← All concepts
Insecure deserialization

Understanding Insecure deserialization

What it is

Deserialization rebuilds an object from bytes. When those bytes come from the client and the format can encode types or behaviour, a crafted payload can make the server construct objects it never meant to — changing state, or in the worst case running code, the moment it reads them.

How you approach it

  1. Find a value that looks encoded rather than plain — base64, a token, a blob in a cookie. Decode it. Is it a serialized object?
  2. Change one field and re-encode it. Does the server trust what you changed? That trust is the whole vulnerability.
  3. The flag is behind a property the object was not supposed to let you set. Set it.

How it gets fixed

The app deserialized attacker-controlled bytes and trusted the object that came out. Editing a field before re-encoding changed server-side state directly, because nothing re-validated the reconstructed object. The fix is to sign serialized state, or avoid deserializing untrusted formats at all.

Practise it

Every lab in the Insecure deserialization category drills exactly this. Start at Apprentice and work up.

Practise it

PractitionerInsecure deserialization

The role hidden in a base64 cookie

Feed the server a serialized object it will trust and rebuild.

25 pts · 45 minStart →
PractitionerInsecure deserialization

A serialized cart the client can edit

Feed the server a serialized object it will trust and rebuild.

25 pts · 45 minStart →
ExpertInsecure deserialization

Tampering with a signed-but-unverified token

Feed the server a serialized object it will trust and rebuild.

50 pts · 90 minStart →
ExpertInsecure deserialization

Type confusion in a rebuilt object

Feed the server a serialized object it will trust and rebuild.

50 pts · 90 minStart →
MasterInsecure deserialization

A gadget chain to state change

Feed the server a serialized object it will trust and rebuild.

100 pts · 180 minStart →
MasterInsecure deserialization

From deserialization to file write

Feed the server a serialized object it will trust and rebuild.

100 pts · 180 minStart →