Hunting Java Deserialization Gadget Chains

Hunt Java deserialization that turns an untrusted byte stream into code execution: attacker-controlled data reaching readObject, an ObjectInputStream, or a framework endpoint that deserializes, with a gadget on the classpath whose readObject or finalizer drives a property-oriented chain to a dangerous call. Covers native serialization, JNDI lookups reached through deserialized objects, and framework entry points that accept a serialized object over HTTP, a message queue, a cache, or a cookie. Use when a service reads serialized Java objects it did not produce and reachable library versions carry a known gadget. The untrusted serialized stream is the source, the deserialization call is the sink, and the gadget chain from readObject to a runtime or naming call is the bug.

UnboundCompute e377a4c 9.0 KB Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/hunting-java-deserialization-gadget-chains commit e377a4c06d

Frequently asked questions

npx skillmds@latest add unboundcompute/hunting-java-deserialization-gadget-chains