RSS Ruby on Rails Security Blog
哪吒推荐该订阅
简介:exploring the security of rails and friends.
原站:http://www.rorsecurity.info
标签:ruby
点击立即订阅,“Ruby on Rails Securit...”的内容有更新,哪吒第一时间提醒您
“Ruby on Rails Security Blog”的内容更新
累计:56 篇(自 2007-04-04 起)
更新:约11篇/年,最后更新1226 天前
Ruby on Rails Security Blog
I'm taking part in the Rails Guide Hackfest which is "an attempt to improve Rails documentation and make the barrier to entry as low as possible." You can take a look at it here: http://guides.rails.info/securing_rails_applications/security.htmlIf you find a typo or if you'd like to contribute, the Lighthouse ticket is here:http://rails.lighthouseapp.c... (316 天前)
Ruby on Rails Security Blog
An SQL Injection vulnerability has been found in Rails. The issue affects Rails < 2.1.1, namely the :limit and :offset parameters that are not correctly sanitized:Person.find(:all, :limit => "10; DROP TABLE users;") A possible attack will work only if you allow the user control these two values as in User.find(:all, :limit => 10, :offset => param... (316 天前)
Ruby on Rails Security Blog
Here is a security announcement for the REXML library (links by me) in the Ruby news:There is a DoS vulnerability in the REXML library used by Rails to parse incoming XML requests. A so-called "XML entity explosion" attack technique can be used for remotely bringing down (disabling) any application which parses user-provided XML. Most Rails applications... (316 天前)
Ruby on Rails Security Blog
Here is the news from the Rails Log: Drew Yao at Apple uncovered a handful of nasty security vulnerabilities affecting all current versions of Ruby. The details are still under wraps because an attacker can DoS you or possibly execute arbitrary code—holy crap! Better upgrade sooner than later. According to the official Ruby security advisory, the vuln... (316 天前)
Ruby on Rails Security Blog
Security is not easy-to-use, not fancy and it is hard to remember all those nasty attack methods. So there are automatic security checks, firewalls, helpers and a lot more. They are built to make your application more secure. But automatic security tools can't help you to find logic faults. What if you have a Cross-Site scripting scanner that checks each... (316 天前)
Ruby on Rails Security Blog
Two weeks ago, the Debian package of OpenSSL has been found to generate weak keys (CVE). Here's the news from Heise online:Security expert Luciano Bello has now discovered a critical vulnerability in the OpenSSL package which makes the random number sequences, and therefore keys generated, predictable. The problem only affects Debian and distributions d... (316 天前)
Ruby on Rails Security Blog
Radiant is a no-fluff, open source content management system designed for small teams, written in Ruby on Rails.I have found several security problems in Radiant, informed the vendor, who fortunately removed the (critical) vulnerabilities quickly. As an update is available, I'm now publishing information about the vulnerabilites.CSRF in a real world ap... (316 天前)
订阅者 ( 3 )
martin
IceskYsl
jackeyho
相关订阅源
RSS ITeye资讯频道

ITeye每日IT资讯 - Java, Ruby, AJAX, Agile, 互联网, 软件行业资讯

标签: javaeye java javaeye新闻快报 it ajax

指数 | 336人订阅  

RSS RubyLearning Blog

Ruby helps programmers have more fun!

标签: ruby

指数 | 5人订阅  

RSS 开源中国社区最新软件

开源中国社区——找到您想要的开源软件,分享和交流

标签: 开源 程序员 ruby java

指数 | 15人订阅  

RSS Ruby and Rails jobs: jobs.rubynow.com

ruby jobs available around the world!

标签: ruby

指数 | 2人订阅  

我要反馈