Главная
Study mode:
on
1
Intro
2
Backstory
3
Using mitogen with ansible
4
Running ansible with mitogen
5
What is Pickle
6
Advantages
7
Standard Advice
8
Documentation
9
Remote code execution
10
Ricks Pickle
11
Standard Mitigation
12
Other Attacks
13
Benchmarking
14
Selfreferencing pickles
15
Unpicking pickles
16
Use case
17
Pickle Lite
Description:
Explore the security implications and potential rehabilitation of Python's Pickle serialization protocol in this 30-minute EuroPython 2018 conference talk. Dive deep into the vulnerabilities associated with Pickle, learn about common attacks and their defenses, and discover new research on potential threats and mitigations. Gain insights into implementing safe usage practices, understand the risks of arbitrary code execution, and explore less-known alternatives to Pickle. Examine benchmarks, self-referencing pickles, and use cases while considering the possibility of a more secure "Pickle Lite" implementation.

Rehabilitating Pickle

EuroPython Conference
Add to list
0:00 / 0:00