daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ruby-json-pollution.md (1369B)


      1 ---
      2 title: "Ruby on Rails json pollution"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/deserialization/ruby-_json-pollution.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/deserialization/ruby-_json-pollution.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Ruby on Rails `_json` pollution
     14 
     15 ## Basic information
     16 
     17 When a Rails endpoint receives a JSON body whose root value is not a hash, such as an array, the parsed value is exposed under the synthetic `_json` parameter. Depending on the parser and Rails version, an attacker-supplied `_json` member in an object can create an unexpected parameter shape or collide with application logic that also trusts `_json`.<sup>[[1]](#references)</sup>
     18 
     19 This becomes a security issue when validation or authorization checks one parameter representation but a later operation consumes the polluted `_json` value. The following object illustrates attacker-controlled values placed under that reserved-looking key:<sup>[[1]](#references)</sup>
     20 
     21 ```json
     22 {
     23   "id": 123,
     24   "_json": [456, 789]
     25 }
     26 ```
     27 
     28 ## References
     29 
     30 - [1] [Nasty Stereo - The Ruby on Rails `_json` juggling attack](https://nastystereo.com/security/rails-_json-juggling-attack.html)