File Name Enumeration

Hackerone #33935
Target: Hackerone
Target Module:
Type: Best Practice
Payload: /%5C../etc/passwd
Original: Link
CVE: CVE-2014-7829
Web applications using old versions of Ruby's ActionPack are vulnerable to server file name enumeration.

Affected Ruby Versions Affected: >= 3.0.0 Not affected: < 3.0.0, 4.2.0.beta4 Fixed Versions: 3.2.21, 4.0.12, 4.1.8

For a Ruby instance to be vulnerable to this issue this config must be set:

config.serve_static_assets = true 

How To Perform

  1. Start with a base URL (
  2. Add known unused file (
    1. Note response
  3. Add known file (
  4. Add /%5C.. between the host and the known file (
    1. Repeat and look for a different response from server (