Collected research
Finding and Exploiting .NET Remoting over HTTP using Deserialisation
Servers exposing .NET Remoting over HTTP with TypeFilterLevel set to Full deserialise attacker-supplied SOAP bodies, so ysoserial.net gadgets reach code execution once the Body tags are stripped or a dummy method tag is inserted. Adds safe detection by error message, attacks on clients over unencrypted channels, a crash case, and header and encoding tricks that evade WAFs.
Record
- Researcher
- Soroush Dalili
- Published by
- NCC Group
- Date
- Topic
- HTTP
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Soroush Dalili, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .