Hi
user
Admin Login:
Username:
Password:
Name:
Advanced Pickle Security
--client
pyohio
--show
pyohio_2018
--room hayscape 14185 --force
Next: 8 Tracking the International Space Station in Django with Redis-Queue and RQ Scheduler
show more...
Marks
Author(s):
lvh
Location
Hays Cape
Date
jul Sat 28
Days Raw Files
Start
12:00
First Raw Start
11:51
Duration
0:30:0
Offset
0:08:47
End
12:30
Last Raw End
12:51
Chapters
00:00
0:21:50
Total cuts_time
31 min.
https://pyohio.org/2018/schedule/presentation/23/
raw-playlist
raw-mp4-playlist
encoded-files-playlist
host
archive
mp4
svg
png
assets
release.pdf
Advanced_Pickle_Security_1.json
logs
Admin:
episode
episode list
cut list
raw files day
marks day
marks day
image_files
State:
---------
borked
edit
encode
push to queue
post
richard
review 1
email
review 2
make public
tweet
to-miror
conf
done
Locked:
clear this to unlock
Locked by:
user/process that locked.
Start:
initially scheduled time from master, adjusted to match reality
Duration:
length in hh:mm:ss
Name:
Video Title (shows in video search results)
Emails:
email(s) of the presenter(s)
Released:
has someone authorised pubication
Unknown
Yes
No
Normalise:
Channelcopy:
m=mono, 01=copy left to right, 10=right to left, 00=ignore.
Thumbnail:
filename.png
Description:
markdown
Python's standard library comes with an object serialization framework called `pickle`. It's no secret pickles are unsafe. Any time you load a pickle, you really have no guarantee what it'll do. While it's designed to just reconstitute objects from some bytes, it could open network connections, delete all your files, or really anything else it wants. Despite all of these flaws, it's very popular, especially in the scientific Python community. Many of its users actually have pretty good reasons to use it, so just telling them not to isn't very helpful. For example, numpy's various array types have custom behavior to fine-tune how they are serialized and deserialized -- features explicitly supported by the Pickle module's extension points. Most scientific applications also don't just have a matrix: they might have fairly complex object graphs that require serialization. Pickle supports this out of the box, and that's great! This talk is intended for intermediate and expert Python programmers. It's expected that you have heard of the Pickle module before and that you know it's unsafe. We'll (quickly) go through how Pickle works at a Pickle VM opcode level. Then we'll show how you can get arbitrary code execution, followed by some more advanced exploitation techniques (e.g. how you can put other behavior in a pickle while keeping equivalent functionality; e.g. the pickle still turns into the object you were expecting). Finally, we'll talk about how we can make this safe again in the end anyway, culminating in the practical implementation I have open sourced. If I have time (big stretch for the talk, but maybe not for the hallway track), I'll show techniques for how to attack Pickles that are "protected" by malleable encryption schemes like AES-CTR.
Comment:
production notes
2018-07-28/11_51_13.ts
Apply:
11:51:13 - 11:59:23 ( 00:08:10 )
S:
11:51:13 -
E:
12:21:13
D:
00:30:00
(
End:
490.0)
show more...
vlc ~/Videos/veyepar/pyohio/pyohio_2018/dv/hayscape/2018-07-28/11_51_13.ts :start-time=00.0 --audio-desync=0
Raw File
Cut List
11:51:13
seconds: 0.0
Wall: 11:51:13
Duration
00:30:00
12:21:13
seconds: 490.0
Wall: 11:59:23
Comments:
mp4
mp4.m3u
dv.m3u
Split:
Sequence:
:
delete
2018-07-28/11_51_13.ts
Apply:
11:59:23 - 12:21:13 ( 00:21:50 )
S:
11:51:13 -
E:
12:21:13
D:
00:30:00
(
Start:
490.0)
show more...
vlc ~/Videos/veyepar/pyohio/pyohio_2018/dv/hayscape/2018-07-28/11_51_13.ts :start-time=0490.0 --audio-desync=0
Raw File
Cut List
11:51:13
seconds: 490.0
Wall: 11:59:23
Duration
00:30:00
12:21:13
seconds: 0.0
Wall: 11:51:13
Comments:
mp4
mp4.m3u
dv.m3u
Split:
Sequence:
:
delete
2018-07-28/12_21_13.ts
Apply:
12:21:13 - 12:30:57 ( 00:09:44 )
S:
12:21:13 -
E:
12:51:12
D:
00:29:59
(
End:
584.0)
show more...
vlc ~/Videos/veyepar/pyohio/pyohio_2018/dv/hayscape/2018-07-28/12_21_13.ts :start-time=00.0 --audio-desync=0
Raw File
Cut List
12:21:13
seconds: 0.0
Wall: 12:21:13
Duration
00:29:59
12:51:12
seconds: 584.0
Wall: 12:30:57
Comments:
mp4
mp4.m3u
dv.m3u
Split:
Sequence:
:
delete
2018-07-28/12_21_13.ts
Apply:
12:30:57 - 12:51:12 ( 00:20:15 )
S:
12:21:13 -
E:
12:51:12
D:
00:29:59
(
Start:
584.0)
show more...
vlc ~/Videos/veyepar/pyohio/pyohio_2018/dv/hayscape/2018-07-28/12_21_13.ts :start-time=0584.0 --audio-desync=0
Raw File
Cut List
12:21:13
seconds: 584.0
Wall: 12:30:57
Duration
00:29:59
12:51:12
seconds: 0.0
Wall: 12:21:13
Comments:
mp4
mp4.m3u
dv.m3u
Split:
Sequence:
:
delete
Rf filename:
root is .../show/dv/location/, example: 2013-03-13/13:13:30.dv
Sequence:
get this:
check and save to add this
2018-07-28/11_51_13.ts
2018-07-28/12_21_13.ts
Veyepar
Video Eyeball Processor and Review