Security Announcement for Devise (Rails authentication solution)
blog.plataformatec.com.br
blog.plataformatec.com.br
User.where(password_token: params[:password_token])
You could make `params[:password_token]` return `{ "$ne" => "1" }` and effectively get any record from the database in MongoDB ORMs. So we limit the set of input values you can pass as argument for a while now. This is also why our patches were so simply, the whole sanitization infra structure was already there.We were not able to test all ORMs and databases (because we would need to effectively test combinations of those) but we could verify the problem does not happen for PostgreSQL nor SQLite3. That's why you must upgrade if you don't want to take any risks.
I had a different guess: Rails has gotten so popular that it's worth investing time as a blackhat because there will be payoff.
Of course, if the rails community responds quite rapidly, the return-on-effort for the black hats drops substantially. (hint hint)
Well, not quite. In security there's a fundamental imbalance between attackers and defenders: a defender needs to find every bug, where an attacker only needs to find one. At the end of the day, if it's a platform that's worth attacking, attackers will always have the upper hand. This is why finding and fixing individual bugs is not nearly as effective as eliminating whole classes of bugs; of course, it's much cheaper to do.
Rails has been pretty good on the whole, in terms of security. Given the size and wide distribution of the platform, it's held up impressively well. Of course, the last couple bugs have marred that a bit, and there are definitely places where Rails apps have traditionally failed badly (e.g. mass assignment).
If this is the bug I think it is (from following joernchen), it has a lot more to do with the "MySQL is terrible" post from a few days back than it does with Rails/Devise.
The recent remote code execution bug was so bad that I think it is in fact legit to worry about how many people had been running around with it months or years before disclosure.
if you don't have anything that is enforcing types then you are fucked :) it is ok to have untyped (or weakly typed) db and statically typed frontend. it is ok to have typed db and dynamically typed frontend. but if you have untyped db and dynamically typed frontend you are in for a world of pain.