Web Hack List

Collected research

Finding Weak Rails Security Tokens

Rails signs session cookies with a secret token, and tokens committed to public GitHub repositories stay usable. Cookies were gathered from roughly 20,000 Shodan-found Rails servers and 40,000 Alexa sites, then matched against the harvested tokens by recomputing the HMAC-SHA1 digest. Seven servers used a leaked token; none of the 303 matching Alexa sites did.

Record

Published by
AverageSecurityGuy
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of AverageSecurityGuy, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .