5 ms·
Checkout the lengthy write-up for the original vulnerability. http://ronin-ruby.github.com/blog/2013/01/09/rails-pocs.html http://ronin-ruby.github.com/blog/201
by postmodern_mod3 14y ago
Checkout the lengthy write-up for the original vulnerability.
http://ronin-ruby.github.com/blog/2013/01/09/rails-pocs.html http://ronin-ruby.github.com/blog/2013/01/09/rails-pocs.html
- matthuggins 14y agoThanks for the link, but it looks like that's for CVE-2013-0156 and CVE-2013-0155. This HN post is about CVE-2013-0333. It does look like there's a newer blog post about this issue though: http://ronin-ruby.github.com/blog/2013/01/28/new-rails-poc.html http://ronin-ruby.github.com/blog/2013/01/28/new-rails-poc.h...
- postmodern_mod3 14y agoTook a while to write a new blog post. Still, CVE-2013-0333 relies on the same YAML deserialization technique as CVE-2013-0156, so all the previous information is still relevant.