Collected research
New Method to Leverage Unsafe Reflection and Deserialisation to RCE on Rails
Unsafe Ruby reflection or Marshal deserialisation in a Rails app becomes remote code execution by constructing a SQLite3 database object whose extensions option loads an attacker-supplied shared library. The file is planted by abusing multipart temporary files and reached through a process file-descriptor path, and it works on a default minimal Rails install.
Record
- Researcher
- Alex Brown
- Published by
- elttam.com
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Alex Brown, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .