Web Hack List

Collected research

From Arbitrary File Write to RCE in Restricted Rails apps

An arbitrary file write in a Rails app confined to a few writable directories becomes code execution through Bootsnap's compiled-bytecode cache. The attacker forges the cache key for a file the app requires, writes malicious compiled Ruby at its hashed path, then writes a restart file so the server reloads and runs it.

Record

Researcher
Research Team Conviso and @conviso
Published by
Conviso AppSec
Date
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Research Team Conviso and @conviso, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .