3 ms·
Does ruby's Marshal have the same problems that python's pickle have? Could you construct a valid Marshal bitsting that when loaded would run malicious code?
by icepick 15y ago
Does ruby's Marshal have the same problems that python's pickle have? Could you construct a valid Marshal bitsting that when loaded would run malicious code? Is this exposing folks to a MITM attack on rubygems?
- alexrothenberg 15y agoThere's another HN thread that says "Ruby's Marshal library is not quite as blatantly insecure as pickle..." http://news.ycombinator.com/item?id=813306 http://news.ycombinator.com/item?id=813306.
- tptacek 15y agoI'd be willing to stake some money on a bet that they're going to regret the decision to build key Ruby infrastructure on Marshal, say, within 12 months. Having said that, I cannot at this moment tell you how to take over a Ruby runtime with a malicious Marshal byte string.
- qrush 15y agoAFAIK Marshal is pretty safe, it's not the most safe or reliable data transport BUT it is on everyone's machine who has Ruby, on all versions. I'd much rather be using JSON but I was told Marshal or plaintext...I'll go with Marshal. :/
- evanphx 15y agoI don't know what the specific issue with pickle is, but ruby's Marshal format is pretty bulletproof at this point. It is a data only format with pretty strict verification of the stream as it builds the object tree. Also, Marshal doesn't allow any kind of code to be included into the stream, so there is no ability for stream to perform remote code injection. Marshal call back into Ruby for non-builtin types, but it does so by simply calling a method on the constant and passing either the raw Marshal data or a previous created object tree. This provides enough protection that there haven't been any reported cases of it being exploited and no know issues exist with it.
- moeffju 15y agoWhat about the old Marshal problems? I just played with Marshal on my rails console again and it seems it still encapsulates all sorts of implementation details. I haven't tried whether it's now compatible across Ruby versions, but I recall the Marshal format changed a few times, introducing incompatibility. tl;dr: Why, oh why, Marshal, and not, say, JSON?
- evanphx 15y agoNot sure what you mean by Marshal having implementation details in the bitstream, it doesn't. Marshal has been reimplemented in many different implementations just fine. As for why not JSON, because there is no JSON parser as part of the standard library and rubygems needs to be extremely careful about what dependencies it has.
- chc 15y agoAFAIK, Ruby's Marshal only calls internal stuff like allocate and special Marshal methods (e.g. marshal_dump and marshal_load) on classes in the Marshal data. It doesn't even actually use new or initialize to create instances, and it doesn't go through methods to set up the object. So unless you have a class that overrides Marshal hooks or Ruby internals in an insecure way, it shouldn't allow arbitrary code execution (barring buffer overflows and the like that could allow arbitrary code execution from any function). Basically, I'm not convinced Marshal is necessarily any more risky than something like YAML would be, even though it feels scarier. But I haven't done an extensive audit or anything — I just looked over the Marshal code a while back because I was curious what it was doing.