Unserialize Session Allows $47M Bank Transfer Hack?!

UNSERIALIZE APOCALYPSE! Session fixation + unserialize() = REMOTE CODE EXECUTION! Banking app backdoor installed! $47M transferred to offshore accounts! Banking license REVOKED! CTO ARRESTED!

#php #phpdisaster #unserialize #remotecodeexecution #sessionfixation #bankinghack #productionbug #phpshorts #phpwtf #$47mstolen #careerending #criminalcharges

https://www.youtube.com/watch?v=4KkePjaeFq0

Unserialize Session Allows 47M Bank Transfer Hack?! #sessionfixation

YouTube

How to Stop unserialize From Becoming Code Execution

Untrusted serialize data can run magic methods.

#php #unserialize #objectinjection #security #howto #rce

https://www.youtube.com/watch?v=Yi43pgKyKB8

How to Stop unserialize From Becoming Code Execution #unserialize

YouTube