Web Hack List

Top 10 winner

Exploiting Hardened .NET Deserialization

Exploiting Hardened .NET Deserialization: New Exploitation Ideas and Abuse of Insecure Serialization (Whitepaper)

Shows how to keep exploiting .NET deserialization sinks that vendors hardened with type allow-lists and binders: new gadgets in product code and third-party libraries, arbitrary getter-call chains, and abuse of insecure serialization to reach remote code execution, arbitrary file read and environment-variable leaks, demonstrated on SolarWinds Platform and Delta InfraSuite.

Record

Document
Exploiting Hardened .NET Deserialization: New Exploitation Ideas and Abuse of Insecure Serialization (Whitepaper)
Researcher
Piotr Bazydło
Published by
Trend Micro Zero Day Initiative
Format
Whitepaper
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Piotr Bazydło, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .