4 ms·
> serializing objects is so very complicated and dangerous. Serialized "data" is a program that can do everything a normal Java program can do. As I recall, th
by marcodave 8y ago
> serializing objects is so very complicated and dangerous. Serialized "data" is a program that can do everything a normal Java program can do.
As I recall, the default behavior of Java (de)serializer, would only write the data fields one by one in binary format.
The code itself, i.e. the bytecode of the methods and the class definition itself have to be in the classpath at application startup, so how could this malign code be injected as part of the attack?
- hedora 8y agoIn the face of an attack, the serializer framework unexpectedly invokes arbitrary existing methods/constructors on untrusted data, including malformed private object states. So, if the attacker can trick one class anywhere on the classpath into doing something bad, then they can bootstrap an attack. It is similar to “return oriented programming”, which is one way to escalate c stack overflows to arbitrary code execution.