Тёмный

Deserialization exploits in Java: why should I care? by Brian Vermeer 

Devoxx UK
Подписаться 11 тыс.
Просмотров 2 тыс.
50% 1

For more info on the next Devoxx UK event 👉 www.devoxx.co.uk
Hackers refer to deserialization in Java as “the gift that keeps on giving”. But what is actually the problem? In most cases, it is not even your own code that creates this security vulnerability. This problem is also not restricted to Java’s custom serialization framework. When deserializing JSON, XML, or YAML, similar issues can occur as well. In this talk, I explain how deserialization vulnerabilities work natively in Java and how attack chains are created. Next, I will show that deserializing XML, JSON, and YAML can also get you into trouble. And of course, we had the recent Log4j problems with deserialization. Many different problems can occur when deserializing data and in this session, I will use several demos to illustrate various security issues. How do you avoid these issues? I will give you some pointers on how to mitigate these problems in your own applications, this also includes new features in Java 17. At the end of this session, you will have an understanding of the problem space and be able to take action in your code to prevent it.

Опубликовано:

 

8 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 4   
@DavidvanDeijk
@DavidvanDeijk 2 года назад
learned quite a few things, thanks Brian!
@abcxyzheck123
@abcxyzheck123 2 года назад
Great talk
@fabasoad
@fabasoad Год назад
Thanks! That was interesting ❤
@koti2547
@koti2547 2 года назад
Great talk
Далее
How We Decide by ANDREW HARMEL-LAW
50:06
Просмотров 1,2 тыс.
Automated Discovery of Deserialization Gadget Chains
39:14
2017 OWASP Top 10: Insecure Deserialization
8:50
Просмотров 87 тыс.
IntelliJ IDEA Tips & Tricks by ANTON ARHIPOV
50:43
Просмотров 1,9 тыс.
So You Think You Know Git - FOSDEM 2024
47:00
Просмотров 1,1 млн
I've been using Redis wrong this whole time...
20:53
Просмотров 356 тыс.