daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

python.md (1469B)


      1 ---
      2 title: "Python"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/python.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/python.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Python
     14 
     15 ## Python-specific execution probe
     16 
     17 When an input appears to be evaluated as a Python expression, a harmless call to `str()` can help confirm that the result is being executed rather than reflected verbatim. Adapt the surrounding quotes to the injection context:<sup>[[1]](#references)</sup>
     18 
     19 ```python
     20 "+str(True)+"  # If True is printed, the expression was evaluated.
     21 ```
     22 
     23 Do not treat this probe alone as proof that arbitrary statements or operating-system commands can run; the sink may expose only a restricted expression language.
     24 
     25 ## Related techniques
     26 
     27 [Readme](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/python/bypass-python-sandboxes/README.md)
     28 
     29 [Readme](/hacktricks/pentesting-web/ssti-server-side-template-injection/overview)
     30 
     31 [Readme](/hacktricks/pentesting-web/deserialization/overview)
     32 
     33 ## References
     34 
     35 - [1] [Python documentation - Built-in Functions: `eval()` and `str()`](https://docs.python.org/3/library/functions.html)