by @M
08 Aug 2022

Exploiting Google SLO Generator with Python YAML Deserialization Attack

by @M
08 Aug 2022

Exploiting Google SLO Generator with Python YAML Deserialization Attack

Screenshots from the blog posts

blog-posts/images/cl6kv7qos09wk0mqe59s98yzf.pngblog-posts/images/cl6kv7qos09wk0mqe59s98yzf.png

Summary

In this blog post, we will be detailing a new vector to exploit a vulnerable version of Google SLO Generator, a widely used Python library publicly available on Github. In other words, we will be searching for an older version that we can exploit to highlight the importance of keeping software packages up to date.

Description

users/photos/cl6kswav508am0jrz4trk2uj4.png

@M

6 posts

Total vcoins

6.7K

Badges

badges/images/cl1xi65zx02el0jms239bekpv.png

Malware Researcher

Comments (2)