PortSwigger Labs by Desdes
Ctrlk
  • 👋Bienvenid@!
  • WebSockets
  • Insecure deserialization
    • Lab: Modifying serialized objects
    • Lab: Modifying serialized data types
    • Lab: Using application functionality to exploit insecure deserialization
    • Lab: Arbitrary object injection in PHP
    • Lab: Exploiting Java deserialization with Apache Commons
    • Lab: Exploiting PHP deserialization with a pre-built gadget chain
    • Lab: Exploiting Ruby deserialization using a documented gadget chain
    • Lab: Developing a custom gadget chain for Java deserialization
    • Lab: Developing a custom gadget chain for PHP deserialization
    • Lab: Using PHAR deserialization to deploy a custom gadget chain
  • GraphQL API vulnerabilities
  • Server-side template injection
  • Web cache poisoning
  • HTTP Host header attacks
  • HTTP request smuggling
  • OAuth authentication
  • JWT attacks
  • Prototype pollution
  • Essential skills
Con tecnología de GitBook
En esta página
  1. Insecure deserialization

Lab: Arbitrary object injection in PHP

AnteriorLab: Using application functionality to exploit insecure deserializationSiguienteLab: Exploiting Java deserialization with Apache Commons

Última actualización hace 2 años