In Ruby, can request.host be trusted to differentiate between a staging environment and production?

Let’s say I have two environments: https://qa.example.com and https://example.com. In QA, I want to allow access to something insecure, like a special route that allows logging in without a password.
What are the security concerns of check… Continue reading In Ruby, can request.host be trusted to differentiate between a staging environment and production?

Ruby raises $7.3 million to give users granular access control over their data

Ruby announced the close of a $7.3 million round of funding with participation from venture capital funds Digital Strategies, DFG Group, SigNum Capital, D1 Ventures, Global Coin Research, Ocean Foundation, DWeb3 Capital, Maverick Global Ventures, and m… Continue reading Ruby raises $7.3 million to give users granular access control over their data

HackerOne updates Internet Bug Bounty program to improve the security of open source software

HackerOne announced the next evolution of the Internet Bug Bounty (IBB) program at the company’s annual Security conference. The IBB’s mission is to secure open source by pooling funding and incentivizing security researchers to report vulnerabilities … Continue reading HackerOne updates Internet Bug Bounty program to improve the security of open source software

Granulate gProfiler provides support to Graviton processors to improve code quality

Granulate announced the latest addition to its gProfiler, which now provides support to Graviton processors. With this new addition to gProfiler, organizations running workloads on ARM-based Graviton instances can enjoy out-of-the-box, system-wide visi… Continue reading Granulate gProfiler provides support to Graviton processors to improve code quality

Granulate adds Kubernetes filtering feature to open-source gProfiler

Granulate released new Kubernetes filters feature to the company’s gProfiler. gProfiler is an open-source production profiling solution that measures the performance of code in production applications to facilitate computing optimization, improve code … Continue reading Granulate adds Kubernetes filtering feature to open-source gProfiler

RubySMB::Error::CommunicationError: Read timeout expired when reading from the Socket (timeout=30)

I’ve been playing around with the EternalBlue exploit recently. I’ve downloaded a Windows 10 iso file from 2016 and used it to set up a Windows 10 Pro VM as my sandbox. I also ran the nmap script and metasploit scanner module to ensure tha… Continue reading RubySMB::Error::CommunicationError: Read timeout expired when reading from the Socket (timeout=30)

Sentry enhances platform capabilities to improve developer workflows and productivity

Sentry announced new and enhanced platform capabilities designed to improve developer workflows and productivity by making it easier to find and resolve the issues that really matter, faster. Developers are under pressure to write more code than ever t… Continue reading Sentry enhances platform capabilities to improve developer workflows and productivity