This tweet from today sums it up nicely:

Dear Rails, Welcome to the 'popular enough to care about' club. You will 
> probably be getting owned sideways for a while now.


If you don't already know a bunch of very serious vulnerabilities in Rails 
were announced yesterday. Given that Rails is the startup framework du jour 
I thought it might be worth posting info to SB so you can get yourselves 
patched and secure.

Keep in mind that you don't need to be interesting to attract the attention 
of a hacker - The bad guys want your website, they want your visitors, they 
want your bandwidth. Credit card numbers, passwords etc are a bonus.

Article here:
http://thenextweb.com/insider/2013/01/08/critical-rails-vulnerabilities-discovered-lets-attackers-bypass-authentication-systems-perform-ddos-attacks/

Feel free to ask questions if you have them. 

Cheers
@caseyjohnellis <http://twitter.com/caseyjohnellis> from 
@bugcrowd<http://twitter.com/bugcrowd>

-- 
You received this message because you are subscribed to the Silicon Beach 
Australia mailing list. Vist http://siliconbeachaustralia.org for more

Forum rules
1) No lurkers! It is expected that you introduce yourself.
2) No jobs postings. You can use http://siliconbeachaustralia.org/jobs


To post to this group, send email to
[email protected]
To unsubscribe from this group, send email to
[email protected]
For more options, visit this group at
http://groups.google.com/group/silicon-beach-australia?hl=en?hl=en

Reply via email to