Ruby on Rails Security Project

Exploring the Security of Rails and friends.

Ruby on Rails Security Project header image 4

Entries from March 2008

[WebAppSec] Sign-in seals against phishing

March 13th, 2008 · 7 Comments

There's a new sign-in seal on the Yahoo! login page, which is intended to make phishing attacks more unlikely.
A sign-in seal is a secret message or photo that Yahoo! will display on this computer only. Look for it every time you sign in to make sure you're on a genuine Yahoo! site. If the message, […]

[Read more →]

Tags: WebAppSec

Intranet and Admin Security

March 3rd, 2008 · No Comments

These days the intranet is coming back. I heard it a couple of times: Our intranet is safe, there's an authentication system and it can be accessed  by hosts from our local IP range only, but no, there are no further security measures. If someone manages to get in, he will be able to do […]

[Read more →]

Tags: Rails · XSS and Rails