Gabriel Lawrence and Chris Frohoff detailed how applications that deserialize attacker-controlled objects can be manipulated to alter state, bypass business logic, or execute arbitrary code. The issue spans Java, Python, PHP, Ruby, and JSF implementations where serialized data is accepted through cookies, tokens, caches, RPC streams, or client-side ViewState values.
Examples include tampering with Java and Python serialized cookies, abusing PHP serialized objects in Memcache, modifying JSF ViewState expression-language data, and targeting Java deserialization exposed through MyFaces ViewState and RMI Registry. The presentation demonstrated tools such as ysoserial and ViewStateMesser and recommends eliminating open-ended deserialization, allowlisting permitted classes and types, authenticating data before deserialization, hardening exposed services, and retaining session state server-side where feasible.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Gabriel Lawrence and Chris Frohoff presented “Marshalling Pickles,” a talk surveying insecure serialization and deserialization vulnerabilities, exploitation techniques and tools, and mitigations across several languages and frameworks.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.