6 ms·
> Did they find 23 flaws in popular and important Rails apps? Those applications have probably been tested extensively already, and new results are interesting.
by ShaneWilton 10y ago
> Did they find 23 flaws in popular and important Rails apps? Those applications have probably been tested extensively already, and new results are interesting. Random e-commerce applications buried in Github, less so.
Based on the paper, he performed two separate experiments.
For one of them, he chose the 50 most popular Rails projects on Github. Of these, 30 of them used a permission model that could be handled by his tools. The 23 flaws reported were among these 30 apps, with Diaspora being notable among those.
He also worked with a professor to test student submissions for an access-control assignment in a web development course at MIT. He uncovered security vulnerabilities in "over half of these projects" and "about half of those bugs were missed during manual grading."