yuzu-octopus/PyBreak

Browser-based pyjail payload generator

★ 0Forks 0TypeScriptGitHub ↗Compare

README

PyBreak

Browser-only pyjail payload generator. Zero backend, zero execution — pure string construction.

PyBreak takes intended Python code and jail restrictions, then generates payload variants that bypass those restrictions. All generation runs client-side via TypeScript string manipulation — no eval(), no new Function(), no server calls.

Live demo: yuzu-octopus.github.io/PyBreak


Features

  • 20 one-shot generators across 4 categories — encoding (base64, hex, octal, unicode), character/syntax bypass, composite multi-technique, and advanced CTF patterns
  • Multi-strategy solver — runs 4 independent strategies (DirectRCE one-liners, env manipulation, interactive escapes, recursive gadget resolver) and merges results
  • 180+ gadget chain finder — Typhon-style recursive dependency resolver with 7 categories covering Python 3.9–3.13, 26 builtins recovery paths, subclass walk variants across 41 indices
  • DirectRCE strategy — self-contained one-liners like help(), breakpoint(), exec(input()) for jails that leave builtins accessible
  • Interactive escape strategy — help() → pdb and breakpoint() → pdb techniques (opt-in, requires stdin)
  • Env manipulation strategy — PYTHONINSPECT, BROWSER+antigravity, PYTHONSTARTUP tricks
  • Typhon-style input API — paste raw Typhon constraint syntax (banned_chr=[...], max_length=160) parsed into limitation fields
  • Goal types — Execute Command, Read File, Read Env Var (target field adapts)
  • Execution context — exec, eval, or bare wrappers for encoding generators
  • Generator log — per-generator status (ok/skipped/error) with category breakdown
  • 9 technique transforms — applied centrally after chain resolution (TabReplace, ChrJoin, BracketEscape, DotEscape, Fullwidth, BoolArith, KwSplit, Base64, Hex)
  • Dracula-themed UI — resizable panes, syntax-highlighted code editor, filterable results

Quick Start

bun install
bun run dev          # dev server (port 5173)
bun run typecheck    # TypeScript check
bun run lint         # ESLint
bun run build        # production build → docs/

Documentation

  • IMPLEMENTATION.md — Full architecture, pipeline, technique reference (26+ techniques), gadget chain finder internals (multi-strategy solver, 180+ gadgets), CTF challenge index, Typhon input API, and developer guides

Acknowledgments

Inspired by Typhon Breaker, PyJailBreaker, and Parselmouth.


License

MIT © 2026 yuzu-octopus

Issues