Web Hack List

Collected research

Attacking PowerShell CLIXML Deserialization

Analyses PowerShell's CLIXML deserialization, where objects are restored as property bags or rehydrated as live objects, and shows the default rehydrating types supply usable gadgets: a CIM ping type triggering arbitrary DNS lookups, a registry type whose formatter captures Net-NTLMv2 hashes, and a popular third-party module whose converter wraps BinaryFormatter for code execution. PowerShell Remoting and Direct deserialize server-supplied CLIXML, so a guest can attack its Hyper-V host.

Record

Researcher
siteadmin and @Truesec
Published by
Truesec
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of siteadmin and @Truesec, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .