Closed martinstnv closed 1 year ago
Hello,
The "missing spaces" are null bytes, invisible to the naked eye. Generally, you can't just copy paste your payload from the console. Either pipe it to base64, or (preferably) use the -b
flag of phpggc to tell it to base64 encode it. You can also use -s
to soft urlencode for instance, or use the ASCII armor, or chain encoders... Check the help / readme for more details.
Charles
Hi!
I tried the following command in order to solve a popular challenge by Portswigger:
And received the following result:
There are missing spaces which break the serialized object.
If I pipe the output of the command directly to base64 and decode it in Burp Suite's "Decoder", the serialized object will again be displayed without spaces. However, upon closer inspection I noticed that there is "something" in between and it turned out to be null bytes (
\0
) where the spaces were supposed to be.