Skip to Content
ASP.NET Core 5 Secure Coding Cookbook
book

ASP.NET Core 5 Secure Coding Cookbook

by Roman Canlas
July 2021
Intermediate to advanced
324 pages
5h 35m
English
Packt Publishing
Content preview from ASP.NET Core 5 Secure Coding Cookbook

Chapter 9: Insecure Deserialization

.NET has full support for serialization and deserialization of data. This language feature allows ASP.NET Core web applications to convert in-memory objects into a stream of bytes (serialize) and rebuild these byte streams back to an object (deserialize). Serialization makes the transfer, storage, and caching of data possible, as well as state persistence between systems.

In the process of deserialization, the data format can be either JavaScript Object Notation (JSON) or Extensible Markup Language (XML), and it can also be in binary format. However, as with any input type, the data source can be untrustworthy or tampered with before it gets deserialized back into a web application as an in-memory object. ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Hands-On RESTful Web Services with ASP.NET Core 3

Hands-On RESTful Web Services with ASP.NET Core 3

Samuele Resca
ASP.NET Core and Vue.js

ASP.NET Core and Vue.js

Devlin Basilan Duldulao
ASP.NET Core Security

ASP.NET Core Security

Christian Wenz

Publisher Resources

ISBN: 9781801071567Supplemental Content