Collected research
Teaching the Old .NET Remoting New Exploitation Tricks
Three ways to exploit .NET Remoting servers hardened with a low type filter level and Code Access Security. The attacker calls framework methods that assert privileges in order to drop and load a DLL for code execution, or coerces the server into serialising a remotable object such as a web client, getting back a proxy that reads and writes arbitrary files.
Record
- Published by
- code-white.com
- Topic
- Other
In the archive
Related sources
- HTTP Remoting demonstration application
- log4net RemotingAppender removal
- NewRemotingTricks source code
Tags
This page is the archive's own catalogue record. The research is the work of code-white.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .