Web Hack List

Collected research

Memcached Command Injections at Pylibmc

Flask-Session builds its memcached key by concatenating a prefix with the session cookie value, so CRLF smuggled in through octal-quoted cookie escapes injects raw memcached commands. An attacker can store an arbitrary pickle under a chosen key and then load it as their own session, gaining remote code execution when the library unpickles it.

Record

Published by
btlfry.gitlab.io
Topic
Injection

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of btlfry.gitlab.io, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .