Improving Insecure Deserialization Discovery in Web Applications

dc.contributor.advisorDjenouri, Djamel
dc.contributor.authorAlmuaddi, Ahmed
dc.date.accessioned2023-11-21T09:55:22Z
dc.date.available2023-11-21T09:55:22Z
dc.date.issued2023-10-25
dc.description.abstractInsecure deserialization vulnerability has posed a persistent threat to backend systems and web applications since 2004, exposing devastating exploits such as remote code execution and privilege escalation. A significant challenge for testing for this vulnerability is the reliability of feed-back obtained from the tested target which made detecting the vulnerability difficult. This project aims to address this issue by introducing a novel method to provide a viable feedback mechanism that should show success or failure of attack and thus, improve the accuracy of testing. Our pro-posed tool addresses the lack of reliability issue by applying the blind approach on testing insecure deserialization. This mechanism removes the need for readable feedback from the target and instead relies on the behaviour of the target to determine the success or failure of the approach. This pro-vides a much more precise assessment of attack success or failure, thus improving the overall relia-bility of vulnerability detection. This was observable in my tests where the tool provided the out-come of the test. The tool also performed internal port scanning, which could be a serious vulnera-bility. In conclusion, the feedback mechanism introduced in this project shows the severity of Inse-cure deserialization, as well as the opportunity to automate the scanning process. Keywords: Serialization; RMI; RCE; CVE; OWASP; NIST; NVD; SQL; Gadgets; Bytestream; Magic Method; Transformers.
dc.format.extent18
dc.identifier.urihttps://hdl.handle.net/20.500.14154/69756
dc.language.isoen
dc.publisherSaudi Digital Library
dc.subjectSerialization
dc.subjectRMI
dc.subjectRCE
dc.subjectCVE
dc.subjectOWASP
dc.subjectNIST
dc.subjectNVD
dc.subjectSQL
dc.subjectGadgets
dc.subjectBytestream
dc.subjectMagic Method
dc.subjectTransformers.
dc.titleImproving Insecure Deserialization Discovery in Web Applications
dc.typeThesis
sdl.degree.departmentComputing and Creative Technology
sdl.degree.disciplineCyber Security
sdl.degree.grantorUniversity of the West of England
sdl.degree.nameMaster's Degree

Files

Copyright owned by the Saudi Digital Library (SDL) © 2025