All demo files are at the https://github.com/o2platform/DefCon_RESTing repository.
See these blog posts for details on the demos:
- Using XMLDecoder to execute server-side Java Code on an Restlet application (i.e. Remote Command Execution)
- Neo4J CSRF payload to start processes (calc and nc) on the server