文档payload生成工具包参考资料 文档《记一次Java反序列化漏洞的发现和修复》https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet payload生成工具包 https://github.com/frohoff/ysoserial https://github.com/Contrast-Security-OSS/contrast-rO0 https://github.com/federicodotta/Java-Deserialization-Scanner 参考资料 http://www.freebuf.com/vuls/170344.html https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet/blob/master/README.md https://github.com/mbechler/marshalsec/tree/master/src/main/java/marshalsec/gadgets https://github.com/frohoff/ysoserial/blob/master/src/main/java/ysoserial/payloads/util/Gadgets.java