tpaidakis▌
Writeups About

Broken-Access-Control

2026-08-02 10 min read ruby-on-railsbroken-access-controlsecret-sharingnil-comparisonpassword-pusher

Who owns this secret? Nobody. Great, that's me: deleting secrets in Password Pusher

An unauthenticated visitor holding only a Password Pusher link could permanently destroy the secret behind it, even with deletable_by_viewer turned off, because the ownership check compared two nils and Ruby said they matched.

Theodosis Paidakis · Offensive Security
RSS