Wrong confirmation ID
  • Email
  • Favorite
  • Download
  • Embed
  • Private Content

Ruby on Rails Security

by Jonathan Weiss on Jan 03, 2008

  • 39,961 views

The slides from the 24C3 session "Ruby on Rails Security" by Jonathan Weiss, 30.12.2007. ...

The slides from the 24C3 session "Ruby on Rails Security" by Jonathan Weiss, 30.12.2007.

Even though Ruby on Rails introduces a lot of best practices to the developer, it is still quite easy for an imprudent programmer to forget that every web application is a potential target. Web application attacks like Cross Site Scripting or Cross Site Request Forgery are very popular these days and every Rails developer should have an idea about the different possibilities that his application presents to an attacker.

This talk will cover most of the common web application vulnerabilities like Cross Site Scripting and Cross Site Request Forgery, SQL and Code injection, and deployment security and how they apply to Rails. Further Ruby on Rails specific issues like Rails plugin security, JavaScript/Ajax security, and Rails configuration will be examined and best practices introduced.

Accessibility

Categories

Tags

rails rubyonrails xss security validation ruby ruby on rails ror seguridad web xxs webapp csrf systems web2.0 ror security subversion segurança sql rail pertitor 24c3 ddos rails security apache on piston railssecurity dev

More...

Upload Details

Uploaded via SlideShare as Adobe PDF

Usage Rights

© All Rights Reserved

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel

44 Embeds 2,560

http://blog.innerewut.de 2100
http://www.informatik-student.de 176
http://techvideos.humourbox.info 61
http://www.slideshare.net 50
http://blog.peritor.com 42
http://www.planetrubyonrails.org 35
http://weijing329.blogspot.com 19
http://10.10.10.5 12
http://weijing329.wordpress.com 11
http://agileweb.org 6
http://planetrubyonrails.org 5
http://mergejil.blogspot.com 4
http://quantumcomputernews.com 2
http://guardrobots.com 2
http://mp3songsdownload.org 2
http://antiagingservice.com 2
http://www.alabama-courtrecords.info 2
http://brentwoodtnhomesforsale.org 2
http://static.slideshare.net 2
http://www.easyrapidshare.com 1
http://www.florida-courtrecords.info 1
http://209.85.135.104 1
http://florida-courtrecords.info 1
http://zip-offenders.info 1
http://www.web-investigator.info 1
http://safe.tumblr.com 1
http://virginia-courtrecords.info 1
http://www.workingwithrails.com 1
http://www.health.medicbd.com 1
http://www.slidecoaching.com 1
http://west-virginia-courtrecords.info 1
http://hugobarauna.blogspot.com 1
http://3dvirtualenvironments.com 1
http://3-dweb.com 1
http://www.cwalsh.org 1
http://s3.amazonaws.com 1
http://sobiegraj.com 1
http://babyinformation.info 1
http://www.babyinformation.info 1
http://lj-toys.com 1
http://www.filescon.com 1
http://japaneserobots.org 1
http://pianostorehelper.com 1
http://presentacion.org 1

More...

Statistics

Favorites
80
Downloads
1,575
Comments
6
Embed Views
2,560
Views on SlideShare
37,401
Total Views
39,961

16 of 6 previous next Post a comment

Post Comment
Edit your comment Cancel

Ruby on Rails Security — Presentation Transcript