Ruby 2.x Universal RCE Deserialization Gadget Chain
elttam.com.au
elttam.com.au
- Java: https://github.com/frohoff/ysoserial
I’m personally very impressed with this research and I think it does a net good, demonstrating that deserialization of Ruby objects in any form is unsafe when you can’t trust the input.
It's tough to think of a use case where anybody would even want to do this. "Hey, let's let users upload.... arbitrary binary representations.... of.... Ruby objects? And then deserialize them! YEAH! PROFIT!!!! SYNERGY!!! WOOOOOOO!!!!"
Previously (for Marshal anyways, not sure about pickle), you would need to know a least a little bit about how the input is being used, so that you could monkeypatch one of the methods eventually used by it. This makes it possible to get RCE without any knowledge of the codebase.
"we want to craft a gadget chain that has no dependencies, gadgets can only be sourced from the standard library"
But, you would still need to find something that unmarshalls unstrusted input. Don't know how hard that is to find.
$ git clone --config=core.gitProxy=awk 'git://BEGIN{system("cowsay pwned > \x2fdev\x2ftty")}/'
Cloning into 'BEGIN{system("cowsay pwned > \x2fdev\x2ftty")}'...
_______
< pwned >
-------
\ ^__^
\ (oo)\_______
(__)\ )\/\
||----w |
|| ||
fatal: Could not read from remote repository.
Please make sure you have the correct access rights
and the repository exists.<bang type="yaml"> #{gadget payload} </bang>
But this has been fixed in Rails since CVE-2013-0156- https://groups.google.com/forum/#!topic/rubyonrails-security...
Is this RCE possible on Rails application having fix for CVE-2013-0156 and using Ruby versions 2 to 2.5 ?