4 ms·
Seems rather similar to the strong_password case from a month back: https://news.ycombinator.com/item?id=20377136 https://news.ycombinator.com/item?id=20377136
by htns 7y ago
Seems rather similar to the strong_password case from a month back: https://news.ycombinator.com/item?id=20377136 https://news.ycombinator.com/item?id=20377136 . I wonder if anyone has checked basic things like scanning all of rubygems for "pastebin" or "eval( * http * )".
- gotts 7y agoit surprises me a bit. I'm wondering why wouldn't RubyGems implement some basic form of malware detection? This type of code shouldn't be too hard to classify.
- derimagia 7y agoMalicious users would just change their code slightly to get past it. Use a different service than pastebin, or just obfuscating it more.
- gotts 7y agoAfter thinking about.. I think you must be right. Malware detection is not an easy task especially because of Ruby's dynamic nature. Even simple open(), sleep(), eval() could be easily obfuscated.