Vickie Li
1 min readSep 29, 2019

--

Hi Xinxing, thanks for your kind words. It generally doesn’t matter what the intended object type is or if you can get a hold of the source code or not. As long as it’s a serialized object that you can control, it’s worth testing out. Although if you can’t read the source code, exploitation would require more time and effort once the vulnerability is confirmed.

--

--

Vickie Li
Vickie Li

Written by Vickie Li

Professional investigator of nerdy stuff. Hacks and secures. Creates god awful infographics. https://twitter.com/vickieli7

Responses (1)