The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Exploiting Ruby deserialization using a documented gadget chain

Aman | Last updated: Jul 28, 2020 09:32PM UTC

Here is One line in Solution that. Browse the web to find the "Ruby 2.x Universal RCE Gadget Chain" by Luke Jahnke. But i am not able to understand that which is Luke Jahnke script. because here is many more scripts by name Luke Jahnke. can you share Real script of Luke Jahnke for this lab. I have tired from many days and stucking here. can help me?

Uthman, PortSwigger Agent | Last updated: Jul 29, 2020 09:00AM UTC

Hi Aman, I think the lab is referring to this blog post: https://www.elttam.com/blog/ruby-deserialization/

Max | Last updated: Aug 20, 2021 10:21AM UTC