Skip to content

Comment on Exploitation of an old Rails vulnerabilityparent

Comments

Doh! I just got the landing page setup, and the signup configured, but never pushed it out.

Try it now.

Thanks

Interesting idea, it looks like you scan the Gemfile.lock (or equivalent) at "deploy" time.

My preference would be to upload that Gemfile.lock to a location, and then it could be scanned as and when new vulnerabilities were detected.

The problem with an upload is that you rely on someone to re-upload when they change their Gems. Changing the locked Gems means a re-check is needed, as they might have switched to bad versions.

Making this automatic is the key part - if you don't get burned very often, you'll eventually forget to do the right thing manually and open yourselves to badness.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.