Deserialisation Labs
Learn how insecure deserialisation leads to object injection, RCE, and authentication bypass.
Lab 1 - PHP Object Injection (Cookie)
Lab 2 - Magic Method Abuse (__wakeup)
Lab 3 - Authentication Bypass via Deserialisation
Solution