Hacker News new | past | comments | ask | show | jobs | submit login

Apparently Paperclip library already covered this long before this vulnerability is published.

https://github.com/thoughtbot/paperclip/issues/2190#issuecom...




Well, they check the filetype. I wouldn't be so certain that covers all the bases. Read this: http://www.openwall.com/lists/oss-security/2016/05/03/18


Of course I would like to see specific tests that covers everything about this vulnerability. I see now that there are more problems than the one mentioned in the article.

But the link submitted to hackernews specifically mentioned "magic bytes" which is the file type problem. I think Paperclip is not affected on that one.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: