3 ms·
As a pen tester, I wholeheartedly disagree. It’s probably more common to see unsafe YAML deserialization, rather than directly deserializing marshaled Ruby obje
by HackAllThings 8y ago
As a pen tester, I wholeheartedly disagree. It’s probably more common to see unsafe YAML deserialization, rather than directly deserializing marshaled Ruby objects, but both are impactful and these types of vulnerabilities do exist. Just recently I assessed an application that used unsafe serialization to pass around an object encoded in the value of a cookie. It contained transient data related to the user’s session (e.g. what page they last visited). Last year I assessed an application that allowed users to upload YAML files, which would get parsed and deseralized as Ruby objects. Unfortunately I didn’t have a universal gadget chain then, so I had to note it as theoretically exploitable in my report. That’s troublesome because some clients may take it less seriously.
I’m personally very impressed with this research and I think it does a net good, demonstrating that deserialization of Ruby objects in any form is unsafe when you can’t trust the input.