首页
社区
课程
招聘
[转帖]Breaking Python 3 eval protections
2021-1-24 09:14 1812

[转帖]Breaking Python 3 eval protections

2021-1-24 09:14
1812

Breaking Python 3 eval protections

Today I’m presenting you some research I’ve done recently into the Python 3 eval protections.

It’s been covered before, but it surprised me to find that most of the info I could find was only applicable for earlier versions of Python and no longer work, or suggested solutions would not work from an attacker perspective inside of eval since you need to express it as a single statement.


Since these break every so often, I’ve gone to some length to describe how I arrived at my conclusions to hopefully proverbially ‘teach you how to fish’ so you can work out your own technique should any of the exact solutions I arrived at break in the future.


I have also included a copy-and-paste section at the end of this if you’re in a hurry.

https://netsec.expert/posts/breaking-python3-eval-protections/



阿里云助力开发者!2核2G 3M带宽不限流量!6.18限时价,开 发者可享99元/年,续费同价!

收藏
点赞2
打赏
分享
最新回复 (2)
雪    币: 2013
活跃值: (8365)
能力值: ( LV2,RANK:15 )
在线值:
发帖
回帖
粉丝
2DCoXrq 2021-1-24 09:18
2
0

上传的附件:
雪    币: 85485
活跃值: (198795)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
linhanshi 2021-1-24 09:19
3
0
游客
登录 | 注册 方可回帖
返回