JEP 187 (original) (raw)

Peter Firmstone peter.firmstone at zeus.net.au
Thu Jul 10 08:01:33 UTC 2014


The attached code shares the same motivations as JEP 187 and may help establish a baseline.

One more thing we're looking into (for a later release) is trusted class lists to avoid deserialization attacks.

https://issues.apache.org/jira/browse/RIVER-362

http://www.ibm.com/developerworks/java/library/se-lookahead/index.html

Regards,

Peter. -------------- next part -------------- An embedded and charset-unspecified text was scrubbed... Name: Portable.java URL: <http://mail.openjdk.java.net/pipermail/core-libs-dev/attachments/20140710/666d8bfe/Portable.java> -------------- next part -------------- An embedded and charset-unspecified text was scrubbed... Name: PortableFactory.java URL: <http://mail.openjdk.java.net/pipermail/core-libs-dev/attachments/20140710/666d8bfe/PortableFactory.java> -------------- next part -------------- An embedded and charset-unspecified text was scrubbed... Name: PortableObjectInputStream.java URL: <http://mail.openjdk.java.net/pipermail/core-libs-dev/attachments/20140710/666d8bfe/PortableObjectInputStream.java> -------------- next part -------------- An embedded and charset-unspecified text was scrubbed... Name: PortableObjectOutputStream.java URL: <http://mail.openjdk.java.net/pipermail/core-libs-dev/attachments/20140710/666d8bfe/PortableObjectOutputStream.java> -------------- next part -------------- An embedded and charset-unspecified text was scrubbed... Name: PortablePermission.java URL: <http://mail.openjdk.java.net/pipermail/core-libs-dev/attachments/20140710/666d8bfe/PortablePermission.java> -------------- next part -------------- An embedded and charset-unspecified text was scrubbed... Name: PortableObject.java URL: <http://mail.openjdk.java.net/pipermail/core-libs-dev/attachments/20140710/666d8bfe/PortableObject.java> -------------- next part -------------- An embedded and charset-unspecified text was scrubbed... Name: PortableFactoryTest.java URL: <http://mail.openjdk.java.net/pipermail/core-libs-dev/attachments/20140710/666d8bfe/PortableFactoryTest.java> -------------- next part -------------- An embedded and charset-unspecified text was scrubbed... Name: PortableObjectOutputStreamTest.java URL: <http://mail.openjdk.java.net/pipermail/core-libs-dev/attachments/20140710/666d8bfe/PortableObjectOutputStreamTest.java>



More information about the core-libs-dev mailing list