ruby-json-pollution.md (1369B)
1 --- 2 title: "Ruby on Rails json pollution" 3 section: "Web Pentesting" 4 sectionSlug: "pentesting-web" 5 sourcePath: "src/pentesting-web/deserialization/ruby-_json-pollution.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/deserialization/ruby-_json-pollution.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Ruby on Rails `_json` pollution 14 15 ## Basic information 16 17 When a Rails endpoint receives a JSON body whose root value is not a hash, such as an array, the parsed value is exposed under the synthetic `_json` parameter. Depending on the parser and Rails version, an attacker-supplied `_json` member in an object can create an unexpected parameter shape or collide with application logic that also trusts `_json`.<sup>[[1]](#references)</sup> 18 19 This becomes a security issue when validation or authorization checks one parameter representation but a later operation consumes the polluted `_json` value. The following object illustrates attacker-controlled values placed under that reserved-looking key:<sup>[[1]](#references)</sup> 20 21 ```json 22 { 23 "id": 123, 24 "_json": [456, 789] 25 } 26 ``` 27 28 ## References 29 30 - [1] [Nasty Stereo - The Ruby on Rails `_json` juggling attack](https://nastystereo.com/security/rails-_json-juggling-attack.html)