Other nomination
Teaching the Old .NET Remoting New Exploitation Tricks
Three ways to exploit .NET Remoting servers hardened with a low type filter level and Code Access Security. The attacker calls framework methods that assert privileges in order to drop and load a DLL for code execution, or coerces the server into serialising a remotable object such as a web client, getting back a proxy that reads and writes arbitrary files.
In the archive
Related sources
- HTTP Remoting demonstration application
- log4net RemotingAppender removal
- NewRemotingTricks source code
Tags
This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.