3 ms·
For whose wondering, brief read of the paper's initial chapters show that it's a methodology (and toolset) to find access control issues in RoR. Seems like a sm
by fmavituna 10y ago
For whose wondering, brief read of the paper's initial chapters show that it's a methodology (and toolset) to find access control issues in RoR. Seems like a smart approach, need to see it in production though. I'm not really surprised if they found various ACL related vulnerabilities with this model in web apps, it's a common issue and not easy to test & check.
Injection vulnerabilities (XSS, SQLI etc.) are out of the scope of this document/toolset, it's heavily designed for detect ACL issues in web applications.