TryHackMe Insecure Deserialisation - Full Walkthrough 2025
YouTube transcript, YouTube translate
A quick preview of the first subtitles so you know what the video covers.
Hi everybody. Good morning. I'm doing um uh insecure where is it? Insecure decentralization advanced serverside attack part web application p testing. I noticed this a couple of rooms I didn't do video from them and finishing try to finish. So insecure des serialization get in depth knowledge of the des serialization process and how it poses a vulnerability in web apps of course now we have uh the attack box and machine this is my attack box I start the machine that's the IP of the machine I don't think there is a port 80 but let's try we see what's happening there. Okay, that's fine. I have my um terminal. So, user supply input has cons. This is I think it's a free room. Let's confirm free room. So we can go straight to the lob as you can read. User supplied input has consistently been a catalyst for vulnerabilities posing persistent threat across numerous platform and application exploiting user input from SQL injection to cross-sight scripting is a well known challenge in securing web applications. Another less understood but equally dangerous vulnerability associated with user input is secure drealization. A security decalization exploit occur when an application trust serialized data enough to use it without validating or its authenticity. This trust can lead to disastrous outcomes as attacker manipulate serialized object to achieve remote code execution. But basically same story user input always check user input. Learning objective throughout this room you will gain a comprehensive understanding of the following key concept. How the serialization and derization process work. Potential risk to web application exploitation technique mitigation measures. Uh preox web protocol top 10. You can do this room if you want uh with connected machine. Let's uh go there. So basically uh the whole story of serialization is uh you find it in cookies, you find it in um uh cookies uh application that saves stuff in the database because sometimes the structure of um I have an example here. For example, if you have a data like an array like that, you want to save it.