Understanding Java RMI: Implementation and Security Considerations

What is RMI? Remote Method Invocation (RMI) is a Java-native mechanism that enables method calls between different JVM processes. Unlike generic RPC frameworks, RMI is purpose-built for Java environments, allowing objects in one virtual machine to invoke methods on objects residing in another JVM across the network. The communication backbone o ...

Posted on Tue, 15 Sep 2026 16:39:08 +0000 by Mr Camouflage

Understanding and Mitigating Cross-Site Request Forgery (CSRF) Attacks in Web Applications

Cross-Site Request Forgery (CSRF), often pronounced "sea-surf", is a type of malicious exploit where unauthorized commands are transmitted from a user that the web application trusts. Attackers trick a user's browser into sending a forged request to a vulnerable web application where the user is currently authenticated. Since request ...

Posted on Sun, 16 Aug 2026 16:03:28 +0000 by gilbertwang

Understanding HttpSecurity Architecture in Spring Security

Spring Security fundamentally operates as a filter chain This filter chain follows the responsibility chain design pattern HttpSecurity In earlier versions of Spring Security, configuration was done through XML files using the <http> tag to define HTTP request security settings like user permissions. However, with Spring Boot projects, ...

Posted on Wed, 12 Aug 2026 16:45:14 +0000 by chet139

Exploiting Shiro RememberMe Deserialization for Webshell Creation

Exploiting Shiro RememberMe Deserialization for Webshell Creation Modifying ysoserial for Java Code Execution Payloads The default implementation in ysoserial can be enhanced to support direct Java code execution. Below is the modified code that checks if the command parameter starts with "code:" to determine whether to execute a system comma ...

Posted on Sun, 26 Jul 2026 16:34:58 +0000 by philweb

SQL Injection Concepts and Prevention Techniques

Understanding SQL Injection SQL injection is a prevalent form of cyber attack that exploits vulnerabilities in database query construction. It typical occurs when user input is directly concatenated into SQL queries without proper validation or sanitization, allowing attackers to manipulate SQL logic or execute arbitrary commands. Example of SQ ...

Posted on Fri, 15 May 2026 13:00:35 +0000 by Asperon