Talk With an Expert

Fear of the Unknown: A Meta-Analysis of Insecure Object Deserialization Vulnerabilities

Fear of the Unknown: A Meta-Analysis of Insecure Object Deserialization Vulnerabilities (PDF, 4.96MB)Published: 28 Oct, 2020
Created by
Karim Lalji

Deserialization vulnerabilities have gained significant traction in the past few years, resulting in this category of weakness taking eighth place on the OWASP Top 10. Despite the severity, deserialization vulnerabilities tend to be among the less popular application exploits discussed (Bekerman, 2020) and frequently misunderstood by security consultants and penetration testers without a development background. This knowledge discrepancy leaves adversaries with an advantage and security professionals with a disadvantage. This research will aim to demonstrate exploitation techniques using insecure deserialization on multiple platforms, including Java, .NET, PHP, and Android, to obtain a metanalysis of exploitation techniques and defensive strategies.