Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Bill Sempf -- Insecure Deserialization

34 min2 februari 2018

Om avsnittet

What happens when data arriving at an application is allowed to recreate objects and trigger unexpected behavior? Bill Sempf joins Chris and Robert to unpack insecure deserialization, a new category in the 2017 OWASP Top 10. He explains serialization through familiar programming examples and describes the research questions that drew him into the topic. The conversation follows attacks across language ecosystems, discusses the possible impact of accepting untrusted serialized objects, and considers ways to reduce exposure. Bill also shares how an assessor might recognize serialized data, investigate application behavior, and use an intercepting proxy during testing. Alongside his work in the .NET security community, this archive conversation captures practitioners working through a difficult vulnerability class and debating the limits of their tools and assumptions.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Bill Sempf:
Bill Sempf’s developer profile

Mentioned in this episode:
OWASP Top 10 project repository
ZAP
Burp Suite

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Insecure deserialization with Bill Sempf
01:14 Bill’s security origin story
06:54 Filling gaps in .NET security guidance
08:05 Why deserialization entered the 2017 Top 10
10:48 Researching examples across platforms
12:22 Serialization and deserialization explained
15:54 The impact of malicious serialized objects
17:35 Reducing deserialization risk
23:09 ViewState and framework considerations
24:37 Debating .NET and language-specific behavior
27:29 Recognizing serialized data during an assessment
28:53 Investigating with intercepting proxies
30:31 What testing tools can find

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.