Learn, hack!

Hacking and security documentation: slides, papers, video and audio recordings. All in high-quality, daily updated, avoiding security crap documents. Spreading hacking knowledge, for free, enjoy. Follow on .

Understanding the Java Serialization Attack Surface

Type
Slides
Tags
Java
Authors
Daniel Grzelak
Event
Ruxcon 2010
Indexed on
Mar 26, 2013
URL
http://www.ruxcon.org.au/assets/Presentations/daniel-grzelak.understanding-java-serialization.2010.pdf
File name
daniel-grzelak.understanding-java-serialization.2010.pdf
File size
844.4 KB
MD5
faf3aa85d0e7c7926ae8fe71acd21019
SHA1
b6d06e5334f5ac52974c88b0c418d6b78b7f1135

We have recently been asked to perform a number of security assessments which use Java serialised objects to communicate information between client and server. This approach is quite common, particularly in applications which implement some form of thick(ish) client. However, whenever I see these things flying across my proxy I always get excited and think "there has to be something wrong here..." So is there something really wrong? What should we be concentrating on when trying to attack these applications?

About us

Secdocs is a project aimed to index high-quality IT security and hacking documents. These are fetched from multiple data sources: events, conferences and generally from interwebs.

Statistics

Serving 8166 documents and 531.0 GB of hacking knowledge, indexed from 2419 authors from 163 security conferences.

Contribute

To support this site and keep it alive, you can click on the buttons below. Any help is really appreciated! This service is provided for free, but real money is needed to pay bills.

Flattr this Click here to lend your support to: Keep live SecDocs for an year and make a donation at www.pledgie.com !