Back to Blog

ASP.NET resource files (.RESX) and deserialization issues

I have recently published a blog post via NCC Group’s website about the deserialization issue by abusing the ASP.NET resource files (.resx and .resources extensions). A number of products were exploited and some file uploaders can also be vulnerable to this type of attack.

In addition to this, the advisories can be seen via:

I had also reported the same vulnerability in Telerik justDecompile and JetBrains dotPeek:

Relevant tweets about this:

This entry was posted in Security Posts

Creation date: August 13, 2018