Java Deserializaon A0acks - OWASP

private String command; … public final Object readObject(ObjectInputStream ois) ... (of class to deserialize) ... – Use other formats instead of serialized objects: JSON, XML, etc. • But be aware of XML-based deserialization attacks via XStream, XmlDecoder, etc. ... ................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download