3 ms·
Absolute child's play compared to: https://gist.github.com/llllllllll/b1ac68a6b77535a64c0b13bfd887c05a https://gist.github.com/llllllllll/b1ac68a6b77535a64c0b1
by jamesdutc 9y ago
Absolute child's play compared to:
https://gist.github.com/llllllllll/b1ac68a6b77535a64c0b13bfd887c05a https://gist.github.com/llllllllll/b1ac68a6b77535a64c0b13bfd...
(Python's LOAD_FAST bytecode does `fastlocals[i]`: how can we abuse the lack of bounds checking on this array access?)
(We've also discussed potential extensions this to approach "lift" C-extension code in bytestrings into interpreter objects. This would be useful to escalate existing interpreter attacks in environments that try to lock things down.)
- Myrmornis 9y agoThat's amazing, but doesn't work for me (python 3.6.4). Not sure I'm going to try debugging it... t = (0, 1) tuple_setitem(t, 0, 99) print(t) # (0, 1) EDIT: Ah, it seems to work in 3.6.3