I couldn't find a good video on how to exploit deserialization vulnerabilities using Burp Suite so I made one.
This is an example of discovering and exploiting a known deserialization vulnerability in an old version of JBoss (based on https://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/) using Burp Suite Pro (https://portswigger.net/burp), the Java Deserialization Scanner extension (https://techblog.mediaservice.net/2017/05/reliable-discovery-and-exploitation-of-java-deserialization-vulnerabilities/) and ysoserial (https://github.com/frohoff/ysoserial).
Download
0 formats
No download links available.
Exploiting a Java Deserialization Vulnerability using Burp Suite | NatokHD