Started reading it, pretty good so far! Only thing, why did you choose to introduce block cipher modes in the stream cipher chapter? This makes little sense to me.
As a pen tester, I wholeheartedly disagree. It’s probably more common to see unsafe YAML deserialization, rather than directly deserializing marshaled Ruby objects, but both are impactful and these types of…
That is fully captured in the notion of a universal deserialization gadget chain. However, for those not familiar with the concept of gadgets, yes, I can see how it might be a bit confusing at first.
Started reading it, pretty good so far! Only thing, why did you choose to introduce block cipher modes in the stream cipher chapter? This makes little sense to me.
As a pen tester, I wholeheartedly disagree. It’s probably more common to see unsafe YAML deserialization, rather than directly deserializing marshaled Ruby objects, but both are impactful and these types of…
That is fully captured in the notion of a universal deserialization gadget chain. However, for those not familiar with the concept of gadgets, yes, I can see how it might be a bit confusing at first.