Sour Pickles¶
Slaviero, M. (2011). Sour Pickles: A Serialised Exploitation Guide in One Hundred Slides or Fewer.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Domain-specific¶
- Insecure Deserialization
- Python's
pickleprotocol executes arbitrary Python via the__reduce__protocol during unpickling, making any service that unpickles network-supplied data directly exploitable for remote code executionThis sourceIt does not reach the machine-learning model-loader surface, a later development that is not cited to this talk. Sour Pickles circulates under two subtitles — "A Serialised Exploitation Guide in One Hundred Slides or Fewer" and "...in One Part"; the form given above is one of them.
- Python's
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:4499360083c6 · see in the full table