Burp Suite User Forum

Create new post

java deserialize

Kelley | Last updated: May 09, 2017 08:22PM UTC

Hello - I am currently testing Oracle E-Business Suite that has a mix of normal HTTPS traffic with params and also HTTPS traffic that has the params java serialized. Is there way to deserialize the object to XML or some other readable format to then scan/fuzz with Burp. Looking at the options online, I can't seem to get any of the options out there to work correctly and I'm not seeing a plugin in the store that just does the deserialization to readable request format. Thanks!

PortSwigger Agent | Last updated: May 10, 2017 10:39AM UTC

Burp doesn't natively support automatic deserializing of Java objects, sorry. If someone does have, or wants to create, an extension for this purpose, we'd be happy to include it in the BApp Store.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.