Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

While working on the serialize vulnerability, I (Jacques Le Roux) stumbled upon this article "Closing the open door of java object serialization" and found notsoserial was a better Java agent than the one I introduced at r1717058. Because it easily protects you from all possible serialize vulnerabilities as explained here! So I replaced contrast-rO0.jar by notsoserial-1.0-SNAPSHOT at r1730735 + r1730736. To be safe in case you use RMI for instance, use one of the start*-secure ant targets or use the JVM arguments those targets use.

...