Collected research
Exploiting Deserialisation in ASP.NET via ViewState
ASP.NET signs and encrypts the __VIEWSTATE parameter using machineKey values, so when MAC validation is disabled or the validation and decryption keys leak, an attacker forges a ViewState carrying a serialisation gadget and executes code on the server. Covers a ysoserial.net plugin, legacy .NET behaviour, recovering the application path, __EVENTVALIDATION, and WAF evasion.
Record
- Researcher
- Soroush Dalili
- Published by
- soroush.me
- Date
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Soroush Dalili, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .