This one from link 3 caught my eye:
"".__class__.__mro__[2].__subclasses__()[40]("/etc/passwd").read()
Looks to be a Python 2 specific way of trying to read a file in a sneaky way. I say Python 2 specific because Python 3 strings only have 2 supertypes now, so __mro__[2] is out of range, but __mro__[1] is 'object', and I'm guessing they were going for a file like class, but right now object.__subclasses__()[40] points at "mappingproxy".
And the only subclasses of object I can find with a read classmethod are these:
109 <class 'codecs.StreamReaderWriter'>
110 <class 'codecs.StreamRecoder'>
Found with:
for i, x in enumerate("".__class__.__mro__[1].__subclasses__()):
if "read" in dir(x):
print(str(i) + " " + str(x))