← All Challenges
Challenge 37 of 66

Object Breaker

🟠 Hard Injection +100 XP

A Java application deserializes user-supplied objects. Craft a malicious serialized object to achieve remote code execution.

Object Breaker // sandbox
The app uses Apache Commons Collections. Look for known gadget chains.

🏆 Challenge Complete!

+100 XP earned
Next Challenge →