Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Php deserialization vulnerability

Shulou Source: shulou.com Published: 2022-06-01 08:27:18 10月03日 Update

0x00 serialization

All values in php can be represented by using the function serialize () to return a string containing a stream of bytes. The unserialize () function can change the string back to the original value of php. Serializing an object will save all the variables of the object, but not the method of the object, only the name of the class. All values in php can use functions.

Serialize ()

To return a string containing a byte stream to represent.

Unserialize ()

Function can change the string back to the original value of php. Serializing an object will save all the variables of the object, but not the method of the object, only the name of the class.

An example of serialization

Tags: Sequences objects methods variables characters magic functions strings examples properties vulnerabilities that is code time results parameters two number name instance Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Linux OPPO Reno Shulou Information Apple macOS