sensu-admin icon indicating copy to clipboard operation
sensu-admin copied to clipboard

Remove secret_token.rb from repository

Open tomekr opened this issue 10 years ago • 3 comments

Hey team,

Just wanted to let you know that if your users deploy this server publicly as-is, attackers can execute arbitrary code on their servers.

Here's an example: http://exfiltrated.com/research-Instagram-RCE.php#Ruby_RCE

For more information on why this is the case, see section 2.1 here: http://www.phrack.org/papers/attacking_ruby_on_rails.html

tomekr avatar Dec 17 '15 23:12 tomekr

+1

jeanbza avatar Dec 18 '15 02:12 jeanbza

+1

z avatar Dec 18 '15 03:12 z

#117 has been merged to clean this up, this project is deprecated in favor of the newer dashboards, so this may need to be clearer in the README also

agoddard avatar Dec 18 '15 04:12 agoddard