.NET Rocks! cover image

Hacking APIs with Dana Epp

.NET Rocks!

00:00

Using Serialization and Deserialization Attacks to Defend Your APIs

As an attacker I like to see that because then I can extract more information quickly. It's not just for denial of service type attacks but abuse being able to modify or manipulate there's things like Wysos serial dot net which is a dot net payload generator for deserialization attacks. If you know how it works you can actually generate payloads that can give you reverse shells from your API simply by knowing how to how to cause a deserialization attack.

Play episode from 46:42
Transcript

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app