Web Hack List

Other nomination

From Arbitrary File Write to RCE in Restricted Rails apps

An arbitrary file write in a Rails app confined to a few writable directories becomes code execution through Bootsnap's compiled-bytecode cache. The attacker forges the cache key for a file the app requires, writes malicious compiled Ruby at its hashed path, then writes a restart file so the server reloads and runs it.

Record

Researcher
Research Team Conviso and @conviso
Published by
Conviso AppSec
Date

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Research Team Conviso and @conviso, first published at the original source. Preserved copies are kept so the citation survives its host.