AppSec Tales XXIV | Deserialization

Karol Mazurek
5 min readDec 13, 2023

Application Security Testing for Insecure Deserialization vulnerabilities.

INTRODUCTION

The article explains how to test for Insecure Deserialization vulnerabilities when a website deserializes user-supplied data.

Serialization (marshalling or pickling) converts complex data structures, such as objects and their fields, into a “flatter” format…

--

--