Black Hat USA 2018 - Automated Discovery of Deserialization Gadget Chains @HackersOnBoard
Black Hat USA 2018 - Automated Discovery of Deserialization Gadget Chains  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 4 days ago
Although vulnerabilities stemming from the deserialization of untrusted data have been understood for many years, unsafe deserialization continues to be a vulnerability class that isn't going away. Attention on Java deserialization vulnerabilities skyrocketed in 2015 when Frohoff and Lawrence published an RCE gadget chain in the Apache Commons library and as recently as last year's Black Hat, Muñoz and Miroshis presented a survey of dangerous JSON deserialization libraries. While much research and automated detection technology has so far focused on the discovery of vulnerable entry points (i.e. code that deserializes untrusted data), finding a "gadget chain" to actually make the vulnerability exploitable has thus far been a largely manual exercise. In this talk, I present a new technique for the automated discovery of deserialization gadget chains in Java, allowing defensive teams to quickly identify the significance of a deserialization vulnerability and allowing penetration testers to quickly develop working exploits. At the conclusion, I will also be releasing a FOSS toolkit which utilizes this methodology and has been used to successfully develop many deserialization exploits in both internal applications and open source projects.
Black Hat USA 2018 - Automated Discovery of Deserialization Gadget ChainsBlack Hat USA 2018 - Back to the Future A Radical Insecure Design of KVM on ARMBlack Hat USA 2018 - AFLs Blindspot and How to Resist AFL Fuzzing for Arbitrary ELF BinariesBlack Hat USA 2018 - DeepLocker - Concealing Targeted Attacks with AI LocksmithingDEF CON 27 - Bill Swearingen - HAKC THE POLICEDEF CON 27 - Breaking The Back End It Is Not Always A Bug Sometimes It Is Just Bad DesignDEF CON 27 - 100 Seconds of Solitude Defeating Cisco Trust Anchor With FPGA Bitstream ShenanigansDEF CON 27 - Panel - DEF CON to help hackers anonymously submit bugs to the government discussDEF CON 27 - Alvaro Munoz - SSO Wars The Token MenaceBlack Hat USA 2018 - Fire & Ice Making and Breaking macOS FirewallsDEF CON 27 - smea - Adventures In Smart Buttplug Penetration testingDEF CON 27 - Unpacking Pkgs A Look Inside Macos Installer Packages And Common Security Flaws
HackersOnBoard |

Black Hat USA 2018 - Automated Discovery of Deserialization Gadget Chains

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER