MadeStone

Lab: Exploiting Ruby deserialization using a documented gadget chain

Просмотры:
35
Дата загрузки:
04.12.2023 08:25
Длительность:
00:14:32
Категория:
Лайфстайл

Описание

This lab uses a serialization-based session mechanism and the Ruby on Rails framework. There are documented exploits that enable remote code execution via a gadget chain in this framework.

To solve the lab, find a documented exploit and adapt it to create a malicious serialized object containing a remote code execution payload. Then, pass this object into the website to delete the morale.txt file from Carlos's home directory.

https://github.com/vXqw4NdusPm65jTw/WSA/blob/main/Lab:%20Exploiting%20Ruby%20deserialization%20using%20a%20documented%20gadget%20chain

Источники:

Рекомендуемые видео