Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So does Apache's mod_security... but this isn't a normal SQLi and I certainly wouldn't rely on that saving you.


[deleted]


I'm not a Ruby developer, but keeping any application up-to-date is a necessity. If a server is connected to a network, it is already vulnerable.


Given the nature of this exploit it's unlikely to weed out anything at all, unless they've pushed something out to look specifically for this case.


Since I haven't seen the exploit, I don't know that it will do anything at all!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: