Deserialization: Tools

on under Deserialization Tools
1 minute read
Return Home

Ruby Universal Deserialization Gadget

This blog post details exploitation of arbitrary deserialization for the Ruby programming language and releases the first public universal gadget chain to achieve arbitrary command execution for Ruby 2.x. This will be described in the following sections which detail deserialization issues and related work, discovery of usable gadget chains, and finally exploitation of ruby serialization.