Back to Blog
Finding and Exploiting .NET Remoting over HTTP using Deserialisation
Articleās PDF file: https://soroush.me/downloadable/finding_and_exploiting_dotnet_remoting_over_http_using_deserialisation.pdf
I have published a blog post in NCC Groupās website to explain how to test deserialisation issues within the SOAP requests that are used by ASP.NET Remoting over a HTTP channel:
This research is accompanied by an open source project that show a sample vulnerable server and a client that can be useful for testing purposes: https://github.com/nccgroup/VulnerableDotNetHTTPRemoting/
This entry was posted in Security Posts
Creation date: March 26, 2019