Burp Suite User Forum

Create new post

Pentesting serialized PHP objects

Chris | Last updated: Aug 01, 2016 07:02PM UTC

Hello, Can you please tell me an efficient way to test base64 encoded PHP serialized objects? Recently I see this scheme very often. Is there any extension for that? (I have the PRO version) Thank you

Liam, PortSwigger Agent | Last updated: Aug 04, 2016 04:51PM UTC

Hi Chris Thanks for your message. Burp passively scans for this vulnerability - "Serialized object in HTTP message". - https://portswigger.net/KnowledgeBase/Issues/Details/00400900_SerializedobjectinHTTPmessage Exploiting the issue can be a lengthy manual process. This blog contains a section providing a brief overview of some exploitation methods: - https://securitycafe.ro/2015/01/05/understanding-php-object-injection/ Please let us know if you need any further assistance.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.