Videos

Published on November 22nd, 2016 📆 | 1824 Views ⚑

0

Pwning Your Java Messaging With Deserialization Vulnerabilities


iSpeech.org


by Matthias Kaiser

Messaging can be found everywhere. It's used by your favourite Mobile Messenger as well as in your bank's backend system. Message Brokers such as Pivotal's RabbitMQ, IBM's WebSphere MQ and others often form a key component of a modern backend system's architecture. Furthermore, there are various messaging standards in place like AMQP, MQTT, and STOMP. When it comes to the Java World it is rather unknown that Messaging in the Java ecosystem relies heavily on Java's serialization. Recent advances in the exploitation of Java deserialization vulnerabilities can be applied to exploit applications using Java messaging. This talk will show the attack surface of various Java messaging API implementations and their deserialization vulnerabilities. Last but not least, the Java Messaging Exploitation Tool (JMET) will be presented to help you identify and exploit message-consuming systems like a boss.

video, sharing, camera phone, video phone, free, upload
2016-11-22 17:33:52

source





Tagged with:



Comments are closed.