulting JDK image should be found in build/*/j2sdk-image
ysoserial
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.ciphr
CLI crypto swiss-army knife for performing and composing encoding, decoding, encryption, decryption, hashing, and other various cryptographic operations on streams of data from the command line; mostly intended for ad hoc, infosec-related uses.inspector-gadget
Primitive tool for exploring/querying Java classes via the Tinkerpop Gremlin graph traversal languagegrepcidr
from http://www.pc-tools.net/unix/grepcidr/jdk8u-dev-jdk
jdeserialize
From https://code.google.com/p/jdeserialize/rails_exploits
serialysis
from http://weblogs.java.net/blog/emcmanus/archive/2007/06/disassembling_s.htmlappseccali-java
pd-buddy-wye
From https://git.clarahobbs.com/pd-buddy/pd-buddy-wye.gitctfd-trektheme
Star Trek LCARS inspired pure CSS theme for CTFd (v2.1.1) used during the 2019 LayerOne CTF and ToorCon CTF.inyourface
From http://www.synacktiv.com/ressources/inyourface-0.2.tar.gzappseccali-marshalling-pickles
Slide deck from AppSecCali 2015 Talk "Marshalling Pickles: how deserializing objects will ruin your day"sleepyhead
imported from https://sourceforge.net/projects/sleepyhead/grepcidr2
from http://www.taugh.com/grepcidr-2/owaspsd-deserialize-my-shorts
Slide deck from OWASP SD Talk "Deserialize My Shorts: Or How I Learned to Start Worrying and Hate Java Object Deserialization"burp-plugin-requestutils
Plugin for manipulating requests in PortSwigger Burp Suite Pro v1.5+jimmix
From http://www.synacktiv.com/ressources/jimmix-0.3.tar.gzjdk7u
shellshock-pocs
jmitm2
From http://www.david-guembel.de/uploads/media/jmitm2-0.1.0-source.tar.gzjdk6
dotfiles
pwdagent
A barebones CLI utility to prompt for and cache a password in memory, then hand it out over HTTP or raw TCPburp-debug
ircbots
reserializer
privilegedaccessor
From https://code.google.com/p/privilegedaccessor/frohoff.github.io
Github Pages Sitelambda-zip-test
docker run -v [homedir]/.aws/:/root/.aws/ -e AWS_DEFAULT_PROFILE=[profilename] [containerid]appseccali-rails-redis
java-suid-exec
Break glass in case of suid java executable.Love Open Source and this site? Check out how you can help us