Understanding Insecure deserialization
What it is
Deserialization rebuilds an object from bytes. When those bytes come from the client and the format can encode types or behaviour, a crafted payload can make the server construct objects it never meant to — changing state, or in the worst case running code, the moment it reads them.
How you approach it
- Find a value that looks encoded rather than plain — base64, a token, a blob in a cookie. Decode it. Is it a serialized object?
- Change one field and re-encode it. Does the server trust what you changed? That trust is the whole vulnerability.
- The flag is behind a property the object was not supposed to let you set. Set it.
How it gets fixed
The app deserialized attacker-controlled bytes and trusted the object that came out. Editing a field before re-encoding changed server-side state directly, because nothing re-validated the reconstructed object. The fix is to sign serialized state, or avoid deserializing untrusted formats at all.
Practise it
Every lab in the Insecure deserialization category drills exactly this. Start at Apprentice and work up.