166 terms · 75/46/45
kompozit · edukator režim · za predavanje i PDF

Insecure Deserialization

Pretnja u centru, tehnike kojima se izvodi levo, odbrane koje je suzbijaju desno. Ispod — mapa faza napada: kojom tehnikom se ulazi i koja odbrana je presreće.

↘ Techniques used to carry it out2

Techniques used to carry it out. Klik vodi na stranicu pojma.

threat · № 046 · applications

Insecure Deserialization

Deserialization is the return of a packed object into a form the application can use. The problem arises when an application accepts an object from an untrusted source and handles it as though it were safe. At that point the attacker is not sending mere data but a specially prepared structure that can change the flow of execution.

↓ mapa faza · kojom tehnikom se ulazi, koja odbrana presreće
faza · ubacivanje · tehnika Posebno pripremljen serijalizovan objekat
presreće · odbrana Izbegavanje deserijalizacije nepoverljivih podataka · validacija · potpisivanje
faza · izvršavanje · tehnika Gadget chain, promena logike ili izvršavanje koda
presreće · odbrana Patch biblioteka · sandbox · ograničen skup dozvoljenih tipova
faza · uporište · tehnika Dalji pristup serveru ili eskalacija
presreće · odbrana Least privilege · EDR · logging-monitoring

↗ How it is defended against4

How it is defended against. Klik vodi na stranicu pojma.