Web-Chains

Web-Chains

The Swiss Army Knife in Security Research

2,064GitHub
Description

The web-chains project, also known as the java-chains project, is led by Master Ar3h and is full of loopholes and supported by the Code Audit Planet. We stand on the shoulders of giants and are committed to building the strongest Swiss Army Knife in the field of Java security research. Web-chains includes but is not limited to the following features: Java deserializes native Payload generation Hessian 1/2 deserialized Payload generation Hessian1 supports the generation of deserialized data in Hessian Servlet format Shiro data generation (custom KEY uses GCM to confuse characters, etc.) AMF3 data generation (based on multiple advanced combinations of native data) XStream data generation (based on multiple advanced combinations of native data) BCEL bytecode generation (direct execution of commands, memory horse generation, echo generation, detection of bytecode, reading and writing files) Class bytecode generation (direct execution of commands, memory code generation, echo generation, detection of bytecode, reading and writing files) Various database Payload generation (Derby| H2 | PostgreSql | Sqlite) Fastjson/SnakeYAML/SpringBeanXML/Velocity/OGNL/MVEL/SPEL/JS/GROOVY Username/Password: admin/admin

Screenshots
Screenshot 1
Screenshot 2
App Information
Version
0.1.1
Package Size
474.39 KB
Image Size
536.99 MB
Updated
October 11, 2025
Source Code
Java-Chains
Platform Support
PC
Keywords
security research