Weaponizing Perl Serialization Flaws with MetaSploit

Weaponizing Perl Serialization Flaws with MetaSploit

Weaponizing Perl Serialization Flaws with MetaSploit

Talk at the Houston Perl Mongers that walks through the weaponization of CVE-2015-1592 in MovableType.

The metasploit modules and payload generating source code is available here:


Final version merged to metasploit is here:
