<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>XStream Deserialization on bokkapig</title><link>https://bokkapig.pages.dev/tags/xstream-deserialization/</link><description>Recent content in XStream Deserialization on bokkapig</description><generator>Hugo</generator><language>en-gb</language><lastBuildDate>Sat, 21 Feb 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://bokkapig.pages.dev/tags/xstream-deserialization/index.xml" rel="self" type="application/rss+xml"/><item><title>Interpreter</title><link>https://bokkapig.pages.dev/writeups/interpreter/</link><pubDate>Sat, 21 Feb 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/interpreter/</guid><description>Pre-auth RCE via CVE-2023-43208 XStream deserialization in Mirth Connect 4.4.0, lateral movement through MySQL credential extraction and password hash replacement, privilege escalation via Python eval() injection in an internal Flask notification app running as root.</description></item></channel></rss>