Sign inSign up

dockerbucket/insecure_deserialization

By dockerbucket

•Updated almost 8 years ago

Flask App vulnerable to Insecure Deserialization

Image
1

426

dockerbucket/insecure_deserialization repository overview

What is Insecure Deserialization?

Insecure Deserialization is a vulnerability which occurs when untrusted data is used to abuse the logic of an application, inflict a denial of service (DOS) attack, or even execute arbitrary code upon it being deserialized.

Using Python Flask and Json Pickle, a vulnerable app has been developed in an Ubuntu Container.

To access this app run the container by using the below mentioned command:

docker run -p 3000:3000 dockerbucket/insecure_deserialization

For more reference regarding Insecure Deserialization you can have a look into my blog where things are explained in detail. Link for the blog has been provided below

https://medium.com/@0xbughunter/de-serialization-sometimes-pickle-can-be-too-sour-45c930e18b8e⁠

Tag summary

Content type

Image

Digest

Size

180.5 MB

Last updated

almost 8 years ago

docker pull dockerbucket/insecure_deserialization