Collected research
From Arbitrary File Write to RCE in Restricted Rails apps
An arbitrary file write in a Rails app confined to a few writable directories becomes code execution through Bootsnap's compiled-bytecode cache. The attacker forges the cache key for a file the app requires, writes malicious compiled Ruby at its hashed path, then writes a restart file so the server reloads and runs it.
Record
- Researcher
- Research Team Conviso and @conviso
- Published by
- Conviso AppSec
- Date
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Research Team Conviso and @conviso, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .