Collected research
Generating deserialization payloads for MessagePack C#’s Typeless mode
Generating deserialization payloads for MessagePack C#'s Typeless mode
Builds MessagePack Typeless payloads by serializing a surrogate object graph and replacing cached type names with the intended assembly-qualified names. The article explains limitations of serialization hooks and gadget versions, including ObjectDataProvider behavior and XmlResolver settings relevant to XML external entity access.
Record
- Document
- Generating deserialization payloads for MessagePack C#'s Typeless mode
- Researcher
- Dane Evans
- Published by
- Netwrix
- Topic
- Other
In the archive
Related sources
- Added ObjectDataProvider gadget generation for MessagePack (Typeless)
- Friday the 13th JSON Attacks Whitepaper
- Ysoserial.NET
- Added ObjectDataProvider gadget generation for MessagePack (Typeless)
Tags
This page is the archive's own catalogue record. The research is the work of Dane Evans, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .