September 3rd, 2009

RubyOnRails XSS Vulnerability Claims Twitter, Basecamp And My Confidence

It was only three days ago that I wrote about the almost hopeless challenge of web security, specifically around new vectors with cross-site scripting attacks. Today came news that an XSS vulnerability had been found in the RubyOnRails development framework – and that applications built on the framework, such as Twitter and Basecamp, were vulnerable to XSS attacks. The vulnerability was… → Read More