Tag Archive for: Rails

Ruby on Rails flaw used to create botnet – ITWorld Canada


ITWorld Canada

Ruby on Rails flaw used to create botnet
ITWorld Canada
A critical vulnerability in the Web application development framework Ruby on Rails is being exploited by hackers to compromise servers and build a botnet. The vulnerability, known as CVE-2013-0156 was the subject of patch released by the Ruby on rails 

and more »

android botnet – read more

Extremely crtical Ruby on Rails bug threatens more than 200,000 sites

Hundreds of thousands of websites are potentially at risk following the discovery of an extremely critical vulnerability in the Ruby on Rails framework that gives remote attackers the ability to execute malicious code on the underlying servers.

The bug is present in Rails versions spanning the past six years and in default configurations gives hackers a simple and reliable way to pilfer database contents, run system commands, and cause websites to crash, according to Ben Murphy, one of the developers who has confirmed the vulnerability. As of last week, the framework was used by more than 240,000 websites, including Github, Hulu, and Basecamp, underscoring the seriousness of the threat.

“It is quite bad,” Murphy told Ars. “An attack can send a request to any Ruby on Rails sever and then execute arbitrary commands. Even though it’s complex, it’s reliable, so it will work 100 percent of the time.”

Read 3 remaining paragraphs | Comments


Ars Technica » Technology Lab