TGViewer
Python notes Python notes @python_development_notes · 514 subscribers
Post #119 833
This tutorial explores the security vulnerabilities associated with Python's pickle module, demonstrating how it can be exploited for remote code execution by crafting malicious serialized objects. It emphasizes the critical warning never to unpickle data from untrusted sources, illustrating the risk with a practical example involving a Flask web application and a reverse shell payload.
https://davidhamann.de/2020/04/05/exploiting-python-pickle/
David Hamann Exploiting Python pickles How unpickling untrusted data can lead to remote code execution.
More from @python_development_notes
  1. Sep 24, 2025https://www.youtube.com/watch?v=g-Cytq7YDCc
  2. Sep 23, 2025A recent report from The New Stack covers the major announcement that Nvidia is adding nat…
  3. Sep 22, 2025https://www.youtube.com/watch?v=A4Pn2lEdoLQ
  4. Sep 21, 2025🚀 The fast, Pythonic way to build MCP servers and clients https://github.com/jlowin/fastm…
  5. Sep 20, 2025This commentary from Jyn.dev embraces the idea of writing imperfect but effective Python c…
  6. Sep 19, 2025https://www.youtube.com/watch?v=5avSMc79V-w
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →