RCE (Remote Code Execution) Vulnerability on Ruby
Medium
Vulnerability Details
Hi Ruby,
Here is Shaifullah Shaon (Black_EyE), An Ethical Hacker.
a white hat cyber security researcher from Bangladesh reporting a serious
[3'rd ranking in OWASP] security vulnerability on your system.
I faced a technical security bug called RCE (Remote Code Execution) Vulnerability on Ruby.
Let's follow me...
1. Find any online execution site for ruby. CZ I didn't enough Speach for install ruby in my HDD. ;p
2. Input this code only.
Code:
# Hello World Program in Ruby
system "clear;ls;uname -a;echo RCE in Ruby Language By Black_EyE";
3. As you see, Here have RCE using your Language.
Please See my Video Poc for understand clearly. Hopefully Those are Very critical issue.
Resolve those issue as soon as possible.
Here is proof as video concept: https://youtu.be/XTdSzAbNQ9Q
Thank you
Shaifullah Shaon (Black_EyE)
[email protected]
Actions
View on HackerOneReport Stats
- Report ID: 218342
- State: Closed
- Substate: not-applicable
- Upvotes: 9