Later archive addition
Second Breakfast: Implicit and Mutation-Based Serialization Vulnerabilities in .NET
A serializer can be made to emit data that deserializes into a different type than was serialized: a dictionary key named like its type specifier, such as __type or $type, is written verbatim and read back as a type instruction. Untrusted key-value data that is only stored and later reloaded yields remote code execution, even when the attacker never touches the serialized stream.
Record
- Researcher
- Jonathan Birch
- Published by
- DEF CON
- Format
- Whitepaper
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Jonathan Birch, first published at the original source. Preserved copies are kept so the citation survives its host.