Everyone is talking about common classes of bugs, sql injection, XSS, CSRF, IDOR etc. But, as in all things in life, there are more, fancier things that true bug connoisseurs love. This talk will show some nice deserialization and request forgery tricks. So if you want to expand your application security knowledge for either offensive or defensive purposes, this might be the talk for you.