
Bill Sempf -- Insecure Deserialization
Om avsnittet
What happens when data arriving at an application is allowed to recreate objects and trigger unexpected behavior? Bill Sempf joins Chris and Robert to unpack insecure deserialization, a new category in the 2017 OWASP Top 10. He explains serialization through familiar programming examples and describes the research questions that drew him into the topic. The conversation follows attacks across language ecosystems, discusses the possible impact of accepting untrusted serialized objects, and considers ways to reduce exposure. Bill also shares how an assessor might recognize serialized data, investigate application behavior, and use an intercepting proxy during testing. Alongside his work in the .NET security community, this archive conversation captures practitioners working through a difficult vulnerability class and debating the limits of their tools and assumptions.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Bill Sempf:
→ Bill Sempf’s developer profile
Mentioned in this episode:
→ OWASP Top 10 project repository
→ ZAP
→ Burp Suite
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Insecure deserialization with Bill Sempf
01:14 Bill’s security origin story
06:54 Filling gaps in .NET security guidance
08:05 Why deserialization entered the 2017 Top 10
10:48 Researching examples across platforms
12:22 Serialization and deserialization explained
15:54 The impact of malicious serialized objects
17:35 Reducing deserialization risk
23:09 ViewState and framework considerations
24:37 Debating .NET and language-specific behavior
27:29 Recognizing serialized data during an assessment
28:53 Investigating with intercepting proxies
30:31 What testing tools can find
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.