3 ms·
Brandon - what methods are you using to run untrusted Python code in a secure sandbox?
by benhamner 13y ago
Brandon - what methods are you using to run untrusted Python code in a secure sandbox?
- brandonhsiao 13y agoRight now what I'm doing is: 1. search code for double underscores (to block magic methods) 2. replace `__builtins__` with a whitelisted version 3. hook `__import__` to only allow a whitelist 4. hook `getattr` to reject any key containing double underscores
- michaelmior 13y agoMany of the builtins that are disabled seem quite harmless to me (especially something like "min"). Curious how you decided which ones to disable.
- jerf 13y agoYou may want to bear in mind that, at least last I knew, the official position of the CPython dev team is that it is not possible to sandbox CPython. If they can't do it.... At any rate it is certainly not as simple as that, and not only is it not as simple as that, it is not even close to being that simple. In fact, I recall warning people off of this exact project many years ago on comp.lang.python. This seems up-to-date: https://wiki.python.org/moin/Asking%20for%20Help/How%20can%20I%20run%20an%20untrusted%20Python%20script%20safely%20%28i.e.%20Sandbox%29 https://wiki.python.org/moin/Asking%20for%20Help/How%20can%2... It looks like the only even remotely feasible option is PyPy, and this link doesn't look like much fun: https://pypi.python.org/pypi/RestrictedPython/ https://pypi.python.org/pypi/RestrictedPython/ It looks to me like you'd still have many, many opportunities to end up with holes in the system. I really, really don't recommend Python for this. You might find this interesting: http://blog.delroth.net/2013/03/escaping-a-python-sandbox-ndh-2013-quals-writeup/ http://blog.delroth.net/2013/03/escaping-a-python-sandbox-nd... (And before you go "Oh, I've got that blocked"... read it, like, really really read it, not just skim for "one thing I can do to block that stuff", but to see just how many things there are in Python for this sort of hackery. Personally I'd guess the "I blocked double-underscores" would not have slowed them down much.)
- pearjuice 13y agoThis. You _will_ get compromised. Maybe not today or tomorrow but it is inevitable.
- heyboyheygirl 13y ago>This. Obvious samefag is obvious. Go back to 4chan kthxbai.
- jsmeaton 13y agoHoly shit, that article was brilliant. A few of those tricks I was aware of ( __class__.__class__ ), but crafting code objects? I need to re-read this a few times to properly grok how it works. I find things like this absolutely fascinating.
- maxjus 13y agoCheck out https://github.com/haypo/pysandbox/ https://github.com/haypo/pysandbox/
- oakwhiz 13y agoI would recommend looking at the PyPy sandbox environment as it is not possible to secure CPython in this way.
- blueblob 13y agoIs this python 2 or 3? Your description said that you didn't allow underscores, but if this is python 2, people would still be able to run threads (threads were renamed _thread in python 3).
- ybaumes 13y agoSame question here. I am a total novice to Python, so it might be a stupid question. When I launch with python2.6 it does not find the RestrictedPython package. If I launch with Python 3.2 then it complains about the "print" syntax.
- dbaupp 13y agoAre you at least running the code in a secured VM, or a Linux sandbox?
- Breakthrough 13y agoYou might also want to consider using a sandbox/jail such as AppArmor, to prevent the Python (sub)process itself from accessing any resources should those methods fail. I came across a project called CodeJail, which seems to help configure Python (or other scripting languages) nicely with AppArmor, to help execute untrusted code in a safe(r) manner: https://github.com/edx/codejail https://github.com/edx/codejail