tags:javadeserialization original link: Java Deserialization Tricks
newsletter link: exploits.club Weekly Newsletter 13


Exploits Club Summary:

Synacktiv put together a list of helpful tips and tricks for Java Deserialization, specifically focusing on “once a gadget chain leading to RCE has been identified”. The post centers around how to make your exploit stealthier and avoid detections. The post also links out to other posts Synacktiv has written on the topic, which would serve as a great primer on the topic for anyone unfamiliar with exploiting the vuln class.