Python Search – eval(raw_input())
github.com
github.com
>input([prompt]) -> value
>Equivalent to eval(raw_input(prompt)).
Github is turning up these results because that bit of Python is inside the C code as a string documenting the function.
Python 3 does not evaluate what's passed to input(), however. To get the same effect, use eval(input()). [1]
[0]: Limiting it to C examples https://github.com/search?l=c&q=%22eval%28raw_input%28%29%29...
We are not evaling something from a file, or from an internet connection. We are evaling something typed in at the keyboard.
Assuming your python isn't setuid root, anyone at the keyboard could just open a new terminal, type 'python', and start evaling raw_input as much as they like.
Yes.
$ echo foo | python -c 'print raw_input()[::-1]'
oof
$ ps | python -c 'print raw_input()'
PID TTY TIME CMD
But I suppose you could just loop to get around that anyway.Besides, this isn't even low hanging fruit. If you want to really find some terrifying github contents, try to think of a library that is used to access the TTY, say to enter passphrases for ssh/telnet/mount/sudo/etc. in a PRODUCTION environment. Then think how it's api would be used, and search for that. Example below: using expect to enter passphrases:
Example:
https://github.com/search?q=+expect+send+root+ssh&type=Code&...
There is a ton of low hanging fruit out there.
Edit: Not sure why I got downvoted. Developer #1 writes script that prompts technical user for input expecting (as parent did) that stdin will be a local console. Developer #2 later wraps script with a web form so sales/marketing can access the tool as well.
[0] http://en.wikipedia.org/wiki/Read%E2%80%93eval%E2%80%93print...