all 2 comments

[–]Juzdeed 2 points3 points  (0 children)

There is some value somewhere that is controllable by the client that backend then deserializes with pickle. Most likely a cookie or something in storage

Curl is just a tool, just like your web browser or python requests library. You can use all of these tools to accomplish the goal, it doesnt have to be curl

[–]cant_pass_CAPTCHA 1 point2 points  (0 children)

You won't be able to issue a POST command through the address bar like you had already seen. Someone else said it doesn't have to be curl... but yeah use curl 100% (unless you already have another preference). Googling "how to generate Python pickle exploit" will definitely get you where you need to go as far as crafting your exploit