Hacker News new | ask | show | jobs
by ademarre 1401 days ago
That quote supports my statement. Notice that the serialized object is the thing that was constructed by the attacker, not some user data that you serialized yourself.
1 comments

No the input was not serialized, it was carefully crafted so that when it gets serialized and deserialized, it triggers the malicious payload.