Skip to content

Commit 52eb1e9

Browse files
norajKINGSABRI
authored andcommitted
add examples + various fixes
- add ctf-party examples - URI.encode / URI.decode doesn't exist anymore - add more ruby stdlib alternatives - fix formating
1 parent ec8fd68 commit 52eb1e9

1 file changed

Lines changed: 110 additions & 20 deletions

File tree

‎module-0x1-or-basic-ruby-kung-fu/string/conversion.md‎

Lines changed: 110 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -74,6 +74,14 @@ or
7474
"ABCD".chars.map {|c| '\x%x' % c.ord}.join #=> "\\x41\\x42\\x43\\x44"
7575
```
7676

77+
or with [ctf-party][ctf-party]
78+
79+
```ruby
80+
require 'ctf_party'
81+
'ABCD'.to_hex #=> "41424344"
82+
'ABCD'.to_hex(prefixall: '\\x') #=> "\\x41\\x42\\x43\\x44"
83+
```
84+
7785
## Convert Hex to String/Binary
7886

7987
```ruby
@@ -92,6 +100,13 @@ or for raw socket
92100
"41424344".scan(/../).map(&:hex).pack("C*") #=> ABCD
93101
```
94102

103+
or with [ctf-party][ctf-party]
104+
105+
```ruby
106+
require 'ctf_party'
107+
'41424344'.from_hex #=> "ABCD"
108+
```
109+
95110
in-case of binary that is out of `.chr` range. For example you may need to convert an IP-address to hex raw then send it through the socket. The case of just converting it to hex would not work for you
96111

97112
```ruby
@@ -109,6 +124,14 @@ To solve this issue, use pack to convert integers to 8-bit unsigned \(unsigned c
109124
ip.split(".").map(&:to_i).pack("C*") #=> "\xC0\xA8d\n"
110125
```
111126

127+
or with [ctf-party][ctf-party]
128+
129+
```ruby
130+
require 'ctf_party'
131+
'192.168.100.10'.to_hexip #=> "c0a8640a"
132+
'192.168.100.10'.to_hexip(prefixall: '\\x') #=> "\\xc0\\xa8\\x64\\x0a"
133+
```
134+
112135
**Note about hex:** Sometimes you might face non-printable characters, especially when dealing with binary raw. In this case, append **\(**`# -*- coding: binary -*-`**\)** at the top of your file to fix any interpretation issues.
113136

114137
## Convert Hex \(Return address\) to Little-Endian format
@@ -188,22 +211,37 @@ require 'base64'
188211
Base64.encode64 "RubyFu"
189212
```
190213

191-
**Decode**
214+
or with [ctf-party][ctf-party]
192215

193216
```ruby
194-
"UnVieUZ1".unpack('m0')
217+
require 'ctf_party'
218+
'RubyFu'.to_b64 #=> "UnVieUZ1"
195219
```
196220

197-
or
221+
**Decode**
198222

199223
```ruby
200-
Base64.decode64 "UnVieUZ1"
224+
"UnVieUZ1".unpack('m0')
201225
```
202226

203227
{% hint style="info" %}
204228
**TIP:** The string unpack method is incredibly useful for converting data we read as strings back to their original form. To read more, visit the String class reference at www.ruby-doc.org/core/classes/String.html .
205229
{% endhint %}
206230

231+
or
232+
233+
```ruby
234+
require 'base64'
235+
Base64.decode64 "UnVieUZ1"
236+
```
237+
238+
or with [ctf-party][ctf-party]
239+
240+
```ruby
241+
require 'ctf_party'
242+
'UnVieUZ1'.from_b64 #=> "RubyFu"
243+
```
244+
207245
## En/Decode URL String
208246

209247
URL encoding/decoding is well known. From a hacker's point of view, we need it often for client-side vulnerabilities.
@@ -212,22 +250,74 @@ URL encoding/decoding is well known. From a hacker's point of view, we need it o
212250

213251
```ruby
214252
require 'uri'
215-
puts URI.encode 'http://vulnerable.site/search.aspx?txt="><script>alert(/Rubyfu/.source)</script>'
253+
URI('http://vulnerable.site/search.aspx?txt="><script>alert(/Rubyfu/.source)</script>').to_s #=> "http://vulnerable.site/search.aspx?txt=%22%3E%3Cscript%3Ealert(/Rubyfu/.source)%3C/script%3E"
216254
```
217255

218-
**Decoding string**
256+
or
219257

220258
```ruby
221259
require 'uri'
222-
puts URI.decode "http://vulnerable.site/search.aspx?txt=%22%3E%3Cscript%3Ealert(/Rubyfu/.source)%3C/script%3E"
260+
URI::Parser.new.escape 'http://vulnerable.site/search.aspx?txt="><script>alert(/Rubyfu/.source)</script>' #=> "http://vulnerable.site/search.aspx?txt=%22%3E%3Cscript%3Ealert(/Rubyfu/.source)%3C/script%3E"
223261
```
224262

225263
You can encode/decode any non-URL string, of-course.
226264

227-
The above way will encode any non-URL standard strings only \(ex. `<>"{}`\) however if you want to encode the full string use `URI.encode_www_form_component`
265+
The above way will encode any non-URL standard strings only \(ex. `<>"{}`\) however if you want to encode the full string use one of the following methods:
266+
267+
```ruby
268+
require 'uri'
269+
URI.encode_www_form_component 'http://vulnerable.site/search.aspx?txt="><script>alert(/Rubyfu/.source)</script>' #=> "http%3A%2F%2Fvulnerable.site%2Fsearch.aspx%3Ftxt%3D%22%3E%3Cscript%3Ealert%28%2FRubyfu%2F.source%29%3C%2Fscript%3E"
270+
```
271+
272+
or
273+
274+
```ruby
275+
require 'cgi'
276+
CGI.escape 'http://vulnerable.site/search.aspx?txt="><script>alert(/Rubyfu/.source)</script>' #=> "http%3A%2F%2Fvulnerable.site%2Fsearch.aspx%3Ftxt%3D%22%3E%3Cscript%3Ealert%28%2FRubyfu%2F.source%29%3C%2Fscript%3E"
277+
```
278+
279+
or
280+
281+
```ruby
282+
require 'erb'
283+
ERB::Util.url_encode 'http://vulnerable.site/search.aspx?txt="><script>alert(/Rubyfu/.source)</script>' #=> "http%3A%2F%2Fvulnerable.site%2Fsearch.aspx%3Ftxt%3D%22%3E%3Cscript%3Ealert%28%2FRubyfu%2F.source%29%3C%2Fscript%3E"
284+
```
285+
286+
or with [ctf-party][ctf-party]
228287

229288
```ruby
230-
puts URI.encode_www_form_component 'http://vulnerable.site/search.aspx?txt="><script>alert(/Rubyfu/.source)</script>'
289+
require 'ctf_party'
290+
'http://vulnerable.site/search.aspx?txt="><script>alert(/Rubyfu/.source)</script>'.urlencode #=> "http://vulnerable.site/search.aspx?txt=%22%3E%3Cscript%3Ealert(/Rubyfu/.source)%3C/script%3E"
291+
'http://vulnerable.site/search.aspx?txt="><script>alert(/Rubyfu/.source)</script>'.urlencode_component #=> "http%3A%2F%2Fvulnerable.site%2Fsearch.aspx%3Ftxt%3D%22%3E%3Cscript%3Ealert%28%2FRubyfu%2F.source%29%3C%2Fscript%3E"
292+
```
293+
294+
**Decoding string**
295+
296+
```ruby
297+
require 'uri'
298+
URI::Parser.new.unescape "http://vulnerable.site/search.aspx?txt=%22%3E%3Cscript%3Ealert(/Rubyfu/.source)%3C/script%3E" #=> "http://vulnerable.site/search.aspx?txt=\"><script>alert(/Rubyfu/.source)</script>"
299+
```
300+
301+
or
302+
303+
```ruby
304+
require 'uri'
305+
URI.decode_www_form_component "http://vulnerable.site/search.aspx?txt=%22%3E%3Cscript%3Ealert(/Rubyfu/.source)%3C/script%3E" #=> "http://vulnerable.site/search.aspx?txt=\"><script>alert(/Rubyfu/.source)</script>"
306+
```
307+
308+
or
309+
310+
```ruby
311+
require 'cgi'
312+
CGI.unescape "http://vulnerable.site/search.aspx?txt=%22%3E%3Cscript%3Ealert(/Rubyfu/.source)%3C/script%3E" #=> "http://vulnerable.site/search.aspx?txt=\"><script>alert(/Rubyfu/.source)</script>"
313+
```
314+
315+
or with [ctf-party][ctf-party]
316+
317+
```ruby
318+
require 'ctf_party'
319+
"http://vulnerable.site/search.aspx?txt=%22%3E%3Cscript%3Ealert(/Rubyfu/.source)%3C/script%3E".urldecode #=> "http://vulnerable.site/search.aspx?txt=\"><script>alert(/Rubyfu/.source)</script>"
320+
"http://vulnerable.site/search.aspx?txt=%22%3E%3Cscript%3Ealert(/Rubyfu/.source)%3C/script%3E".urldecode_component #=> "http://vulnerable.site/search.aspx?txt=\"><script>alert(/Rubyfu/.source)</script>"
231321
```
232322

233323
## HTML En/Decode
@@ -236,26 +326,28 @@ puts URI.encode_www_form_component 'http://vulnerable.site/search.aspx?txt="><sc
236326

237327
```ruby
238328
require 'cgi'
239-
CGI.escapeHTML('"><script>alert("Rubyfu!")</script>')
329+
CGI.escapeHTML('"><script>alert("Rubyfu!")</script>') #=> "&quot;&gt;&lt;script&gt;alert(&quot;Rubyfu!&quot;)&lt;/script&gt;"
240330
```
241331

242-
Returns
332+
or with [ctf-party][ctf-party]
243333

244-
```text
245-
&quot;&gt;&lt;script&gt;alert(&quot;Rubyfu!&quot;)&lt;/script&gt;
334+
```ruby
335+
require 'ctf_party'
336+
'"><script>alert("Rubyfu!")</script>'.htmlescape # => "&quot;&gt;&lt;script&gt;alert(&quot;Rubyfu!&quot;)&lt;/script&gt;"
246337
```
247338

248339
**Decoding HTML**
249340

250341
```ruby
251342
require 'cgi'
252-
CGI.unescapeHTML("&quot;&gt;&lt;script&gt;alert(&quot;Rubyfu!&quot;)&lt;/script&gt;")
343+
CGI.unescapeHTML("&quot;&gt;&lt;script&gt;alert(&quot;Rubyfu!&quot;)&lt;/script&gt;") #=> "\"><script>alert(\"Rubyfu!\")</script>"
253344
```
254345

255-
Returns
346+
or with [ctf-party][ctf-party]
256347

257-
```text
258-
"><script>alert("Rubyfu!")</script>
348+
```ruby
349+
require 'ctf_party'
350+
"&quot;&gt;&lt;script&gt;alert(&quot;Rubyfu!&quot;)&lt;/script&gt;".htmlunescape # => "\"><script>alert(\"Rubyfu!\")</script>"
259351
```
260352

261353
## En/Decode SAML String
@@ -282,11 +374,9 @@ Returns
282374
"<?xml version=\"1.0\" encoding=\"UTF-8\"?>\r\n<samlp:AuthnRequest xmlns:samlp=\"urn:oasis:names:tc:SAML:2.0:protocol\" ID=\"agdobjcfikneommfjamdclenjcpcjmgdgbmpgjmo\" Version=\"2.0\" IssueInstant=\"2007-04-26T13:51:56Z\" ProtocolBinding=\"urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST\" ProviderName=\"google.com\" AssertionConsumerServiceURL=\"https://www.google.com/a/solweb.no/acs\" IsPassive=\"true\"><saml:Issuer xmlns:saml=\"urn:oasis:names:tc:SAML:2.0:assertion\">google.com</saml:Issuer><samlp:NameIDPolicy AllowCreate=\"true\" Format=\"urn:oasis:names:tc:SAML:2.0:nameid-format:unspecified\" /></samlp:AuthnRequest>\r\n"
283375
```
284376

285-
286-
287377
* [Source](http://stackoverflow.com/questions/3253298/base64-decode64-in-ruby-returning-strange-results)
288378
* **Resources**
289379
* [more about SAML](http://dev.gettinderbox.com/2013/12/16/introduction-to-saml/)
290380

291381

292-
382+
[ctf-party]:https://github.com/noraj/ctf-party

0 commit comments

Comments
 (0)