首页
社区
课程
招聘
[转帖]Breaking Python 3 eval protections
发表于: 2021-1-24 09:14 2095

[转帖]Breaking Python 3 eval protections

2021-1-24 09:14
2095

Breaking Python 3 eval protections

Today I’m presenting you some research I’ve done recently into the Python 3 eval protections.

It’s been covered before, but it surprised me to find that most of the info I could find was only applicable for earlier versions of Python and no longer work, or suggested solutions would not work from an attacker perspective inside of eval since you need to express it as a single statement.


Since these break every so often, I’ve gone to some length to describe how I arrived at my conclusions to hopefully proverbially ‘teach you how to fish’ so you can work out your own technique should any of the exact solutions I arrived at break in the future.


I have also included a copy-and-paste section at the end of this if you’re in a hurry.

https://netsec.expert/posts/breaking-python3-eval-protections/



[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)

收藏
免费 2
支持
分享
最新回复 (2)
雪    币: 2318
活跃值: (8730)
能力值: ( LV2,RANK:15 )
在线值:
发帖
回帖
粉丝
2

上传的附件:
2021-1-24 09:18
0
雪    币: 97697
活跃值: (200824)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
3
2021-1-24 09:19
0
游客
登录 | 注册 方可回帖
返回
//