On this week's show we get into a serious technical discussion about
deserialisation attacks with with one of Adam Boileau's colleagues, Brendan
Jamieson about the biggest issue in infosec that no one is talking about --
deserialisation vulnerabilities and their exploitation.
This attack class is a serious problem in enterprise environments thanks to
the release of the YSoSerial tool about a year ago. Pen-testers who are
across this bug class are finding issues everywhere they look, and hardly
anyone is talking about it. But we do, this week.
read more [1]
[1] http://risky.biz/RB401