4 ms·
Yes, exactly. This is only directly exploitable if the user can submit a hash with symbol keys. Otherwise, it seems like it would take some unusual code path in
by InAnEmergency 14y ago
Yes, exactly. This is only directly exploitable if the user can submit a hash with symbol keys. Otherwise, it seems like it would take some unusual code path in the app to exploit the vulnerability.
The original post of the problem goes like this:
1. Gain an application's secret key, used to sign session cookies.
2. Inject a marshalled hash with _symbol_ keys into the session cookie, sign it with the secret key.
3. Now you can exploit the SQL vulnerability in the dynamic finders, assuming the session value is used directly as input.