Back to Skills

deserialization-insecure

Insecure deserialization playbook. Use when Java, PHP, or Python applications deserialize untrusted data via ObjectInputStream, unserialize, pickle, or similar mechanisms that may lead to RCE, file access, or privilege escalation.

1,292stars177forksUpdated 7/6/2026

Security Assessment

Critical Risk(10/100)

Detected risks:

Agent-reviewed override(Offensive attack playbook (RCE via Java/PHP/Python gadget chains — ysoserial, Shiro SHIRO-550, WebLogic T3, pickle). Import attached no SKILL.md so the assessor defaulted to safe; scored manually from the real GitHub content (fetched, enriched here). Genuine offensive tooling, per gotcha #7.)
Security Score10/100

About deserialization-insecure

An insecure-deserialization attack playbook for authorized security testing, spanning Java, PHP, Python, .NET, and Ruby. It focuses on the practical gap between finding a deserialization sink and landing a working gadget chain. The guidance begins with traffic fingerprinting: recognising serialized data by its magic bytes and encodings across cookies, POST bodies, headers, and message queues (Java's AC ED and its Base64 form, the PHP object pattern, Python pickle protocol markers, and .NET/Ruby signatures). For Java it walks through ysoserial-based exploitation, choosing among the CommonsCollections, Spring, Groovy, and Hibernate chains, and using the DNS-only URLDNS chain as a damage-free confirmation probe before escalating. Framework-specific sections cover Apache Shiro rememberMe (SHIRO-550 / CVE-2016-4437) and its known default keys, WebLogic over the T3 and IIOP protocols and via XMLDecoder (CVE-2017-10271), and the Java RMI registry, alongside a JDK-version matrix explaining when remote class loading is available or must be bypassed. PHP coverage explains the unserialize magic-method chain and PHAR attacks; Python coverage addresses pickle abuse. A companion reference adds a gadget-chain version-compatibility matrix and further formats such as SnakeYAML, Hessian, Kryo, XStream, and .NET ViewState. It is intended for penetration testers and security researchers working under authorization.

FAQ

Which languages and serialization formats does it cover?

Java (ObjectInputStream), PHP (unserialize/PHAR), and Python (pickle) as primary targets, with notes on .NET ViewState and Ruby YAML plus formats like SnakeYAML, Hessian, Kryo, and XStream.

How do you confirm the vulnerability without causing damage?

Use the URLDNS gadget chain, which triggers only a DNS lookup and no code execution; a hit on your collaborator/DNSLog domain confirms the sink before escalating.

What tools does the playbook rely on?

Primarily ysoserial for Java gadget-chain payloads (including its RMI exploit module), with references to PHPGGC for PHP and ysoserial.net/Blacklist3r for .NET ViewState.

How does the JDK version affect exploitation?

It includes a matrix showing remote class loading via RMI/LDAP works before 8u121, is partially restricted through 8u190, and is blocked from 8u191 onward, after which an LDAP-returns-gadget approach is needed.

Is this for offensive or defensive use?

It is an offensive/pentesting playbook for authorized assessments; defenders can reuse its fingerprints and CVE references to prioritize patching and detection.

Install deserialization-insecure

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill