Ruby on Rails SQL Injection
seclists.org
seclists.org
I thought that SQL injection was "mostly" a thing of the past with newer frameworks such as Rails and Django. I mean, short of concatenating your query string together, it is much harder to set yourself up for failure.
It's the first query, the metadata one, that applies the passed arguments in a raw form directly to the query. The exploit takes place inside of a 'show' operation. It's totally unprotected and lets you run pretty much any select you're interested in.
It also goes beyond prepared statements - the metadata query in question is totally separate from the one specified by any parameterized query you'd pass using something like ('id = ?', params[:id]). So essentially, as a developer, you can't do anything better. This is kind of on the framework side alone :/
You can see those tests here:
http://seclists.org/oss-sec/2012/q2/att-504/3-2-sql-injectio...
(this is for 3.2, you can change the patch name for 3.1, etc.)
When you pass nested query parameters such as "id[a]=b&id[c]=d", Rails will parse it as parameters :id => {'a' => 'b', 'c' => 'd'}
If you use where(:id => params[:id]) it will become where(:id => {'a' => 'b', 'c' => 'd'})
And when Rails convert that to SQL statement, something can be exploited (though it's not mentioned in the report).
gem 'rails', '3.2.6'
I also had to run "bundle update railties" to fix a couple of dependences. $ bundle update rails
$ bundle install
should bring you up to speed.Thanks to everyone who upvoted and made the comment that it requires a whole new patch/upgrade, I would've missed it otherwise.
This is probably a case in which editorializing the submission title ("This is brand new from last week") would've been a good service
CVE-2012-2695
Please note, this vulnerability is a variant of CVE-2012-2661, even if you upgraded to address that issue, you must take action again.
http://benmmurphy.github.com/blog/2012/05/15/abusing-dynamic...
Around me there are many times more Rails apps than Sinatra apps. I do believe that the increased exposure of Rails makes it more likely to detect vulnerabilities over there.
This approach will be a hard sell for Father O'Reilly and Dwight David "Ike" Eisenhower
Same for validations, foreign keys, primary keys, indexes, enumerations, etc. (/rant)