PHP Serialization Pollution Attack

Written by AbiusX on . Posted in Computer, English, Security

PHP Serialization has a fatal flaw which allows for pollution of the scope and global context of an application, as well as running arbitrary code in some scenarios if sources of taint are allowed in. It is a very high impact attack but requires in-depth evaluation criteria and careful inspection to be caught.
I have prepared a lab to explore and try this attack, available at:

PHP Serialization Pollution Lab

Give it a try and let me know what you think. I suggest you do a lot of debugging on the code and master its exact running flow. Don't forget that the source code of that page is available at:

I'm gonna describe this with details in a much later date.

Tags: , , , , , , ,

Trackback from your site.

Comments (4)

  • Hessam


    My solution :
    we send this serialized data to overwrite sessions through the __destruct() function:


    Afterward we can login with “admin” username and “1337” password.


  • masood


    please fix this page :

    PHP Serialization Pollution Lab(404 NOT found ERROR)


    • AbiusX


      Apparently because of the new website structure I can’t :D It poses a security risk!


  • abhiyall


    can u please share the source


Leave a comment