To whom it may concern:
https://groups.google.com/forum/?fromgroups=#!topic/rubyonrails-security/DCNTNp_qjFM
https://groups.google.com/forum/?fromgroups=#!topic/rubyonrails-security/DCNTNp_qjFM
it only affects people who use dynamic finders (Post.find_by_id), not normal ORM shit (Post.whereid, params[:id]))
fucking A!
nb4 Rob
nb4 Matt
nb4 Darrin
nb4 Lee
FUCKING YES!!!!
Thank god PHP has never has any serious exploits like this. Yes, I know Rails is a framework and not a language, but who uses Ruby for web dev and doesn't use Rails?
lot's of people do. we have a ton of components of serpIQ that are private internal APIs that have nothing to do with Rails.
D is using Sinatra IIRC.
Thank god PHP has never has any serious exploits like this. Yes, I know Rails is a framework and not a language, but who uses Ruby for web dev and doesn't use Rails?
jake's fancy, I'm boring