PortSwigger Labs by Desdes
search
⌘Ctrlk
PortSwigger Labs by Desdes
  • 👋Bienvenid@!
  • WebSockets
  • Insecure deserialization
    • Lab: Modifying serialized objects
    • Lab: Modifying serialized data types
    • Lab: Using application functionality to exploit insecure deserialization
    • Lab: Arbitrary object injection in PHP
    • Lab: Exploiting Java deserialization with Apache Commons
    • Lab: Exploiting PHP deserialization with a pre-built gadget chain
    • Lab: Exploiting Ruby deserialization using a documented gadget chain
    • Lab: Developing a custom gadget chain for Java deserialization
    • Lab: Developing a custom gadget chain for PHP deserialization
    • Lab: Using PHAR deserialization to deploy a custom gadget chain
  • GraphQL API vulnerabilities
  • Server-side template injection
  • Web cache poisoning
  • HTTP Host header attacks
  • HTTP request smuggling
  • OAuth authentication
  • JWT attacks
  • Prototype pollution
  • Essential skills
gitbookCon tecnología de GitBook
block-quoteEn esta páginachevron-down

Insecure deserialization

Lab: Modifying serialized objectschevron-rightLab: Modifying serialized data typeschevron-rightLab: Using application functionality to exploit insecure deserializationchevron-rightLab: Arbitrary object injection in PHPchevron-rightLab: Exploiting Java deserialization with Apache Commonschevron-rightLab: Exploiting PHP deserialization with a pre-built gadget chainchevron-rightLab: Exploiting Ruby deserialization using a documented gadget chainchevron-rightLab: Developing a custom gadget chain for Java deserializationchevron-rightLab: Developing a custom gadget chain for PHP deserializationchevron-rightLab: Using PHAR deserialization to deploy a custom gadget chainchevron-right
AnteriorLab: Cross-site WebSocket hijackingchevron-leftSiguienteLab: Modifying serialized objectschevron-right

Última actualización hace 2 años