Case 89C340 · Web AppSec · L3 Applied
Insecure Deserialization
Practise as: Explain it
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Deserializing untrusted data can instantiate arbitrary types and trigger code during object reconstruction
- Gadget chains (e.g. ysoserial for Java, Commons Collections) chain existing classes into RCE
- Risky APIs: Java ObjectInputStream, .NET BinaryFormatter, Python pickle, PHP unserialize, Ruby Marshal
- Fix: use data-only formats like JSON with schema validation; never deserialize native objects from clients
- If unavoidable: type allowlists (Java ObjectInputFilter, JEP 290), integrity signing, and isolated processes
If the interviewer pushes back
- Why does signing a serialized blob help, and what key management mistake would undo it?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.