Manfred Stienstra

What's New in Edge Rails: The Security Edition

XSS Vulnerability in Ruby on Rails

There is a vulnerability in the escaping code for the form helpers in
Ruby on Rails. Attackers who can inject deliberately malformed unicode
strings into the form helpers can defeat the escaping checks and inject
arbitrary HTML.

The Camping Episode II - Ruby on Rails Podcast

After a month, Camping Episode II!

  • Chris van Pelt on his cropper and presenter apps.
  • Manfred Stienstra talks about his HTTP authentication library for Camping and also UTF-8 encoding in “that other web framework.”
Syndicate content