The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

java deserialize

Kelley | Last updated: May 09, 2017 08:22PM UTC

Hello - I am currently testing Oracle E-Business Suite that has a mix of normal HTTPS traffic with params and also HTTPS traffic that has the params java serialized. Is there way to deserialize the object to XML or some other readable format to then scan/fuzz with Burp. Looking at the options online, I can't seem to get any of the options out there to work correctly and I'm not seeing a plugin in the store that just does the deserialization to readable request format. Thanks!

PortSwigger Agent | Last updated: May 10, 2017 10:39AM UTC