PHP Serialization to JSON: Payload Formats & Object Injection Defense
PHP serialize() outputs proprietary byte-stream representations of PHP data types (s:length:"value"; for strings, a:count:{...} for arrays, O:length:"name":count:{...} for objects). The converter parses serialized PHP payloads into clean JSON.
Format Specifications & Syntax Reference
| Specification Parameter | Standard Value / Parsing Behavior |
|---|---|
| PHP Serialization Standard | PHP Internal Serialization Grammar |
| Vulnerability Class | CWE-502: Deserialization of Untrusted Data (PHP Object Injection) |
| Type Codes | s (string), i (integer), d (float), b (boolean), a (array), O (object), N (null) |
| Target Format | Clean RFC 8259 JSON objects |
⚠️ Common Engineering Edge Cases & Gotchas
- Why is native PHP unserialize() extremely dangerous on untrusted user input: Passing user-controlled data to native PHP
unserialize()allows attackers to trigger magic methods (__wakeup,__destruct) on arbitrary classes loaded in memory (PHP Object Injection), leading to Remote Code Execution. - Why does PHP serialize arrays with sequential integers as objects in JSON: In PHP, all arrays are associative dictionaries. If an array has non-zero or skipped numeric keys (e.g. indices 0, 2), JSON cannot serialize it as a standard contiguous array and must convert it to a JSON object with string keys.
Production Implementation Examples
Node.js (php-serialize converter)
import phpSerialize from 'php-serialize';
const phpPayload = 'a:2:{s:4:"user";s:5:"admin";s:4:"role";s:7:"manager";}';
const parsedObject = phpSerialize.unserialize(phpPayload);
console.log(JSON.stringify(parsedObject, null, 2));
PHP JSON Migration
'admin', 'active' => true];
$jsonString = json_encode($data);
echo $jsonString;
?>
High-Throughput Processing & Memory Safety Bounds
Client-side parsing and data transformation operates against browser V8 memory limits. When manipulating large documents or high-volume datasets approaching the 2MB boundary, synchronous operations can block the main execution thread. Production web applications should delegate heavy serialization and formatting jobs to background Web Workers or leverage streaming parsers (such as the WHATWG TransformStream interface) to maintain interface responsiveness during heavy data ingestion. Ensure robust UTF-8 multi-byte sequence validation to prevent surrogate pair slicing and payload corruption. Incorporate automated benchmark assertions into build pipelines to intercept algorithmic complexity regressions before production release.