Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
JYso — Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions. Supports memory shell injection, serialization payload generation, and MSF/CS integration. | Kitploit
Tools/GitHubGitHub/qi4l/jyso
Penetration Testing FrameworksExploit FrameworksMemory ForensicsPayload GenerationWeb Application ExploitationCTFCommand and ControlShellcode Generation
GitHubqi4l/jyso

JYso

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions. Supports memory shell injection, serialization payload generation, and MSF/CS integration.

1.8k191182 months agoReviewed by Kitploit
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

JYso

It can be used as a tool for ysoserial and JNDIExploit at the same time, and has the bypass function of multiple JNDI high versions, WAF, and RASP

🚀 Getting Started Guide

📢 Please take a moment to read this document, it will help you quickly get familiar with JYso!

🧐 Use the Documentation Wiki.

✔ Download the latest version of Releases.

👍 Features

  • JNDI account password startup
  • JNDI route hiding or encryption
  • JNDI high version Bypass
  • Customize the path, password, HTTP header and value of the memory horse
  • Memory horse supports Fileless landing Agent insertion
  • Memory horse writes JRE or environment variables to hide
  • Serialized data plus dirty data
  • Serialized data is encoded in UTF-8 corresponding to 3 bytes
  • TemplatesImpl _bytecodes feature eliminated and size reduced
  • SignedObject secondary deserialization, can be used to bypass TemplatesImpl blacklist, CC without array and blacklist often seen in CTF, etc.
  • Solve the problem of Shiro Header being too long, get the value of the specified parameter from the request for class loading
  • Dynamically generate obfuscated class names
  • MSF/CS online
  • Code execution through JDBC
  • If you have other great ideas, please let me know! 😎

    🐯 Compile

    Download gradle8.7+ and configure it in the global environment variable, and execute it in the project root directory

    root@kitploit:~
    ./gradlew shadowJar
    

    🌲Directory structure

    For more information, please refer to Directory structure description.

    ✨ CTStack

    JYso has joined the CTStack community

    ✨ 404Starlink

    404StarLink Project Logo

    JYso has joined 404Starlink

    1. 入选2024年KCon兵器谱

    📷 Acknowledgements

    • https://github.com/veracode-research/rogue-jndi
    • https://github.com/welk1n/JNDI-Injection-Exploit
    • https://github.com/welk1n/JNDI-Injection-Bypass
    • https://github.com/WhiteHSBG/JNDIExploit
    • https://github.com/su18/ysoserial
    • https://github.com/rebeyond/Behinder
    • https://github.com/Whoopsunix/utf-8-overlong-encoding
    • https://github.com/mbechler/marshalsec
    • https://t.zsxq.com/17LkqCzk8
    • https://mp.weixin.qq.com/s/fcuKNfLXiFxWrIYQPq7OCg
    • https://xz.aliyun.com/t/11640?time__1311=mqmx0DBDuDnQ340vo4%2BxCwg%3DQai%3DYzaq4D&alichlgref=https%3A%2F%2Fxz.aliyun.com%2Fu%2F8697
    • https://archive.conference.hitb.org/hitbsecconf2021sin/sessions/make-jdbc-attacks-brilliant-again/
    • https://tttang.com/archive/1405/#toc_0x03-jdbc-rce
    • https://xz.aliyun.com/t/10656?time__1311=mq%2BxBDy7G%3DLOD%2FD0DoYg0%3DDR0HG8KeD&alichlgref=https%3A%2F%2Ftttang.com%2F#toc-7
    • https://whoopsunix.com/docs/PPPYSO/advance/UTFMIX/
    • https://tttang.com/archive/1405/#toc_groovyclassloader
    • https://xz.aliyun.com/t/10656?time__1311=mq%2BxBDy7G%3DLOD%2FD0DoY4AKqiKD%3DOQjqx&alichlgref=https%3A%2F%2Ftttang.com%2F
    • https://www.leavesongs.com/PENETRATION/use-tls-proxy-to-exploit-ldaps.html
    • https://tttang.com/archive/1405/#toc_druid
    Download Tool