Ruby on Rails Framework Exceptions

 Original Source: [Sigma source]
Title: Ruby on Rails Framework Exceptions
Status: stable
Description:Detects suspicious Ruby on Rails exceptions that could indicate exploitation attempts
References:
  -http://edgeguides.rubyonrails.org/security.html
  -http://guides.rubyonrails.org/action_controller_overview.html
  -https://stackoverflow.com/questions/25892194/does-rails-come-with-a-not-authorized-exception
  -https://github.com/rails/rails/blob/cd08e6bcc4cd8948fe01e0be1ea0c7ca60373a25/actionpack/lib/action_dispatch/middleware/exception_wrapper.rb
Author: Thomas Patzke
Date: 2017-08-06
modified:2020-09-01
Tags:
  • -'attack.initial-access'
  • -'attack.t1190'
Logsource:
  • category: application
  • product: ruby_on_rails
Detection:
  keywords:
    - 'ActionController::InvalidAuthenticityToken'
    - 'ActionController::InvalidCrossOriginRequest'
    - 'ActionController::MethodNotAllowed'
    - 'ActionController::BadRequest'
    - 'ActionController::ParameterMissing'
  condition:keywords
Falsepositives:
  -Application bugs
Level: medium