Hmm, I thought it was going to inspect an arbitrary object graph recursively looking for a property to place the payload. How does it find the entrypoint? Btw, nice finding with TinyWall!
-
-
-
Yep, that's how I understood it. If you call the program with "file" the deserialization should trigger an exception but deserialize. If you put it into an object's member of Message instead (via calling "graph"), deserialization takes place quietly thanks to graph inspection.
- Još 1 odgovor
Novi razgovor -
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.