The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

LAB: Developing a custom gadget chain for Java deserialization

Lyuben | Last updated: Jul 05, 2024 02:05PM UTC

Dear PortSwigger team, First of all, thank you for the great content and learning materials. Indeed, there are no other platforms that even come close to the Web Security Academy's level when it comes to web vulnerabilities. I have a question regarding the lab for developing custom gadget chains for Java deserialization. I was able to grasp everything except for one thing - why do we need to create a "productcatalog" subfolder in the Java structure? How are we supposed to find that out without looking at online solutions? Lastly, if there is one thing that can be improved in the Web Security Academy - its this. The lab walkthroughs often are merely reproduction steps. For some of the harder labs, it would be great to have some in-depth tutorial. In this particular case, the community solution also did not provide this information. Do you have any good suggestions where I can watch explanations of the solutions for the harder labs? I strongly believe that nothing can be learned if not understood first. Still, you have done an amazing job, thank you!

Ben, PortSwigger Agent | Last updated: Jul 08, 2024 10:08AM UTC