EPISODE · Feb 2, 2018 · 34 MIN
Bill Sempf -- Insecure Deserialization
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
What happens when data arriving at an application is allowed to recreate objects and trigger unexpected behavior? Bill Sempf joins Chris and Robert to unpack insecure deserialization, a new category in the 2017 OWASP Top 10. He explains serialization through familiar programming examples and describes the research questions that drew him into the topic. The conversation follows attacks across language ecosystems, discusses the possible impact of accepting untrusted serialized objects, and considers ways to reduce exposure. Bill also shares how an assessor might recognize serialized data, investigate application behavior, and use an intercepting proxy during testing. Alongside his work in the .NET security community, this archive conversation captures practitioners working through a difficult vulnerability class and debating the limits of their tools and assumptions.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Bill Sempf:→ Bill Sempf’s developer profileMentioned in this episode:→ OWASP Top 10 project repository→ ZAP→ Burp SuiteFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Insecure deserialization with Bill Sempf01:14 Bill’s security origin story06:54 Filling gaps in .NET security guidance08:05 Why deserialization entered the 2017 Top 1010:48 Researching examples across platforms12:22 Serialization and deserialization explained15:54 The impact of malicious serialized objects17:35 Reducing deserialization risk23:09 ViewState and framework considerations24:37 Debating .NET and language-specific behavior27:29 Recognizing serialized data during an assessment28:53 Investigating with intercepting proxies30:31 What testing tools can find
Embed this episode
What this episode covers
What happens when data arriving at an application is allowed to recreate objects and trigger unexpected behavior? Bill Sempf joins Chris and Robert to unpack insecure deserialization, a new category in the 2017 OWASP Top 10. He explains serialization through familiar programming examples and describes the research questions that drew him into the topic. The conversation follows attacks across language ecosystems, discusses the possible impact of accepting untrusted serialized objects, and con...
Ready to play
Bill Sempf -- Insecure Deserialization
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.