Thursday, September 3, 2009

Brian Mastenbrook: How I cross-site scripted Twitter...

Today the Ruby on Rails security team released a patch for a cross-site scripting issue which affected multiple high-profile applications, including Twitter and Basecamp. If you're concerned about the issue and would like to see the patch, please read the advisory from the Rails security team. In this post, I discuss the overall process of finding the issue, and the reason why I'd suggest that no important information be stored on the 37signals applications (Basecamp, Highrise, Backpack, and Campfire).

In fact, Internet is dangerous. However, it looks like the author is bringing some over-importance which is, to my mind, is a little bit excessive here.

# Posted via web from opportunity__cost