by @M
06 Oct 2022

Research: Exploiting Insecure Debugger Console (OC)

by @M
06 Oct 2022

Research: Exploiting Insecure Debugger Console (OC)

Screenshots from the blog posts

blog-posts/images/cl8xa6bu251el0kpl7ta833y6.pngblog-posts/images/cl8xa6bu251el0kpl7ta833y6.png

Summary

One of the many cool Flask features is the interactive debug console in the browser. This can be useful to quickly test what part of your code is causing issues. But in many cases, developers explicitly enable the debug console and disable the pin protection on those debug consoles. One of the consequences is remote command execution on these applications. Let's explore.

Description

users/photos/cl6kswav508am0jrz4trk2uj4.png

@M

6 posts

Total vcoins

6.7K

Badges

badges/images/cl1xi65zx02el0jms239bekpv.png

Malware Researcher

Comments (0)