Web Hack List

Collected research

Ransacking your password reset tokens

Rails applications that hand an unfiltered q parameter to the Ransack library expose search matchers such as start and matches over attributes of associated records, turning a search box into a boolean oracle. An attacker reads password reset tokens and password hashes character by character in a few hundred requests. Hasura and older Sequelize expose the same pattern.

Record

Published by
positive.security
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of positive.security, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .