PentesterLab – Serialize Badge
General writeup notes for Pentesterlab's Serialize badge. This post does not contain any spoilers. This is just information collected by me to understand the exercises better.
TODO
– XMLDecoder
– CVE-2016-0792
– ObjectInputStream
– CVE-2013-0156: Rails Object Injection
– API to Shell