Software supply chains grow more complex every day, bringing new risks from open-source dependencies. While malware attacks are the more trendy supply chain threat, many organizations still struggle with existing software vulnerabilities for legacy libraries. The best way to defend your organization is to understand what hackers are looking for and exploiting, so in this session we will demonstrate achieving Reverse Code Execution by exploiting a Java deserialization vulnerability. You will learn how deserialization works, what Java language semantics allow for this category of attack, and witness how a malicious JAR file can be used as an entrypoint to an organization-wide threat. After understanding the exploit, we will review strategies to remediate and reduce the attack surface of similar attacks.
Session Presented by: