Ruby _json pollution

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

์ด๊ฒƒ์€ ํฌ์ŠคํŠธ์˜ ์š”์•ฝ์ž…๋‹ˆ๋‹ค https://nastystereo.com/security/rails-_json-juggling-attack.html

๊ธฐ๋ณธ ์ •๋ณด

๋ณธ๋ฌธ์— ํ•ด์‹œํ•  ์ˆ˜ ์—†๋Š” ์ผ๋ถ€ ๊ฐ’(์˜ˆ: ๋ฐฐ์—ด)์„ ์ „์†กํ•˜๋ฉด _json์ด๋ผ๋Š” ์ƒˆ ํ‚ค์— ์ถ”๊ฐ€๋ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ๊ณต๊ฒฉ์ž๊ฐ€ ์›ํ•˜๋Š” ์ž„์˜์˜ ๊ฐ’์œผ๋กœ _json์ด๋ผ๋Š” ๊ฐ’์„ ๋ณธ๋ฌธ์— ์„ค์ •ํ•˜๋Š” ๊ฒƒ๋„ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฐ ๋‹ค์Œ, ์˜ˆ๋ฅผ ๋“ค์–ด ๋ฐฑ์—”๋“œ๊ฐ€ ๋งค๊ฐœ๋ณ€์ˆ˜์˜ ์ง„์œ„๋ฅผ ํ™•์ธํ•˜์ง€๋งŒ _json ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์–ด๋–ค ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•˜๋Š” ๊ฒฝ์šฐ, ๊ถŒํ•œ ์šฐํšŒ๋ฅผ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

{
"id": 123,
"_json": [456, 789]
}

์ฐธ๊ณ  ๋ฌธํ—Œ

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ