Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Dangerous Pickles – Malicious Data Serialization in Python (intoli.com)
31 points by foob on Dec 6, 2017 | hide | past | favorite | 3 comments


It's quite simple: they are executable code.


pickle is neat, but so is eval.


And both are easily avoided with a little work.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: