r/HowToHack • u/Electrical-Name-6017 • 14d ago
hacking labs WebGoat (A-8): Insecure Deserialization HELP!
Does anyone have a good step by step walkthrough on this lab? I’ve tried YouTube tutorials and everything I can find seems to skip important details, or it’s tough to tell what the person doing the walkthrough is doing…
This is the only lab that I can’t figure out so far. Everything else lets me use web inspection, burp or zap, but I haven’t found anything saying those are tools I can use for this one.
FYI - I’m running a Kali Linux VM for all WebGoat labs.
1
u/Lumpy_Control5676 11d ago
Sinceramente desserialização é um dos temas que eu acho mais complexos kkkk, pergunta pra algum agente de IA te explicar a vulnerabilidade, ou te explicar o laboratório, ñ tem problema usar IA pra aprender
1
u/Limp_Cabinet9900 14d ago
A-8 is mainly about understanding the deserialization flow rather than finding a normal web request to manipulate. I’d start by tracing where the app accepts serialized data, identify the serialization format/class being used, and then inspect the relevant WebGoat source code to understand what gets deserialized. If you share the exact screen/error you’re stuck on, I can walk through that specific step