Sven Morgenroth, Netsparker
Sven will talk about PHP Object injection vulnerabilities and explain the dangers of PHP's unserialize function. He will show the format of serialized PHP Objects, explain PHP's magic methods and how to write an exploit for a PHP Object Injection vulnerability during his technical demo.
Full Show Notes: https://wiki.securityweekly.com/Episode584
To learn more about Netsparker, go to: https://www.netsparker.com/securityweekly
Hosts



Jeff Man
Sr. InfoSec Consultant – Online Business Systems at Online Business Sytems

Larry Pesce
Product Security Research and Analysis Director at Finite State