<rt id="bn8ez"></rt>
<label id="bn8ez"></label>

  • <span id="bn8ez"></span>

    <label id="bn8ez"><meter id="bn8ez"></meter></label>

    First they ignore you
    then they ridicule you
    then they fight you
    then you win
        -- Mahatma Gandhi
    Chinese => English     英文 => 中文             
    隨筆-221  評論-1047  文章-0  trackbacks-0

    RoR遭遇嚴重的安全危機!

    ?SearchAppSecurity.com story?報道了RoR的一個嚴重的安全漏洞,致使開發(fā)者不得不迅速推出一個安全補丁的版本,而且該版本需要強制升級。

    由于這個錯誤非常嚴重,以至開發(fā)者不得不隱藏這個漏洞的細節(jié),所以升級過程中的人們無法知道如何預防該漏洞帶來的攻擊。

    ? 這樣的官方發(fā)布的安全問題,可謂是給RoR狂熱撲了一盆大冷水。RoR的開發(fā)者們甚至嚇得都不敢公開的這個錯誤。然而這個錯誤只是一個開始,還遠遠沒有結 束。從windows,j2ee,php任何開發(fā)都經(jīng)歷過這個過程。而他們都趨于穩(wěn)定,尤其是j2ee,php在unix下的安全架構更是非常可靠,我們 積累了大量這個領域進行防范的經(jīng)驗。


    原文地址:http://blog.csdn.net/danny_xcz/archive/2006/08/11/1049441.aspx

    -----------------------------------------------------------------------------------------------------------------------

    Ruby on Rails experiences serious security breach


    A serious security vulnerability has forced the creators of Ruby on Rails to issue an immediate upgrade for the software. Version 1.1.5, which is being called a mandatory upgrade, is available now.

    Rails 1.0 and prior, as well as 1.1.3, are not affected. The creators are still trying to determine how contaminated 1.1.0, 1.1.1, 1.1.2, and 1.1.4 are.

    The vulnerability is so critical that the creators aren't disclosing any details so as to prevent attacks and protect people who are still in the process of upgrading.

    From on the Riding Rails blog: "If you have a public Rails site, you MUST upgrade to Rails 1.1.5. The security issue is severe and you do not want to be caught unpatched."

    Rails 1.1.5 is fully drop-in compatible with 1.1.4. It includes only a few bug fixes and no new features.

    "As always, the trick is to do 'gem install rails' and then either changing config/environment.rb, if you're bound to gems, or do "rake rails:freeze:gems" if you're freezing gems in vendor," according to the advisory in the blog posting.

    The creators are continuing their investigation into the breach and promise to issue a full report once it's complete and people have had enough time to upgrade.



    附:Groovy輕松入門——Grails實戰(zhàn)之GORM篇

    posted on 2007-04-22 05:17 山風小子 閱讀(632) 評論(0)  編輯  收藏 所屬分類: Python & Ruby & RoROthers
    主站蜘蛛池模板: 一级毛片免费观看不卡视频| 国产aⅴ无码专区亚洲av麻豆 | 国产精品成人无码免费| 亚洲国产成人久久综合一区| 足恋玩丝袜脚视频免费网站| 亚洲成人在线网站| 99久久免费看国产精品| 亚洲第一永久在线观看| 99久久综合国产精品免费| 国产亚洲中文日本不卡二区| 精品国产一区二区三区免费看| 亚洲熟妇无码八V在线播放| 狠狠久久永久免费观看| 日韩毛片一区视频免费| 99久久精品毛片免费播放| 亚洲午夜未满十八勿入网站2| 人妻在线日韩免费视频| 亚洲伊人久久大香线蕉苏妲己| 69av免费视频| 亚洲 综合 国产 欧洲 丝袜| 亚洲午夜久久久久妓女影院| 久久香蕉国产线看免费| 亚洲国产成人久久三区| 国产国产成年年人免费看片| jzzjzz免费观看大片免费| 亚洲邪恶天堂影院在线观看| 最近中文字幕免费mv视频8| 特级毛片爽www免费版| 国产成人在线观看免费网站| 久久精品无码免费不卡| 亚洲精品日韩中文字幕久久久| 无码高潮少妇毛多水多水免费| 无码 免费 国产在线观看91| 亚洲高清无在码在线无弹窗| 中文字幕在线成人免费看| 亚洲高清无在码在线电影不卡| 蜜桃精品免费久久久久影院| 国产免费无码一区二区| 亚洲中文无码卡通动漫野外 | 亚洲一级毛片免费在线观看| 久久精品国产亚洲AV天海翼|