Lead AI Strategy with UCSB's Agentic AI Program — Microsoft Certified
Python, Prompt Engineering, Data Science — Build the Skills Employers Want Now
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Learn about Java deserialization vulnerabilities and their security implications in this conference talk from Devoxx Poland 2023. Explore why deserialization exploits pose significant threats to Java applications and understand the mechanisms behind these attacks. Discover how malicious actors can leverage deserialization processes to execute arbitrary code, compromise system integrity, and gain unauthorized access to sensitive data. Examine real-world examples of deserialization vulnerabilities and their potential impact on enterprise applications. Understand the technical details of how serialized objects can be manipulated to create security breaches and learn to identify vulnerable code patterns in your applications. Gain practical knowledge about defensive programming techniques, secure coding practices, and mitigation strategies to protect against deserialization attacks. Review industry best practices for handling serialized data safely and explore alternative approaches to object serialization that reduce security risks. Understand the importance of input validation, object filtering, and proper security controls when working with serialized data in Java environments.
Syllabus
Deserialization exploits in Java: why should I care? • Brian Vermeer • Devoxx Poland 2023
Taught by
Devoxx Poland