A popular opinion says to not use the pickle class on a data given by user because on deserialization it may lead to the object injection attack and malicious code execution.
Subscribe:
But what about other formats? Are they also dangerous?
My name is Kacper Szurek and in today’s episode of “from 0 to pentesting hero“ I’m going to talk about yaml files.
Yaml format is not as simple as it might seem.
In the standard parser used in Python, we can also use the apply tag, which allows you to call any function from any module, and pass appropriate parameters to them.
So it is equivalent to the ability to execute arbitrary code on the server that we attack.
In our case, we will use the function to list the contents of the current directory.
Twitter:
Website:
Github:
#from0topentestinghero #bugbounty #python
3 views
6
2
9 months ago 00:32:25 0
Nitrux “ub” — #DisruptiveByDesign — New Nitrux Not Up to UI Standards | Hands on Review
10 months ago 01:13:28 12
Как использовать Ansible для автоматизации установки и настройки веб-сервера Apache под Linux
11 months ago 00:08:00 0
Секретная фича Docker Compose | Создаём несколько окружений для Spring Boot | Amplicode
1 year ago 00:09:27 1
GitLab: DevSecOps: Part 5/12: Protect your Apps with Static Application Security Testing (SAST)
1 year ago 01:58:20 2
Разрабатываем Admin UI на React Admin в VS Code вместе с Amplicode
1 year ago 00:12:30 0
FREE 2023 Stable Diffusion PC INSTALLATION! AI Art For BEGINNERS!
2 years ago 00:13:01 0
Do NOT Learn Kubernetes Without Knowing These Concepts...
2 years ago 01:01:19 0
Ansible для автоматизации установки и настройки Apache под Linux
2 years ago 01:04:51 0
Курсы Git за час: руководство для начинающих DevOps / DevNet инженеров
2 years ago 00:58:57 0
Как программировать на Python: метод, функция, класс для DevOps
2 years ago 01:57:17 0
Как создавать, использовать и хранить пароли DevOps / DevNet
2 years ago 01:39:16 0
Как стать специалистом DevOps / DevNet и зарабатывать от $3000
2 years ago 01:24:50 0
Установка и настройка Docker: как создать веб-приложение в Docker-контейнере
2 years ago 01:41:21 0
Python с нуля до DevOps на практике за 1,5 часа
2 years ago 00:51:46 0
08-Docker-COMPOSE. Простой запуск контейнеров.
2 years ago 00:19:34 0
Установил Visual Studio Code на планшет. Программирую с iPad.
2 years ago 00:05:08 0
How to fix “Unable to Load assets“ Error! | flutter | Solved 100%
2 years ago 00:22:19 0
Dockerizing a React App for Development and Production
2 years ago 00:30:14 2
Уроки по Golang. Advanced. REST API. Конфигурация
2 years ago 00:33:12 3
Face Recognition App In Flutter Using TensorflowLite & Google ML KIT
2 years ago 01:09:00 0
GitLab CI CD Tutorial for Beginners [Crash Course]
3 years ago 00:07:42 0
#8:GitLab CI Build Docker Image and Push to Docker Hub | Push Docker Image to Docker Hub GitLab CI
3 years ago 00:08:06 29
Top 5 Reasons to Learn Linux - For Anyone Interested in Tech
3 years ago 00:06:28 0
GITLAB CI CD сокращаем код. Gitlab ci include, extends, reference, remote, local