Re: [Ilugc] SQL Injection vulnerability in Ruby on Rails forces websites to close down

2013-01-10 Thread Arun Khan
On Thu, Jan 10, 2013 at 1:40 PM, Natarajan V wrote: > On Jan 10, 2013 11:50 AM, "Arun Khan" wrote: >> >> On Thu, Jan 10, 2013 at 10:49 AM, Natarajan V wrote: >> > >> > As I was telling Karthick during my session, you can never assume that >> > your code is secure just because you are using some

Re: [Ilugc] SQL Injection vulnerability in Ruby on Rails forces websites to close down

2013-01-10 Thread Madan U Sreenivasan
On 1/10/13, Natarajan V wrote: [snip] > As I was telling Karthick during my session, you can never assume that > your code is secure just because you are using some framework. One of the reasons why I end up always 'inventing' my own framework based on the job at hand - I do feel stupid doing thi

Re: [Ilugc] SQL Injection vulnerability in Ruby on Rails forces websites to close down

2013-01-10 Thread Natarajan V
On Jan 10, 2013 11:50 AM, "Arun Khan" wrote: > > On Thu, Jan 10, 2013 at 10:49 AM, Natarajan V wrote: > > > > As I was telling Karthick during my session, you can never assume that > > your code is secure just because you are using some framework. You > > should always do your home work, and what

Re: [Ilugc] SQL Injection vulnerability in Ruby on Rails forces websites to close down

2013-01-09 Thread Arun Khan
On Thu, Jan 10, 2013 at 10:49 AM, Natarajan V wrote: > Hi, > > A major security vulnerability found in RoR has forced a government > website to close down. The vulnerability exists in ALL versions of RoR > unless you upgraded in the last two days. > > Some Links: > http://blog.phusion.nl/2013/01/0

[Ilugc] SQL Injection vulnerability in Ruby on Rails forces websites to close down

2013-01-09 Thread Natarajan V
Hi, A major security vulnerability found in RoR has forced a government website to close down. The vulnerability exists in ALL versions of RoR unless you upgraded in the last two days. Some Links: http://blog.phusion.nl/2013/01/03/rails-sql-injection-vulnerability-hold-your-horses-here-are-the-fa