Is SerializationException sign of Serialization/Deserialization vulnerability?

I am doing a bug bounty. I intercepted the POST request to the inscription in the target website. I modified the first name and last name POST params to inject bad char (in order to SQL inject) but the API/Registration service sends me a r… Continue reading Is SerializationException sign of Serialization/Deserialization vulnerability?

How do gadget chains work in relation to Java Deserialization attacks?

tl;dr
I would love a detailed explanation how user-controlled input goes from readObject to RCE. Java-specific.
The background
This is my attempt to add specificity to the OP question as requested in the answer here.
I have been slowly but… Continue reading How do gadget chains work in relation to Java Deserialization attacks?

This Week in Security: BGP Bogons, Chrome Zero Day, and Save Game Attacks

Our own [Pat Whetman] wrote about a clever technique published by the University of Michigan, where lasers can be used to trigger a home assistant device. It’s an interesting hack, and you should go read it.

Borrowing IP Addresses

We’ve lived through several IPv4 exhaustion milestones, and the lack of …read more

Continue reading This Week in Security: BGP Bogons, Chrome Zero Day, and Save Game Attacks

Nexus Intelligence Insights Sonatype-2017-0312: jackson-databind, The End of the Blacklist

For our October Nexus Intelligence Insight we will return to a very popular component that has been both a blessing and a curse to developers around the world. We’ll cover a fundamental change to a default setting and how that change in &#82… Continue reading Nexus Intelligence Insights Sonatype-2017-0312: jackson-databind, The End of the Blacklist

Serialization: Protecting Enterprise Critical Applications

Enterprise organizations have built much of their foundations on Oracle’s WebLogic servers. As ubiquitous as they are, it’s no wonder that they are often the target of sophisticated attacks aimed at harvesting sensitive data. It’s no surprise that lar… Continue reading Serialization: Protecting Enterprise Critical Applications

This Week in Security: SACK of Death, Rambleed, HIBP for Sale, and Oracle Weblogic — Again!

Netflix isn’t the first name to come to mind when considering security research firms, but they make heavy use of FreeBSD in their content delivery system and do security research as a result. Their first security bulletin of the year, not surprisingly, covers a FreeBSD vulnerability that happens to also …read more

Continue reading This Week in Security: SACK of Death, Rambleed, HIBP for Sale, and Oracle Weblogic — Again!