Shooting yourself in the feet with php
2019-04-06, 13:00–13:40, SkyPoint

PHP object injection attack review with examples and demos.


In this talk I'm going to uncover php deserialization mechanism and how it can be used to hack web applications. Every exploitation will be demonstrated in real time using prepared lab and debugger. Minimal php knowledge required for better understanding.