Web Hack List

Collected research

New Method to Leverage Unsafe Reflection and Deserialisation to RCE on Rails

Unsafe Ruby reflection or Marshal deserialisation in a Rails app becomes remote code execution by constructing a SQLite3 database object whose extensions option loads an attacker-supplied shared library. The file is planted by abusing multipart temporary files and reached through a process file-descriptor path, and it works on a default minimal Rails install.

Record

Researcher
Alex Brown
Published by
elttam.com
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Alex Brown, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .