macOS Ruby Applications Injection
Last updated
Last updated
Learn & practice AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE) Learn & practice GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)
Kwa kutumia hii env variable inawezekana kuongeza params mpya kwa ruby kila wakati inatekelezwa. Ingawa param -e
haiwezi kutumika kubaini ruby code ya kutekeleza, inawezekana kutumia params -I
na -r
kuongeza folda mpya kwenye maktaba za kupakia na kisha kubaini maktaba ya kupakia.
Unda maktaba inject.rb
katika /tmp
:
Unda popote script ya ruby kama:
Kisha fanya script ya ruby isiyo na mpangilio iitwe na:
Fun fact, inafanya kazi hata na param --disable-rubyopt
:
Learn & practice AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE) Learn & practice GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)