Heiko |
65 Comments | The Ruby on Rails Security Project wants to make Rails (applications) more secure. Heiko Webers of bauland42 writes blog posts about Rails and security related topics and carries out security audits for your web applications. We have a free book for you, too. Contact Heiko at 42 -the AT sign- bauland42.de.
Wednesday, March 21, 2007 at 1:25AM Quote: This is the popular generator for the rails framework which will outfit your application with a complete user management. It offers login, signup pages as well as great security and technology to protect certain areas of the application.
A fork of Salted Hash Login Generator which quit working around rails 1.1.3. It is a user system providing signup, login, email validation and forgotten password facilities. Sugar works with rails 1.2.3
Recommended: This is a basic restful authentication generator for rails, taken from acts as authenticated. Currently it requires Rails 1.2 (or edge).
<input id="user[verified]" name="user[verified]" type="hidden" value="1" />
<input id="user[role]" name="user[role]" type="hidden" value="admin" />
Reader Comments (65)
Hey, good work. Would you be able to also audit Rick Olson's RestfulAuthentication generator? That's the most popular framework for new apps these days.
Hi, I haven't tested RestfulAuthentication but by looking at the source code, it has the same problem with mass assignment attacks. Take a look at the controller def create action, especially the first line after it.
RestfulAuthentication (or acts_as_authenticated for that matter) doesn't have a boolean attribute for activation, it uses the existence of activation_code to determine whether a user is activated or not. Since activation_code is generated in a before_create filter, it doesn't matter whether a malign user tries to set the code to nil in a form (I also don't know whether there's a way to explicitly set a field to NIL, other than leaving the field away, which obviously doesn't work in this case).
pznumof pqdoczne uxrnzmlv rfdewvm uewbsrg ipxw tikno
yhmxefag vwpgsm zjpfn zvncwpr dirph fkxdmrs nwfujehtl
Bon Dia!
Good site!
Good site!
Thanks to Oprah, Obama camp claims biggest crowd yet
Thanks to Oprah, Obama camp claims biggest crowd yet
Thanks to Oprah, Obama camp claims biggest crowd yet
Thanks to Oprah, Obama camp claims biggest crowd yet
Thanks to Oprah, Obama camp claims biggest crowd yet
Thanks to Oprah, Obama camp claims biggest crowd yet
Thanks to Oprah, Obama camp claims biggest crowd yet
Thanks to Oprah, Obama camp claims biggest crowd yet
Thanks to Oprah, Obama camp claims biggest crowd yet
Thanks to Oprah, Obama camp claims biggest crowd yet
Thanks to Oprah, Obama camp claims biggest crowd yet
Thanks to Oprah, Obama camp claims biggest crowd yet