Overview
When an application unserializes data it did not create, an attacker can inject an object whose magic methods trigger file writes, database calls or command execution.\nPHP, Java, Python and .NET all have known gadget chains, so the fix is never to deserialize untrusted input.\nSigned tokens or explicit data-mapping formats such as JSON are the safe alternatives.
Indicators of Compromise
Signals that suggest this is present on a system.
- base64 blobs containing O: or similar type markers
- Session payloads that are not plain JSON
- Unexpected objects appearing after cookie edits
Controls that stop it
-
Validate and Constrain All Input
Treat every request as hostile. Reject anything that does not match an allow list, enforce type, length, range and format, and canonicalise before you validate so encoded bypasses cannot slip through. For file uploads, re-encode the image, randomise the name, strip metadata and store outside the web root on a domain that cannot execute code.