Rails Remote Code Execution Vulnerability

For those friends with rails apps. A nasty Remote Code Execution Vulnerability affecting Ruby on Rails was announced on Jan 09, 2013 https://groups.google.com/forum/?fromgroups=#!topic/rubyonrails-security/61bkgvnSGTQ

To see if your install is affected try out the following steps:

curl -i -H "Content-Type: application/xml" -X POST -d '<id type="yaml">--- !ruby/object:ActionController::Base bar: 1</id>' … 
    

read more | Sun 13 Jan 2013, 00:03 | tags: Ruby on Rails | 0 comments

Sapporo Ruby Conference 2012

This year, 2012, I attended the Sapporo Ruby Conference for the first time. This was the second ruby conference I had ever been to. The first one was RubyKaigi2011.

I have to admit the Sapporo one was a lot more fun but lighter weight on the talks. So …

read more | Tue 02 Oct 2012, 23:49 | tags: conference, Ruby | 0 comments

Yapc::Asia 2012

 

From Scrapbook Photos

The worlds biggest YAPC

I attended my third YAPC::Asia conference in September of 2012. The new venue …

read more | Tue 02 Oct 2012, 23:07 | tags: conference, Perl, YAPC | 0 comments

Introducing Liam

From Scrapbook Photos

read more | Sun 06 Nov 2011, 02:07 | tags: geek | 0 comments

Do you have meat?

 

Kaori and I went out for supplies (the new word for food shopping here in Japan) earlier today. There were a lot more people than usual walking around.

Some were carrying bags from the local shop, others were simply taking a walk, and some were queuing …

read more | Sun 13 Mar 2011, 14:28 | tags: Japan, Japan Quake 2011 | 1 comments