Web Hack List

Collected research

Python Dirty Arbitrary File Write to RCE via Writing Shared Object Files Or Overwriting Bytecode Files

Two ways to turn a restricted arbitrary file write into code execution in Python web applications. Overwriting a cached bytecode file works when the magic number, source timestamp and size are preserved or brute-forced; simpler still, writing a shared object beside a module wins because extension loaders precede source and bytecode loaders.

Record

Researcher
siunam
Published by
siunam's Website
Date
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of siunam, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .