Web Hack List

Collected research

Finding and Exploiting .NET Remoting over HTTP using Deserialisation

Servers exposing .NET Remoting over HTTP with TypeFilterLevel set to Full deserialise attacker-supplied SOAP bodies, so ysoserial.net gadgets reach code execution once the Body tags are stripped or a dummy method tag is inserted. Adds safe detection by error message, attacks on clients over unencrypted channels, a crash case, and header and encoding tricks that evade WAFs.

Record

Researcher
Soroush Dalili
Published by
NCC Group
Date
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Soroush Dalili, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .