#tip: if you find SQL inj in a rails app and it uses e.g. "serialize :options" you can put RCE payload in there. Mass assignment cannot :(
0 replies
1 retweet
0 favorites
Egor Homakov