Playing with Python Pickle #1
ID: 73d23fee-e33f-5c4f-b247-ad9939767b90
STIX ID: report--73d23fee-e33f-5c4f-b247-ad9939767b90
Feed Name: SensePost Blog
Threat Score
This report explains the security risks of deserializing untrusted Python Pickle data, demonstrates how Pickle opcode streams can invoke arbitrary code (including via overwritten memcached entries), and provides opcode-level examples and replication steps to illustrate how an attacker could achieve remote code execution by injecting malicious Pickle objects.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
