Web Hack List

Collected research

Are You My Type? Breaking .NET Through Serialization

Forshaw analyses .NET's BinaryFormatter and shows that deserialising untrusted data reaches dangerous framework classes such as TempFileCollection, FileSystemInfo and IWbemClassObjectFreeThreaded. He bypasses remoting's Low TypeFilterLevel via System.Data.DataSet, and abuses EvidenceBase.Clone (CVE-2012-0160) and XBAP exception marshalling (CVE-2012-0161) to round-trip serialise forged delegates and escape partial trust.

Record

Researcher
James Forshaw
Published by
Context Information Security
Format
Whitepaper
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of James Forshaw, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .