<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>Moves On Rails: Rails Security</title>
    <link>http://www.movesonrails.com/articles/2007/09/20/rails-security</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description>New ways to look at software</description>
    <item>
      <title>Rails Security</title>
      <description>&lt;embed width="477" height="390" allowfullscreen="true" allowscriptaccess="always" quality="high" bgcolor="#FFFFFF" name="player" id="player" src="http://s3.amazonaws.com/slideshare/player.swf?useHttp=1&amp;inContest=0&amp;totalSlides=10&amp;startSlide=1&amp;presentationId=114381&amp;doc=rails-security-bart-ten-brinke1352&amp;321" type="application/x-shockwave-flash"/&gt;
&lt;br/&gt;
&lt;br/&gt;


After a security presentation at RailsConfEurope 2007, I found a lot was missing, so I made this.

I didn’t finish it in time for reject conf, so I posted 
it here. Now it's time for me to go on vacation! See you next week!</description>
      <pubDate>Thu, 20 Sep 2007 19:28:00 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:1b884a8c-82cd-4c7a-a828-f0c72fb55c32</guid>
      <author>bart.tenbrinke@movesonrails.com (Bart ten Brinke)</author>
      <link>http://www.movesonrails.com/articles/2007/09/20/rails-security</link>
      <category>Rails</category>
      <category>Security</category>
      <category>rails</category>
      <category>XXS</category>
      <category>railsconf</category>
      <category>europe</category>
      <category>2007</category>
    </item>
    <item>
      <title>"Rails Security" by Bart ten Brinke</title>
      <description>The to_json XSS exploit is finally fixed in rails 1.2.4 :)!</description>
      <pubDate>Thu, 11 Oct 2007 10:06:28 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:f308e960-323c-42da-a6fd-d05e2293110a</guid>
      <link>http://www.movesonrails.com/articles/2007/09/20/rails-security#comment-98</link>
    </item>
    <item>
      <title>"Rails Security" by Andre Foeken</title>
      <description>Tnx Heiko, it looks great :)</description>
      <pubDate>Tue, 25 Sep 2007 08:35:38 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:175d9258-5155-436e-a2d6-380c70f53b1f</guid>
      <link>http://www.movesonrails.com/articles/2007/09/20/rails-security#comment-85</link>
    </item>
    <item>
      <title>"Rails Security" by Heiko Webers</title>
      <description>I created a Rails security cheatsheet as a follow-up.
&lt;a href="http://www.rorsecurity.info/2007/09/24/ruby-on-rails-security-cheatsheet/"&gt;http://www.rorsecurity.info/2007/09/24/ruby-on-rails-security-cheatsheet/&lt;/a&gt;</description>
      <pubDate>Tue, 25 Sep 2007 00:23:17 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:16b1f48c-447e-40f3-b3a4-59cd432049e3</guid>
      <link>http://www.movesonrails.com/articles/2007/09/20/rails-security#comment-84</link>
    </item>
    <item>
      <title>"Rails Security" by Bart ten Brinke</title>
      <description>Thanks Joseph, I fixed it.</description>
      <pubDate>Fri, 21 Sep 2007 10:29:17 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:726eaa6e-a497-420d-bda9-5b06aba115fb</guid>
      <link>http://www.movesonrails.com/articles/2007/09/20/rails-security#comment-78</link>
    </item>
    <item>
      <title>"Rails Security" by Heiko Webers</title>
      <description>Thanks. You can go on reading at &lt;a href="http://www.rorsecurity.info"&gt;http://www.rorsecurity.info&lt;/a&gt;</description>
      <pubDate>Fri, 21 Sep 2007 09:55:25 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:bbd02147-efff-4294-8ebe-52cfa2cf8e03</guid>
      <link>http://www.movesonrails.com/articles/2007/09/20/rails-security#comment-77</link>
    </item>
    <item>
      <title>"Rails Security" by Joseph</title>
      <description>Typo on slide 3:

Person.find(:first, :conditions =&amp;gt; "name = ?", [name])

should be

Person.find(:first, :conditions =&amp;gt; ["name = ?", name])</description>
      <pubDate>Fri, 21 Sep 2007 05:07:31 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:8496b6ad-1daf-4630-b392-b9cd58736ecd</guid>
      <link>http://www.movesonrails.com/articles/2007/09/20/rails-security#comment-76</link>
    </item>
    <item>
      <title>"Rails Security" by Pratik</title>
      <description>In addition to what Bart said/presented, make sure you don't trust strip_links() and strip_tags().

&lt;a href="http://dev.rubyonrails.org/ticket/8877"&gt;http://dev.rubyonrails.org/ticket/8877&lt;/a&gt;</description>
      <pubDate>Thu, 20 Sep 2007 21:42:41 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:8c26c603-68a8-47bc-81ea-db3421342b96</guid>
      <link>http://www.movesonrails.com/articles/2007/09/20/rails-security#comment-75</link>
    </item>
    <item>
      <title>"Rails Security" by Leon Berenschot</title>
      <description>the presentation @ railsconf missed a lot of topics indeed! Expected more out of it....

maybe next year :)</description>
      <pubDate>Thu, 20 Sep 2007 20:18:19 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:cdf52809-e797-478b-be73-f5ed0b1f3d6f</guid>
      <link>http://www.movesonrails.com/articles/2007/09/20/rails-security#comment-74</link>
    </item>
  </channel>
</rss>
