Web Hack List

Collected research

Exploiting Deserialisation in ASP.NET via ViewState

ASP.NET signs and encrypts the __VIEWSTATE parameter using machineKey values, so when MAC validation is disabled or the validation and decryption keys leak, an attacker forges a ViewState carrying a serialisation gadget and executes code on the server. Covers a ysoserial.net plugin, legacy .NET behaviour, recovering the application path, __EVENTVALIDATION, and WAF evasion.

Record

Researcher
Soroush Dalili
Published by
soroush.me
Date
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Soroush Dalili, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .