{"id":12,"date":"2013-01-12T16:53:59","date_gmt":"2013-01-12T16:53:59","guid":{"rendered":"http:\/\/www.xvudrive.com\/blog\/?p=12"},"modified":"2013-01-12T16:53:59","modified_gmt":"2013-01-12T16:53:59","slug":"ruby-on-rails-exploit-200000-sites-affected","status":"publish","type":"post","link":"https:\/\/www.xvudrive.com\/blog\/ruby-on-rails-exploit-200000-sites-affected\/","title":{"rendered":"&#8220;Ruby on Rails&#8221; server exploit"},"content":{"rendered":"<p>You&#8217;re probably asking yourself &#8220;Why is XVU telling me about something that happens on a server?  I&#8217;m not a techie, I don&#8217;t run a server, why do I care?&#8221;  Well, some server exploits are bad enough that they even threaten you as a user of the web.  Lemme &#8216;splain.<\/p>\n<p><a href=\"http:\/\/arstechnica.com\/security\/2013\/01\/extremely-crtical-ruby-on-rails-bug-threatens-more-than-200000-sites\/\">ARSTechnica reported<\/a> an &#8220;Extremely critical&#8221; bug that &#8220;threatens more than 200,000 sites&#8221;.  200,000 sounds like a big number, but in the grand scheme of the internet, it&#8217;s not that many.  However, look at some of the sites that are in that list:<\/p>\n<p>http:\/\/www.twitter.com\/<br \/>\nhttp:\/\/www.yellowpages.com\/<br \/>\nhttp:\/\/www.whitepages.com\/<br \/>\nhttp:\/\/www.hulu.com\/<br \/>\nhttp:\/\/www.groupon.com\/<br \/>\nhttp:\/\/www.scribd.com\/<br \/>\nhttp:\/\/www.lumosity.com\/<br \/>\nhttp:\/\/www.urbandictionary.com\/<\/p>\n<p>and, well, 200,000 more like that.<\/p>\n<p>&#8220;Ok, so it attacked a bunch of sites I go to every day.  How does that affect ME?!&#8221;  Well, I&#8217;m glad you asked.  According to <a href=\"https:\/\/news.ycombinator.com\/item?id=5028270\">this post<\/a> &#8220;An attacker can execute <b>any <\/b>ruby code he wants including system(&#8220;unix command&#8221;).&#8221;  This means that if the site was exploited, the attacker could infect <b>you<\/b> just by browsing the site.  Perhaps infecting the site with the new <a href=\"http:\/\/www.xvudrive.com\/blog\/java-browser-exploit\/\">Java 0-day exploit<\/a> and installing a keylogger on your computer.<\/p>\n<p>If you have visited any of the above sites, please be sure to run a thorough virus scan, and be sure to use your XVU Drive to access secure sites until we&#8217;re all sure this is thoroughly patched.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>You&#8217;re probably asking yourself &#8220;Why is XVU telling me about something that happens on a server? I&#8217;m not a techie, I don&#8217;t run a server, why do I care?&#8221; Well, some server exploits are bad enough that they even threaten &hellip; <a href=\"https:\/\/www.xvudrive.com\/blog\/ruby-on-rails-exploit-200000-sites-affected\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-12","post","type-post","status-publish","format-standard","hentry","category-browser-exploits"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.xvudrive.com\/blog\/wp-json\/wp\/v2\/posts\/12","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.xvudrive.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.xvudrive.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.xvudrive.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.xvudrive.com\/blog\/wp-json\/wp\/v2\/comments?post=12"}],"version-history":[{"count":1,"href":"https:\/\/www.xvudrive.com\/blog\/wp-json\/wp\/v2\/posts\/12\/revisions"}],"predecessor-version":[{"id":13,"href":"https:\/\/www.xvudrive.com\/blog\/wp-json\/wp\/v2\/posts\/12\/revisions\/13"}],"wp:attachment":[{"href":"https:\/\/www.xvudrive.com\/blog\/wp-json\/wp\/v2\/media?parent=12"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.xvudrive.com\/blog\/wp-json\/wp\/v2\/categories?post=12"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.xvudrive.com\/blog\/wp-json\/wp\/v2\/tags?post=12"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}