From: Robert Klemme Date: 2013-03-28T03:18:16+09:00 Subject: Re: Arbitrary end of a string by using Nullbyte's symbol (Ruby 1.9.3p194) On Wed, Mar 27, 2013 at 6:53 PM, Preth H. wrote: > A couple of days ago I was doing a dummy app using RoR 3.2.12 and ruby > 1.9.3p194.. so after play with the params for a while i realized that > i'm able to skip the file extension by doing > ''' > file="../../../../../etc/passwd\c0000" > @data= File.read('public/'+file+'.txt') > ''' > just like the old PHP versions or some Java versions.. so I though it > was a RoR's bug. therefore I decided to report it with Aron Patterson > (from RoR sec-mailist ). who politely has helped me to figure out that > this is a bug in ruby *1.9.3p194* version. > > The weirdest thing is that I've tested in older versions > (ruby-1.9.2-p320) getting a right outcome from my point of view [ > ArgumentError (string contains null byte) ] but this one particularly > build skip that exception.. > > So my question should be.. Is there any particular reason why in version > of ruby *1.9.3p194* the "string contains null byte" exception is not > deployed? Maybe because there are no null bytes in your example? irb(main):012:0> file="../../../../../etc/passwd\c0000" => "../../../../../etc/passwd\u0010000" irb(main):013:0> file.chars.to_a => [".", ".", "/", ".", ".", "/", ".", ".", "/", ".", ".", "/", ".", ".", "/", "e", "t", "c", "/", "p", "a", "s", "s", "w", "d", "\u0010", "0", "0", "0"] irb(main):014:0> file.chars.each {|c| p c} "." "." "/" "." "." "/" "." "." "/" "." "." "/" "." "." "/" "e" "t" "c" "/" "p" "a" "s" "s" "w" "d" "\u0010" "0" "0" "0" => "../../../../../etc/passwd\u0010000" Even if there were, this seems completely legal: irb(main):015:0> s="a\0b" => "a\u0000b" irb(main):016:0> s.length => 3 irb(main):017:0> s.bytesize => 3 irb(main):018:0> s.chars.to_a => ["a", "\u0000", "b"] But maybe I'm not getting what your issue is. Kind regards robert -- remember.guy do |as, often| as.you_can - without end http://blog.rubybestpractices.com/