Web Hack List

Later archive addition

Are You My Type? Breaking .NET Through Serialization

Forshaw analyses .NET's BinaryFormatter and shows that deserialising untrusted data reaches dangerous framework classes such as TempFileCollection, FileSystemInfo and IWbemClassObjectFreeThreaded. He bypasses remoting's Low TypeFilterLevel via System.Data.DataSet, and abuses EvidenceBase.Clone (CVE-2012-0160) and XBAP exception marshalling (CVE-2012-0161) to round-trip serialise forged delegates and escape partial trust.

Record

Researcher
James Forshaw
Published by
Context Information Security
Format
Whitepaper

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of James Forshaw, first published at the original source. Preserved copies are kept so the citation survives its host.