Ox Remote Code Execution II

Bookmarked!

This exercise covers how you can gain code execution when an application is using Ox to deserialize data and is running on Ruby 2.7

PRO Hard 2-4 Hrs. 37 Brown Badge
Course

In this lab, you will learn how to exploit Ruby deserialization vulnerabilities using a new payload compatible with recent Ruby versions. You will adapt this payload to work with the Optimized XML (Ox) serialization library, overcoming challenges such as the lack of module support in Ox.

Skills covered
Injection

Ready to practice?

Get access to this lab and 600+ hands-on exercises with a PRO subscription.