How I Used a JSON Deserialization 0day to Steal Your Money on the Blockchain

How I Used a JSON Deserialization 0day to Steal Your Money on the Blockchain

Black Hat via YouTube Direct link

Derivation

7 of 15

7 of 15

Derivation

Class Central Classrooms beta

YouTube videos curated by Class Central.

Classroom Contents

How I Used a JSON Deserialization 0day to Steal Your Money on the Blockchain

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Introduction
  2. 2 Demo
  3. 3 Visualizing the serialized process
  4. 4 Autotype support
  5. 5 Autotype bypass
  6. 6 Magic Method
  7. 7 Derivation
  8. 8 JSONpath
  9. 9 Gen
  10. 10 Tron
  11. 11 ReadWrite
  12. 12 LevelDB
  13. 13 Red File
  14. 14 Read Files
  15. 15 Post Penetration

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.