http://blog.pentesterlab.com/2012/06/cve-2012-2661-exploitat...
since it is already public i'm thinking of adding my own write up
since it is already public i'm thinking of adding my own write up
Anyway, the gist is: if you have an unpatched rails server stop reading this, you need to upgrade RIGHT AWAY.
The vast majority of programmers don't know a thing about security. Anything that can be done to improve that, even in the slightest, is a great thing for this world.
Disclosers gonna disclose. Know what I'm saying?
The URI here was just for people to test if they were vulnerable or not.