With that said, you can use Metasploit for this too - we just wanted to make a really easy checker for those that wanted a quick OK/NO GO and didn't want to deal with setting Metasploit up.
Metasploit docs here: https://community.rapid7.com/community/metasploit/blog/2013/...
'grep rails Gemfile.lock'
If you don't see a rails version of 3.2.1, 3.1.10, 3.0.19, or 2.3.15 then you are vulnerable. Yes?
I guess in theory an attacker could have compromised your server and changed the rails version number...
Thus, you might be running an old version, but still actually be safe by disabling the vulnerable bits.
3.2.1 is not safe (you probably meant 3.2.11)
3.0.19 is not safe (3.0.20 was released to fix CVE-2013-0333)
2.3.15 is not safe (2.3.16 was released to fix CVE-2013-0333)Actually probing the running app really is the only way to be sure.
edit : I somehow stumbled into the full scanner on the main site rather than using the yaml scanner, my bad.
If you run a scan from our homepage, you're actually looking for a lot more than just the YAML vulnerability (XSS, Mixed Resource, etc.) as our product isn't limited to just the YAML vulnerability.
If you run the scan from https://www.tinfoilsecurity.com/railscheck, then you'll get a quick check for just the YAML vulnerability.
Does that clarify it a bit?
[edit] This is a code analyzer.