Bill Sempf  -- Insecure Deserialization episode artwork

EPISODE · Feb 2, 2018 · 34 MIN

Bill Sempf -- Insecure Deserialization

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

What happens when data arriving at an application is allowed to recreate objects and trigger unexpected behavior? Bill Sempf joins Chris and Robert to unpack insecure deserialization, a new category in the 2017 OWASP Top 10. He explains serialization through familiar programming examples and describes the research questions that drew him into the topic. The conversation follows attacks across language ecosystems, discusses the possible impact of accepting untrusted serialized objects, and considers ways to reduce exposure. Bill also shares how an assessor might recognize serialized data, investigate application behavior, and use an intercepting proxy during testing. Alongside his work in the .NET security community, this archive conversation captures practitioners working through a difficult vulnerability class and debating the limits of their tools and assumptions.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Bill Sempf:→ Bill Sempf’s developer profileMentioned in this episode:→ OWASP Top 10 project repository→ ZAP→ Burp SuiteFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Insecure deserialization with Bill Sempf01:14 Bill’s security origin story06:54 Filling gaps in .NET security guidance08:05 Why deserialization entered the 2017 Top 1010:48 Researching examples across platforms12:22 Serialization and deserialization explained15:54 The impact of malicious serialized objects17:35 Reducing deserialization risk23:09 ViewState and framework considerations24:37 Debating .NET and language-specific behavior27:29 Recognizing serialized data during an assessment28:53 Investigating with intercepting proxies30:31 What testing tools can find

Episode metadata supplied by the publisher feed · Published Feb 2, 2018

Embed this episode

What happens when data arriving at an application is allowed to recreate objects and trigger unexpected behavior? Bill Sempf joins Chris and Robert to unpack insecure deserialization, a new category in the 2017 OWASP Top 10. He explains serialization through familiar programming examples and describes the research questions that drew him into the topic. The conversation follows attacks across language ecosystems, discusses the possible impact of accepting untrusted serialized objects, and con...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Bill Sempf -- Insecure Deserialization

0:00 34:06

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 34 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on February 2, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!