5 ms·
It is meant for development environments only. Nobody would risk putting a Ruby console in production :) In fact, when using it with Rails, it is loaded only i
by txus 15y ago
It is meant for development environments only. Nobody would risk putting a Ruby console in production :)
In fact, when using it with Rails, it is loaded only in development environment. With other frameworks you should take care of what middlewares you use in which environment.
- patio11 15y agoI would think long and hard about whether giving code execution privileges on your local machine to anyone who can convince you to click on a link is a good idea. Actually, this should not be either long or hard. Edit to add: You don't even need to click on the link, you just need to view an image whose src I can manipulate. Ugh. Seriously: do not install on any environment anywhere.
- nicholaides 15y agoCan you expand on this? What's the risk? What's the attack vector?
- ciupicri 15y agoI think he's saying that someone can make you open a web page that includes an image with the proper src attribute and bang, your Rails site is broken.
- tptacek 15y agoMore likely, your whole data center.
- sabat 15y agoHyperbolic.
- tptacek 15y agoI know you've been a dev/ops guy for 20 years and I respect the fact that your development machines are sealed in vaults, but I've gotten to assess more than half of the top 10 biggest Rails apps in the world over the past couple of years and trust me, you're just wrong about this. Development machines are within reach of developer browsers. Database machines are within reach of development machines.
- ssmoot 15y agoYou've probably figured this out by now, but I'm pretty sure you're missing the point. From your other comments in this thread you appear to think that the machine needs to be internet-accessible. Have a public IP. Open Firewall. All that. The reason this is so dangerous is that it needs none of that. All it needs is for your development machine to have access to the internet. I open up a project, enable this, and run rackup locally. I then view your Twitter stream, where you've embedded a crafted link behind a URL shortener. Because that link is executed by me, you've now remotely executed code on my machine. Assuming I'm anything like most Rails shops you can probably get to a number of other machines through my machine.
- tptacek 15y agoCross-site request forgery. I should add though that even if this thing gets an XSRF token and it's secure, you might as well take the passwords off your SSH keys if you're running this, because you're coughing up an unprotected remote shell to anyone who can talk to a dev server once you turn this on.
- irahul 15y ago> What's the attack vector? CSRF.
- txus 15y agoYou're right, that's a risk. I've opened an issue to implement a simple pseudorandom token to protect AJAX requests. What do you think? https://github.com/codegram/rack-webconsole/issues/4 https://github.com/codegram/rack-webconsole/issues/4
- ianpurton 15y agoI think you can achieve the same thing using shellinabox. Take a look at http://blog.servermonitoringhq.com/posts/the_ultimate_web_based_ide http://blog.servermonitoringhq.com/posts/the_ultimate_web_ba...
- SingAlong 15y agoRight! A dev server is for dev, even to show off the app to your friends you've got to remove this console. So IMHO, you don't have to worry about security if it's your tiny dev machine that runs on your desk, unless you are paranoid about securing your iron cage. If anyone has used the Seaside framework, can you throw some light on how this compares to the in-page editing that Seaside provides (as per what I've heard).
- patio11 15y agoA dev server is for dev, even to show off the app to your friends you've got to remove this console. So IMHO, you don't have to worry about security if it's your tiny dev machine that runs on your desk One of your friends is named Firefox, and he does not take orders from you, he takes orders from me.
- SingAlong 15y agoSo people now downvote if they don't agree with you? sw33t. I would love to know a reason.