HNHacker News
TopNewBestAskShowJobs

hjr3

5 karma · joined January 7, 2013

submissionscomments
hjr3··on Metasploit Rails 3 Remote Code Execution Hours Away
I don't think defensive programming would have based on the current situation across a number of languages. Basically no serializer in any language PHP, Python, Rails, etc is completely safe. There are known exploits for all of them.

There is lots of magic in rails, but I bet there are a number of popular PHP and Python libraries/frameworks that are unserializing in an unsafe way.