Vickie Li
1 min readSep 24, 2019

--

Thanks for your kind words Rohit! The easiest way to find deserialization bugs would be source code analysis. As for black-box methods, they would really depend on the language and library the application uses. I would say determining that is the first step, then look at commonly vulnerable functionalities like cookies.

--

--

Vickie Li
Vickie Li

Written by Vickie Li

Professional investigator of nerdy stuff. Hacks and secures. Creates god awful infographics. https://twitter.com/vickieli7

No responses yet