❌

Normal view

Received yesterday β€” 9 August 2026 ⏭ /r/netsec - Information Security News & Discussion

Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village)

Write once, shell everywhere. Sun Microsystems didn't mean it like this.

Talk from today at DEF CON's Bug Bounty Village. Full technique catalog graded for distroless containers, an errno path oracle for black-box target fingerprinting, and three minimal-guessing techniques: bash fd/255, Rails schema_cache.yml deserialization, and a Node.js worker path overwrite without process restart.

submitted by /u/ZealousidealHunter80
[link] [comments]
Received β€” 30 July 2026 ⏭ /r/netsec - Information Security News & Discussion

KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066)

Active Storage's default vips variant processor exposes an arbitrary file read that chains to RCE on stock Rails 7.x and 8.x, where the app serves back processed variants of user-supplied images. No authentication required in certain setups. Only vips is affected, Magick is not.

Patched in 7.2.3.2, 8.0.5.1, and 8.1.3.1, and the fix requires libvips 8.13+. Chain and PoC withheld while patches roll out.

submitted by /u/ZealousidealHunter80
[link] [comments]
Received β€” 24 July 2026 ⏭ /r/netsec - Information Security News & Discussion
❌