Open cardosec

Case 89C340 · Web AppSec · L3 Applied

Insecure Deserialization

Practise as: Explain it
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Deserializing untrusted data can instantiate arbitrary types and trigger code during object reconstruction
  2. Gadget chains (e.g. ysoserial for Java, Commons Collections) chain existing classes into RCE
  3. Risky APIs: Java ObjectInputStream, .NET BinaryFormatter, Python pickle, PHP unserialize, Ruby Marshal
  4. Fix: use data-only formats like JSON with schema validation; never deserialize native objects from clients
  5. If unavoidable: type allowlists (Java ObjectInputFilter, JEP 290), integrity signing, and isolated processes

If the interviewer pushes back

  • Why does signing a serialized blob help, and what key management mistake would undo it?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.