module

Ruby on Rails Known Secret Session Cookie Remote Code Execution

Disclosed
2013-04-11
Created
2018-05-30

Description

This module implements Remote Command Execution on Ruby on Rails applications.
Prerequisite is knowledge of the "secret_token" (Rails 2/3) or "secret_key_base"
(Rails 4). The values for those can be usually found in the file
"RAILS_ROOT/config/initializers/secret_token.rb". The module achieves RCE by
deserialization of a crafted Ruby Object.

Author

joernchen of Phenoelit joernchen@phenoelit.de

Platform

Ruby

Architectures

ruby

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use exploit/multi/http/rails_secret_deserialization
msf exploit(rails_secret_deserialization) > show targets
...targets...
msf exploit(rails_secret_deserialization) > set TARGET < target-id >
msf exploit(rails_secret_deserialization) > show options
...show and set options...
msf exploit(rails_secret_deserialization) > exploit

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.