YoVDO

Implicit and Mutation-Based Serialization Vulnerabilities in .NET

Offered By: NDC Conferences via YouTube

Tags

Cybersecurity Courses MongoDB Courses Vulnerability Analysis Courses Remote Code Execution Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore novel attacks against .NET serialization that bypass current state-of-the-art mitigations in this 44-minute conference talk from NDC Security in Oslo, Norway. Delve into serialization exploits of platforms not using well-known .NET serializers, "mutation" attacks exploiting deserialization even with untampered serialized data, and techniques for bypassing serialization binders. Witness demonstrations of new remote code execution vulnerabilities in MongoDB, LiteDB, ServiceStack.Redis, RavenDB, MartenDB, JSON.Net, and the .NET JavaScriptSerializer. Learn why applications using these platforms and technologies are likely vulnerable due to violations of typical serializer security assumptions. Discover techniques for detecting and mitigating these vulnerabilities, along with best practices for avoidance, as limited platform-level fixes often require additional application-level security measures.

Syllabus

Second Breakfast: Implicit and Mutation-Based Serialization Vulnerabilities in .NET - Jonathan Birch


Taught by

NDC Conferences

Related Courses

Unlocking Information Security II: An Internet Perspective
Tel Aviv University via edX
Cybersecurity Capstone: Breach Response Case Studies
IBM via Coursera
Complete Ethical Hacking Bootcamp
Udemy
Cyber Security Advanced Persistent Threat Defender Preview
Udemy
Performing Threat Modeling with the PASTA Methodology
Pluralsight