webPromedium

Lab 13 — WebForge — Insecure Deserialization in Config Import

hackadvisor

Task: Flask DevOps platform with config import/export using Python pickle serialization. Solution: Craft malicious pickle payload with __reduce__ method to achieve RCE and read /tmp/flag.txt.

$ ls tags/ techniques/
insecure_pickle_deserializationrce_via_reduce_methodbase64_payload_injectionpython_eval_execution

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups