Skip to content

f0ur0four/Insecure-Deserialization

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

9 Commits
 
 

Repository files navigation

Insecure-Deserialization

Resources to learn about Insecure Deserialization

Learning Resources & Practice Platforms

Starting Out

Portswigger's WebSecAcademy (Free)

PentesterLab (Paid)

TryHackMe (Free)

HackTheBox (Paid)

Academy Modules

Machines (The writeups of these machines are available online)

Easy

Medium

Hard

Insane

Source Incite's Full Stack Web Attack - Challenge

Additional Resources

CheatSheets


Talks, Presentations & Docs

General

(De)Serial Killers

Insecure Deserialization And How Not To Do It

Java

Java Serialization Deep Dive

Unsafe Deserialization Attacks In Java

Mitigating Java Deserialization Attacks

Deserialization: What, How And Why Not

Practical Serialization Attacks

Why We Hate Java Serialization And What We're Doing About It

Marshalling Pickles

Exploiting Deserialization Vulnerabilities In Java

Serial Killer: Silently Pwning Your Java Endpoints

Deserialize My Shorts: Or How I Learned To Start Worrying and Hate Java Object Deserialization

Surviving The Java Serialization Apocalypse

Java Deserialization Vulnerabilities - The Forgotten Bug Class

Pwning Your Java Messaging With Deserialization Vulnerabilities

Defending Against Java Deserialization Vulnerabilities

A Journey From JNDI/LDAP Manipulation To Remote Code Execution Dream Land

Fixing The Java Serialization Mess

Blind Java Deserialization

An Overview of Deserialization Vulnerabilities in the Java Virtual Machine (JVM)

Automated Discovery of Deserialization Gadget Chains

Finding Java Deserialization Gadgets With CodeQL

Far Sides Of Java Remote Protocols

New Exploit Technique In Java Deserialization Attack

ODDFuzz: Hunting Java Deserialization Gadget Chains via Structure-Aware Directed Greybox Fuzzing

Deserialization Exploits In Java: Why Should I Care?

How I Used A JSON Deserialization 0day To Steal Your Money On The Blockchain

C-Sharp / .NET

Attacking .NET Deserialization

.NET Deserialization Attacks And Their Associated Threats In The World Of CMS

Friday The 13th: JSON attacks

Dangerous Contents - Securing .Net Deserialization

RCEvil.Net

Second Breakfast: Implicit and Mutation-Based Serialization Vulnerabilities in .NET

Are You My Type? Breaking .NET Sandboxes Through Serialization

.NET Roulette: Exploiting Insecure Deserialization in Telerik UI

Exploiting Hardened .NET Deserialization

OffensiveCon24 - Piotr Bazydlo - Half Measures and Full Compromise

Python

Sour Pickles

Backdooring Pickles: A Decade Only Made Things Worse

Poisoned Pickles Make You ILL

Perl

Weaponizing Perl Serialization Flaws With MetaSploit

PHP

Practical PHP Object Injection

It's A PHP Unserialization Vulnerability Jim, But Not As We Know It

Exploiting PHP7 Unserialize

PHP Unserialization Vulnerabilities – What Are We Missing

Utilizing Code Reuse/ROP In PHP Application Exploits

Shocking News In PHP Exploitation


Blogs, Articles, Research Papers & Other Resources

General

Java

PHP

Python

Node.js

Ruby

Perl

C-Sharp / .NET


Some HackerOne Disclosed Reports


Tools

Java

.NET

Python

Ruby

About

Resources to learn about Insecure Deserialization

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published