<rt id="bn8ez"></rt>
<label id="bn8ez"></label>

  • <span id="bn8ez"></span>

    <label id="bn8ez"><meter id="bn8ez"></meter></label>

    First they ignore you
    then they ridicule you
    then they fight you
    then you win
        -- Mahatma Gandhi
    Chinese => English     英文 => 中文             
    隨筆-221  評論-1047  文章-0  trackbacks-0

    RoR遭遇嚴重的安全危機!

    ?SearchAppSecurity.com story?報道了RoR的一個嚴重的安全漏洞,致使開發者不得不迅速推出一個安全補丁的版本,而且該版本需要強制升級。

    由于這個錯誤非常嚴重,以至開發者不得不隱藏這個漏洞的細節,所以升級過程中的人們無法知道如何預防該漏洞帶來的攻擊。

    ? 這樣的官方發布的安全問題,可謂是給RoR狂熱撲了一盆大冷水。RoR的開發者們甚至嚇得都不敢公開的這個錯誤。然而這個錯誤只是一個開始,還遠遠沒有結 束。從windows,j2ee,php任何開發都經歷過這個過程。而他們都趨于穩定,尤其是j2ee,php在unix下的安全架構更是非常可靠,我們 積累了大量這個領域進行防范的經驗。


    原文地址:http://blog.csdn.net/danny_xcz/archive/2006/08/11/1049441.aspx

    -----------------------------------------------------------------------------------------------------------------------

    Ruby on Rails experiences serious security breach


    A serious security vulnerability has forced the creators of Ruby on Rails to issue an immediate upgrade for the software. Version 1.1.5, which is being called a mandatory upgrade, is available now.

    Rails 1.0 and prior, as well as 1.1.3, are not affected. The creators are still trying to determine how contaminated 1.1.0, 1.1.1, 1.1.2, and 1.1.4 are.

    The vulnerability is so critical that the creators aren't disclosing any details so as to prevent attacks and protect people who are still in the process of upgrading.

    From on the Riding Rails blog: "If you have a public Rails site, you MUST upgrade to Rails 1.1.5. The security issue is severe and you do not want to be caught unpatched."

    Rails 1.1.5 is fully drop-in compatible with 1.1.4. It includes only a few bug fixes and no new features.

    "As always, the trick is to do 'gem install rails' and then either changing config/environment.rb, if you're bound to gems, or do "rake rails:freeze:gems" if you're freezing gems in vendor," according to the advisory in the blog posting.

    The creators are continuing their investigation into the breach and promise to issue a full report once it's complete and people have had enough time to upgrade.



    附:Groovy輕松入門——Grails實戰之GORM篇

    posted on 2007-04-22 05:17 山風小子 閱讀(626) 評論(0)  編輯  收藏 所屬分類: Python & Ruby & RoROthers
    主站蜘蛛池模板: 国产片AV片永久免费观看| 免费下载成人电影| 亚洲AV中文无码乱人伦| 亚洲成a人无码亚洲成www牛牛 | 亚洲ts人妖网站| 国产精品视频免费观看| 亚洲国产成AV人天堂无码| ww在线观视频免费观看| 亚洲一区二区三区播放在线| 4虎永免费最新永久免费地址| 亚洲国产高清美女在线观看| 三年片在线观看免费大全| 亚洲日韩一区精品射精| 免费观看日本污污ww网站一区| 国产成人久久精品亚洲小说| 亚洲麻豆精品国偷自产在线91| 91在线视频免费观看| 99亚洲精品高清一二区| 久久不见久久见中文字幕免费| 久久久久亚洲精品无码网址色欲 | 亚洲国产精品无码久久SM| 久久久久久久岛国免费播放| 亚洲国色天香视频| 国产高清免费的视频| 中文字幕视频免费在线观看| 亚洲国产天堂久久综合网站| 免费可以在线看A∨网站| 黄页网站在线视频免费| 亚洲精品二区国产综合野狼| 人与禽交免费网站视频| 综合一区自拍亚洲综合图区| 国产国拍亚洲精品mv在线观看| 18禁网站免费无遮挡无码中文| 亚洲AV永久无码精品一福利| 亚洲一区二区三区香蕉| 在线看免费观看AV深夜影院| 搜日本一区二区三区免费高清视频| 亚洲日本在线观看| 免费二级毛片免费完整视频| 成人性生交大片免费看中文| 亚洲乱妇熟女爽到高潮的片|