Insecure Deserialization Attack — TryHackMe Walkthrough

Published: 22 August 2025
on channel: In Phu Sec Lab
1,122
20

TryHackMe's Web App PenTest -- Insecure Deserialization: https://tryhackme.com/room/insecurede...

In this episode of inphuseclab, we continue our series on TryHackMe's web application testing, focusing on insecure serialization. We'll cover the basics of serialization in web applications, common vulnerabilities, and real-world examples like the Log4J and Jenkins Java de-serialization flaws. Learn how to identify, exploit, and mitigate these vulnerabilities in different programming languages, including PHP, Python, and Java. We also explore automated tools like PHPGGC and Ysoserial for efficient testing. This video aims to enhance your web application security skills and help you understand the complexities of insecure serialization.

00:00 Introduction
01:55 Some Basic Concepts
06:58 Serialization Formats
15:45 Identification
25:27 Exploitation - Object Injection
33:31 Automation Script
52:23 Mitigation
54:30 Conclusion


On this page of the site you can watch the video online Insecure Deserialization Attack — TryHackMe Walkthrough with a duration of hours minute second in good quality, which was uploaded by the user In Phu Sec Lab 22 August 2025, share the link with friends and acquaintances, this video has already been watched 1,122 times on youtube and it was liked by 20 viewers. Enjoy your viewing!