It's a PHP Unserialization Vulnerability Jim but Not as We Know It

Black Hat USA 2018

Presented by: Sam Thomas
Date: Thursday August 09, 2018
Time: 17:00 - 17:50
Location: Lagoon JKL

Recent years have seen the emergence of PHP unserialization vulnerabilities as a viable route to remote code execution or other malicious outcomes. The presentation will start with a brief refresher on the issue as it has previously been understood before introducing new research which shows how unserialization can be induced when other types of vulnerability occur, including some that would previously have been considered low impact.

The presentation will include demos of long lived and previously unidentified RCE exploits against some of the most widely deployed open source PHP web applications and libraries.

Sam Thomas

Sam Thomas is the Director of Research at Secarma Ltd. Previously, he was an independent researcher (eshu.co.uk). His recent research focuses on code re- use attacks both for mitigation bypass and within web based applications.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats