Open slinderud opened 5 years ago
Example: curl -XPOST "url" --data-binary "{{ ''.__class__.mro()[1].__subclasses__() }}"
curl -XPOST "url" --data-binary "{{ ''.__class__.mro()[1].__subclasses__() }}"
Things to look at: Don't accept post towards template without authentication (we only need get requests) Limit to RO filesystem in servicefile Fix template user and don't run it as root
Example:
curl -XPOST "url" --data-binary "{{ ''.__class__.mro()[1].__subclasses__() }}"
Things to look at: Don't accept post towards template without authentication (we only need get requests) Limit to RO filesystem in servicefile Fix template user and don't run it as root