Skip to main content

Deadly Uploads: Deserialization & Webshells

Uploading a file seems harmless—until the server executes it. Learn how "Unrestricted File Uploads" lead to Webshells (RCE), and how "Insecure Deserialization" (Java/Python/PHP) turns data objects into remote command execution.

5 chapters
85m total

Sign in to continue

Sign in to unlock lessons based on your plan and track your progress.