Skip to content

[Java] I've written a rule, but it's a bit flawed and doesn't fully check out the entire path of request->bytes. #334

Answered by smowton
SummerSec asked this question in Q&A
Discussion options

You must be logged in to vote

This looks like it's working fine -- the source at getValue is detected, base64Decode is known to propagate taint, then Tools.deserialize is recognised as the sink. What's the problem?

Replies: 1 comment 9 replies

Comment options

You must be logged in to vote
9 replies
@SummerSec
Comment options

@SummerSec
Comment options

@SummerSec
Comment options

@smowton
Comment options

@SummerSec
Comment options

Answer selected by SummerSec
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants