Login or register
SecDocs RSS feed

Paper details

Title Attacking JAVA Serialized Communication
Type Paper
Tags Java
Abstract Many applications written in JAVA make use of Object Serialization to transfer full blown objects across the network via byte streams or to store them on the file system. While Penetration Testing applications communicating via Serialized Objects, current tools/application interception proxies allow very limited functionality to intercept and modify the requests and responses like in typical web applications. I'm trying to introduce a new technique to intercept such Serialized communication and modify it to perform penetration testing with almost the same ease as testing regular web applications. For achieving this I have developed a plug-in for Burp Suite as a proof-of-concept. What makes this technique unique is that it is completely seamless and gives the penetration tester the same control and power that an application developer has.
Authors Manish Saindane
Submitted June 21, 2010
Rating
Currently 0/5 stars (0 votes).
Correlation
Linked to
Event Black Hat EU 2010
Resource ---
Download
Source BlackHat-EU-2010-Attacking-JAVA-Serialized-Communication-wp.pdf
Size 854.6 KB
MD5 e472656ce7371218e3a043f6a9b56f70
SHA1 c0e7c6ea1638cb2581e2dc23e99052efc44fcf01

Comments
No comments.
Add new Only logged in users can comment.


Click here to lend your support to: SecDocs and make a donation at www.pledgie.com !