MIT Bug Finder Uncovers Flaws In Web Apps In 64 Seconds (csoonline.com)
itwbennett quotes a report from CSO: A new tool from MIT exploits some of the idiosyncrasies in the Ruby on Rails programming framework to quickly uncover new ones, writes Katherine Noyes. In tests on 50 popular web applications written using Ruby on Rails, the system found 23 previously undiagnosed security flaws, and it took no more than 64 seconds to analyze any given program. Ruby on Rails is distinguished from other frameworks because it defines even its most basic operations in libraries. MIT's researchers took advantage of that fact by rewriting those libraries so that the operations defined in them describe their own behavior in a logical language.
From what I can tell, it seems like it might be something like a code analysis tool that swapped in a logger to profile methods called along with some metadata (time spent in subroutine, etc).
http://open.blogs.nytimes.com/2008/03/05/the-new-york-times-perl-profiler/?_r=0
BUT ON AN APP!
or am i missing something?
the biggest flaw was that they were written in Ruby on Rails.
Anons need not reply. Questions end with a question mark.
Gone in 64 seconds.
how long did it take to rewrite the libraries?
Many "cool and new" technologies started out with a rather dismissive and arrogant attitude towards predecessors — only to then encounter the same problems as other did before and have to solve them in a hurry, shooting yourself in the same extremity (with the same gun), and stepping on the same rake.
From my experience, Ruby is especially bad at it. Release 1.9.2 not quite compatible with 1.9.1? What?!
Published packages ("gems") not signed. Huh?
So, when I hear about yet another problem in that world, all I can do is shrug...
In Soviet Washington the swamp drains you.
Hipsters like hipster languages developed by hipsters.. what a shock.. The rest of us with real work to do use proven tools.
Yeah! GW-BASIC, man!
Always the same. CSS today is solving the same layout problems that X11 window managers did 25 years ago.
And the CSS designers think this is ubercool.
One of them discovered "Atomic Design" a while ago. http://patternlab.io/about.htm...
This is a rediscovery of.....modularity! Yeah! Breaking up you work in modules! What a nifty idea!!!
Something that CS and Programming language design thoroughly explored in the 1960s and 70s but whatever.
The dangers of excessive individualism are nothing compared to the oppressiveness of excessive collectivism
They jumped ship when the Ruby on Rails hype started really dying down
Good riddance. Rails is a cancer on the Ruby community.
Wow, I checked the link, and they indeed reinvented warm water !
We're probably getting too old for this shyte.
Python and Ruby are similar languages, and yet the cultures around the two are very different. A certain segment of Ruby has moved to node.js now.
https://www.youtube.com/watch?...
http://rareformnewmedia.com/
Yeah, but the difference is that they published it in a REAL BIG font, on a webpage that has all the text CENTERED, so that is wastes 90% of the realestate in the margins -- which it the totally hipster UX designer way of making websites.