Back to Browse

Exploiting a Java Deserialization Vulnerability using Burp Suite

44.4K views
Apr 12, 2018
6:52

I couldn't find a good video on how to exploit deserialization vulnerabilities using Burp Suite so I made one. This is an example of discovering and exploiting a known deserialization vulnerability in an old version of JBoss (based on https://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/) using Burp Suite Pro (https://portswigger.net/burp), the Java Deserialization Scanner extension (https://techblog.mediaservice.net/2017/05/reliable-discovery-and-exploitation-of-java-deserialization-vulnerabilities/) and ysoserial (https://github.com/frohoff/ysoserial).

Download

0 formats

No download links available.

Exploiting a Java Deserialization Vulnerability using Burp Suite | NatokHD