Get a Pentest and security assessment of your IT network.

News

Backdoor mechanism found in Ruby strong_password library

The developer Tute Costa found a backdoor in the Ruby library during regular security audits. The dangerous code was used to check the password strength of user-chosen passwords when the library was being used in a production environment. The code would download a payload from Pastebin.com and execute it to create the actual backdoor. Backdoored code was only distributed through RubyGems, it was not uploaded on the librarys GitHub account. The attacker created a new version of the library (version 0.0.7 that contained the backdoor code) that was downloaded by 537 users.”]

Source: https://securityaffairs.co/wordpress/88093/hacking/ruby-strong_password-library-backdoor.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Terrorism WEEKLY DIGESTTHREAT INTELLIGENCE FEED 23rd Jul 2nd

News

Attacker.NET : Server Management & Security, Website Malware Removal & Website Security