- var_dump: documentation ( source)
- unserialize: documentation ( source)
- serialize: documentation ( source)
- sprintf: documentation ( source)
<?php
class CantUnserializeThis extends ArrayObject
{
}
$className = 'CantUnserializeThis';
var_dump(serialize(new ArrayObject()));
var_dump(unserialize(sprintf(
'C:%d:"%s":0:{}',
strlen($className),
$className
)));
var_dump(unserialize(sprintf(
'S:%d:"%s":0:{}',
strlen($className),
$className
)));