daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

java-jsf-viewstate-faces-deserialization.md (1599B)


      1 ---
      2 title: "Java JSF ViewState Deserialization"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/deserialization/java-jsf-viewstate-.faces-deserialization.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/deserialization/java-jsf-viewstate-.faces-deserialization.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Java JSF ViewState Deserialization
     14 
     15 JavaServer Faces (JSF) may store view state in the client through the `javax.faces.ViewState` parameter. If the application accepts an unauthenticated serialized state without effective integrity protection, a crafted object graph can reach gadget classes on the server's classpath and lead to code execution during deserialization. Exploitability depends on the JSF implementation, its state-saving configuration, cryptographic protection, and available gadgets.<sup>[[1]](#references)</sup>
     16 
     17 The first reference explains the affected configurations and mitigations. The second walks through a practical assessment in which exposed configuration material enabled a protected ViewState to be reproduced.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     18 
     19 ## References
     20 
     21 - [1] [Misconfigured JSF ViewStates can lead to severe RCE vulnerabilities](https://www.alphabot.com/security/blog/2017/java/Misconfigured-JSF-ViewStates-can-lead-to-severe-RCE-vulnerabilities.html)
     22 - [2] [Arkham - Hack The Box writeup (0xRick)](https://0xrick.github.io/hack-the-box/arkham/)