daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (5409B)


      1 ---
      2 title: "Insecure Deserialization"
      3 topic: "Insecure Deserialization"
      4 topicSlug: "insecure-deserialization"
      5 sourcePath: "Insecure Deserialization/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Insecure%20Deserialization/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Insecure Deserialization
     12 
     13 > Serialization is the process of turning some object into a data format that can be restored later. People often serialize objects in order to save them to storage, or to send as part of communications. Deserialization is the reverse of that process -- taking data structured from some format, and rebuilding it into an object - OWASP
     14 
     15 ## Summary
     16 
     17 * [Deserialization Identifier](#deserialization-identifier)
     18 * [POP Gadgets](#pop-gadgets)
     19 * [Labs](#labs)
     20 * [References](#references)
     21 
     22 ## Deserialization Identifier
     23 
     24 Check the following sub-sections, located in other chapters :
     25 
     26 * [Java deserialization : ysoserial, ...](/payloads/insecure-deserialization/java)
     27 * [PHP (Object injection) : phpggc, ...](/payloads/insecure-deserialization/php)
     28 * [Ruby : universal rce gadget, ...](/payloads/insecure-deserialization/ruby)
     29 * [Python : pickle, PyYAML, ...](/payloads/insecure-deserialization/python)
     30 * [.NET : ysoserial.net, ...](/payloads/insecure-deserialization/dotnet)
     31 
     32 | Object Type     | Header (Hex)               | Header (Base64) | Indicators                                                   |
     33 | --------------- | -------------------------- | --------------- | ------------------------------------------------------------ |
     34 | .NET ViewState  | `FF 01`                    | `/w`            | Commonly found inside hidden inputs around HTML forms        |
     35 | BinaryFormatter | `0001 0000 00FF FFFF FF01` | `AAEAAAD`       | Base64 decode and check for the long `FF FF FF FF` sequence. |
     36 | Java Serialized | `AC ED`                    | `rO`            | Base64 decode and check first bytes.                         |
     37 | PHP Serialized  | `4F 3A`                    | `Tz`            | Prefixes like `O:, a:, s:, i:, b:` and length indicators.    |
     38 | Python Pickle   | `80 04 95`                 | `gASV`          | Text: opcodes like `(lp0, S'Test'`.                          |
     39 | Ruby Marshal    | `04 08`                    | `BAgK`          | Base64 decode and look for `\x04\x08` at the start.          |
     40 
     41 ## POP Gadgets
     42 
     43 > A POP (Property Oriented Programming) gadget is a piece of code implemented by an application's class, that can be called during the deserialization process.
     44 
     45 POP gadgets characteristics:
     46 
     47 * Can be serialized
     48 * Has public/accessible properties
     49 * Implements specific vulnerable methods
     50 * Has access to other "callable" classes
     51 
     52 ## Labs
     53 
     54 * [PortSwigger - Modifying serialized objects](https://portswigger.net/web-security/deserialization/exploiting/lab-deserialization-modifying-serialized-objects)
     55 * [PortSwigger - Modifying serialized data types](https://portswigger.net/web-security/deserialization/exploiting/lab-deserialization-modifying-serialized-data-types)
     56 * [PortSwigger - Using application functionality to exploit insecure deserialization](https://portswigger.net/web-security/deserialization/exploiting/lab-deserialization-using-application-functionality-to-exploit-insecure-deserialization)
     57 * [PortSwigger - Arbitrary object injection in PHP](https://portswigger.net/web-security/deserialization/exploiting/lab-deserialization-arbitrary-object-injection-in-php)
     58 * [PortSwigger - Exploiting Java deserialization with Apache Commons](https://portswigger.net/web-security/deserialization/exploiting/lab-deserialization-exploiting-java-deserialization-with-apache-commons)
     59 * [PortSwigger - Exploiting PHP deserialization with a pre-built gadget chain](https://portswigger.net/web-security/deserialization/exploiting/lab-deserialization-exploiting-php-deserialization-with-a-pre-built-gadget-chain)
     60 * [PortSwigger - Exploiting Ruby deserialization using a documented gadget chain](https://portswigger.net/web-security/deserialization/exploiting/lab-deserialization-exploiting-ruby-deserialization-using-a-documented-gadget-chain)
     61 * [PortSwigger - Developing a custom gadget chain for Java deserialization](https://portswigger.net/web-security/deserialization/exploiting/lab-deserialization-developing-a-custom-gadget-chain-for-java-deserialization)
     62 * [PortSwigger - Developing a custom gadget chain for PHP deserialization](https://portswigger.net/web-security/deserialization/exploiting/lab-deserialization-developing-a-custom-gadget-chain-for-php-deserialization)
     63 * [PortSwigger - Using PHAR deserialization to deploy a custom gadget chain](https://portswigger.net/web-security/deserialization/exploiting/lab-deserialization-using-phar-deserialization-to-deploy-a-custom-gadget-chain)
     64 * [NickstaDB - DeserLab](https://github.com/NickstaDB/DeserLab)
     65 
     66 ## References
     67 
     68 * [ExploitDB Introduction - Abdelazim Mohammed(@intx0x80) - May 27, 2018](https://web.archive.org/web/20180527082635/https://www.exploit-db.com/docs/english/44756-deserialization-vulnerability.pdf)
     69 * [Exploiting insecure deserialization vulnerabilities - PortSwigger - July 25, 2020](https://web.archive.org/web/20200725143552/https://portswigger.net/web-security/deserialization/exploiting)
     70 * [Instagram's Million Dollar Bug - Wesley Wineberg - December 17, 2015](https://web.archive.org/web/20151217194413/http://exfiltrated.com/research-Instagram-RCE.php)