### ä»£ç æ³¨å ¥ãå½ä»¤æ§è¡ 1.å ç½®å±é©å½æ° exec execfile eval 2.æ ååºå±é©æ¨¡å os subprocess commands 3.å±é©ç¬¬ä¸æ¹åº Template(user_input) : æ¨¡æ¿æ³¨å ¥(SSTI)æäº§ççä»£ç æ§è¡ subprocess32 4.ååºåå marshal PyYAML pickleåcpickle shelve PIL unzip [Pythonæ²ç®±éé¸çnç§å§¿å¿](https://xianzhi.aliyun.com/forum/read/2138.html) [Python乿°æ®åºååï¼jsonãpickleãshelveï¼](http://www.cnblogs.com/yyds/p/6563608.html) [Exploiting Python PIL Module Command Execution Vulnerability](https://xianzhi.aliyun.com/forum/read/2163.html) [Exploiting Python Code Injection in Web Applications](https://www.doyler.net/security-not-included/exploiting-python-code-injection) [EXPLOITING PYTHON CODE INJECTION IN WEB APPLICATIONS](http://www.securitynewspaper.com/2016/11/12/exploiting-python-code-injection-web-applications/) [Exploiting Python Code Injection in Web Applications](https://sethsec.blogspot.jp/2016/11/exploiting-python-code-injection-in-web.html) [Python evalç常è§é误å°è£ åå©ç¨åç](http://xxlegend.com/2015/07/31/Python%20eval%E7%9A%84%E5%B8%B8%E8%A7%81%E9%94%99%E8%AF%AF%E5%B0%81%E8%A3%85%E5%8F%8A%E5%88%A9%E7%94%A8%E5%8E%9F%E7%90%86/) [Exploiting Pythonâs Eval](http://www.floyd.ch/?p=584) [Exploiting insecure file extraction in Python for code execution](https://ajinabraham.com/blog/exploiting-insecure-file-extraction-in-python-for-code-execution) [æé iReaderæç«Pythonæ¼æ´ææ](https://www.leavesongs.com/PENETRATION/zhangyue-python-web-code-execute.html) [Python Pickleçä»»æä»£ç æ§è¡æ¼æ´å®è·µåPayloadæé ](http://www.code2sec.com/2017/03/22/python-pickle%E7%9A%84%E4%BB%BB%E6%84%8F%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%E5%AE%9E%E8%B7%B5%E5%92%8Cpayload%E6%9E%84%E9%80%A0/) [Python PyYAMLååºååæ¼æ´å®éªåpayloadæé ](http://www.code2sec.com/2017/09/22/python-pyyaml%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E%E5%AE%9E%E9%AA%8C%E5%92%8Cpayload%E6%9E%84%E9%80%A0/) [Exploiting Python Deserialization Vulnerabilities](https://crowdshield.com/blog.php?name=exploiting-python-deserialization-vulnerabilities) [Shellcoding in Pythonâs serialisation format](https://media.blackhat.com/bh-us-11/Slaviero/BH_US_11_Slaviero_Sour_Pickles_WP.pdf) [PyCodeInjectionä»£ç æ³¨å ¥å®éªç¯å¢](https://github.com/sethsec/PyCodeInjection) ### 代ç 审计 [Pythonå®å ¨ç¼ç å代ç 审计](http://xxlegend.com/2015/07/30/Python%E5%AE%89%E5%85%A8%E7%BC%96%E7%A0%81%E5%92%8C%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1/) https://xianzhi.aliyun.com/forum/read/303.html https://xianzhi.aliyun.com/forum/read/302.html https://xianzhi.aliyun.com/forum/read/301.html https://xianzhi.aliyun.com/forum/read/300.html https://xianzhi.aliyun.com/forum/read/274.html [Dangerous Python Functions, Part 1](https://www.kevinlondon.com/2015/07/26/dangerous-python-functions.html) [Dangerous Python Functions, Part 2](https://www.kevinlondon.com/2015/08/15/dangerous-python-functions-pt2.html) [Dangerous Python Functions, Part 3](https://www.kevinlondon.com/2017/01/30/dangerous-python-functions-pt3.html) [è®°ä¸ä¸PythonWeb代ç 审计åºè¯¥æ³¨æçå°æ¹](http://blog.neargle.com/2016/07/25/log-of-simple-code-review-about-python-base-webapp/) [廿°å大佬çpython代ç å®¡è®¡å·¥å ·](https://github.com/shengqi158/pyvulhunter) [æ¥èªopenstackå®å ¨å¢éçpython代ç éæå®¡è®¡å·¥å ·](https://github.com/openstack/bandit) [æ¥èªopenstackå®å ¨å¢éçpython代ç éæå®¡è®¡å·¥å ·2](https://github.com/openstack/syntribos) [代ç å®¡è®¡å·¥å ·pyt](https://github.com/python-security/pyt) [xfkxfkçpythonèªå¨å代ç 审计](https://mp.weixin.qq.com/s?__biz=MzUxOTYzMzU0NQ==&mid=2247483887&idx=1&sn=99ab12309de75381e37c058d53def1b6&chksm=f9f7ee09ce80671fc5887a9c25350fc610559cc1e095f9b689473873889581e4c5fbb0dec2cd&mpshare=1&) åºäº[pyekaboo](https://github.com/SafeBreach-Labs/pyekaboo) å廿°åç[pyvulhunter](https://github.com/shengqi158/pyvulhunter) ### Djangoç¸å ³ [Django debug page XSSæ¼æ´ï¼CVE-2017-12794ï¼åæ](https://www.leavesongs.com/PENETRATION/django-debug-page-xss.html) [Django DeleteView without confirmation template, but with CSRF attack](https://www.leavesongs.com/PYTHON/django-deleteView-without-confirmation-template.html) [Djangoå®å ¨æºå¶](http://xxlegend.com/2015/04/01/Django%E5%AE%89%E5%85%A8%E6%9C%BA%E5%88%B6/) [ä»DjangoçSECTET_KEYå°ä»£ç æ§è¡](http://xxlegend.com/2015/04/01/%E4%BB%8EDjango%E7%9A%84SECTET_KEY%E5%88%B0%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C/) [Django CSRF Bypass (CVE-2016-7401) æ¼æ´åæ](https://paper.seebug.org/58/) [Django CSRF Bypass æ¼æ´åæ(CVE-2016-7401)](http://blog.knownsec.com/2016/10/django-csrf-bypass_cve-2016-7401/) [Djangoç两个urlè·³è½¬æ¼æ´åæ:CVE-2017-7233&7234](https://paper.seebug.org/274/) [Python æ ¼å¼ååç¬¦ä¸²æ¼æ´ï¼Django为ä¾ï¼](https://www.leavesongs.com/PENETRATION/python-string-format-vulnerability.html) [Django å®å ¨æä½³å®è·µ](http://www.atjiang.com/2scoopsdjango1.8-26-security-best-practices/) [ä»Pwnhubè¯çèDjangoå®å ¨ç¼ç ](https://www.leavesongs.com/PYTHON/django-coding-experience-from-pwnhub.html) [pythonådjangoçç®å½éåæ¼æ´(ä»»ææä»¶è¯»å)](http://www.lijiejie.com/python-django-directory-traversal/) [æ°åä»»ææä»¶è¯»åæ¼æ´çç ç©¶](https://www.leavesongs.com/PENETRATION/arbitrary-files-read-via-static-requests.html) [djangoçä¸äºå®å ¨é®é¢çæ¡](https://www.kevinlondon.com/2015/10/16/answers-to-django-security-questions.html) ### packageéé±¼ [Package éé±¼](https://paper.seebug.org/311/) [被忽è§çæ»å»é¢ï¼Python package éé±¼](https://paper.seebug.org/326/) https://www.pytosquatting.org/ ### LDAPæ³¨å ¥ [Pythonå®å ¨ç¼ç ä¹é¢é²LDAPæ³¨å ¥](http://xxlegend.com/2016/12/01/Python%E5%AE%89%E5%85%A8%E7%BC%96%E7%A0%81%E4%B9%8B%E9%A2%84%E9%98%B2LDAP%E6%B3%A8%E5%85%A5/) ### SSRF [è°ä¸è°å¦ä½å¨Pythonå¼å䏿ç»SSRFæ¼æ´](https://www.leavesongs.com/PYTHON/defend-ssrf-vulnerable-in-python.html) [Pythonå®å ¨ - ä»SSRFå°å½ä»¤æ§è¡æ¨æ¡](https://www.leavesongs.com/PENETRATION/getshell-via-ssrf-and-redis.html) [Splash SSRF å°è·åå ç½æå¡å¨ ROOT æé](https://xianzhi.aliyun.com/forum/read/1872.html) ### XSS [Flask Debugger页é¢ä¸çéç¨XSSæ¼æ´åæåææè¿ç¨è®°å½](http://blog.neargle.com/2016/09/21/flask-src-review-get-a-xss-from-debuger/) ### SQLI [讨论PythonWebå¼åä¸å¯è½ä¼éå°çå®å ¨é®é¢ä¹SQLæ³¨å ¥](http://blog.neargle.com/2016/07/22/pythonweb-framework-dev-vulnerable/) ### SSTIæ¨¡çæ³¨å ¥ [Python Security Auditing (II): SSTI](https://www.cdxy.me/?p=738) [exploring-ssti-in-flask-jinja2](https://nvisium.com/blog/2016/03/09/exploring-ssti-in-flask-jinja2/) [exploring-ssti-in-flask-jinja2-part-ii](https://nvisium.com/blog/2016/03/11/exploring-ssti-in-flask-jinja2-part-ii/) ### python webshell https://github.com/evilcos/python-webshell https://github.com/ahhh/Reverse_DNS_Shell ### paper Python_Hack_ç¥éåå®_åå(åå).pdf ### å ¶ä» [å¦ä½å¤æç®æ ç«ç¹æ¯å¦ä¸ºDjangoå¼å](https://www.leavesongs.com/PENETRATION/detect-django.html) [Supervisordè¿ç¨å½ä»¤æ§è¡æ¼æ´ï¼CVE-2017-11610ï¼](https://www.leavesongs.com/PENETRATION/supervisord-RCE-CVE-2017-11610.html) [python坿æ¬XSSè¿æ»¤å¨](https://www.leavesongs.com/PYTHON/python-xss-filter.html) [åºäºmezzanineçæ»é²æ¯èµç¯å¢æå»ºåXXEæ¼æ´æé /](http://xxlegend.com/2016/04/01/%E5%9F%BA%E4%BA%8Emezzanine%E7%9A%84%E6%94%BB%E9%98%B2%E6%AF%94%E8%B5%9B%E7%8E%AF%E5%A2%83%E6%90%AD%E5%BB%BA%E5%8F%8AXXE%E6%BC%8F%E6%B4%9E%E6%9E%84%E9%80%A0/) [Python Wafé»ååè¿æ»¤ä¸çä¸äºBypassæè·¯](http://www.0aa.me/index.php/archives/123/) [Pwnhub Webé¢Classroomé¢è§£ä¸åæ](https://www.leavesongs.com/PENETRATION/pwnhub-web-classroom-django-sql-injection.html) [Programming Secure Web Applications in Python](https://www.thoughtco.com/programming-secure-web-applications-2813531) [Advisory: HTTP Header Injection in Python urllib](http://blog.blindspotsecurity.com/2016/06/advisory-http-header-injection-in.html) [Hack Redis via Python urllib HTTP Header Injection](https://security.tencent.com/index.php/blog/msg/106) [ãææ¯å享ãpython web å®å ¨æ»ç»](http://bobao.360.cn/learning/detail/4522.html) ### å®å ¨å·¥å · [pythonæ£åè¿æ¥åé¨](https://www.leavesongs.com/PYTHON/python-shell-backdoor.html) [struts2 S2-016/S2-017 Python GetShell](https://www.leavesongs.com/PENETRATION/UseOfStruts.html) [Pythonå¤çº¿ç¨ç«¯å£æ«æå·¥å ·](https://www.leavesongs.com/PYTHON/PortScanner.html) [Python JSON Fuzzer: PyJFuzz](https://n0where.net/python-json-fuzzer-pyjfuzz/) https://github.com/smartFlash/pySecurity ### å¯¹è±¡æ³¨å ¥ãåºå±å®å ¨ [DEFENCELY CLARIFIES PYTHON OBJECT INJECTION EXPLOITATION](https://defencely.com/blog/defencely-clarifies-python-object-injection-exploitation/) [OWASP Python Security Project](https://github.com/ebranca/owasp-pysec) [Escaping a Python sandbox with a memory corruption bug](https://hackernoon.com/python-sandbox-escape-via-a-memory-corruption-bug-19dde4d5fea5)