1. Web Security Academy
  2. Insecure deserialization
  3. Exploiting
  4. Lab

Lab: Modifying serialized data types

PRACTITIONER

This lab uses a serialization-based session mechanism and is vulnerable to authentication bypass as a result. To solve the lab, edit the serialized object in the session cookie to access the administrator account. Then, delete Carlos.

You can log in to your own account using the following credentials: wiener:peter