5 ms·
It's disappointing to see this show up on HN without contact myself or the other rubygems.org admins. We've put rubygems.org into maintenance mode until the iss
by evanphx 14y ago
It's disappointing to see this show up on HN without contact myself or the other rubygems.org admins. We've put rubygems.org into maintenance mode until the issue is fixed.
- tptacek 14y agoWhat I saw was Ben twerping to Ruby people asking who to contact about this first, then posting to HN when he couldn't find the right person. Can I ask, where's the security page on Rubygems.org that tells people who to alert when stuff like this happens? I'm trying to find it on Archive.org and drawing a blank.
- benmmurphy 14y agoI looked for contact page first then panicked. I should have used whois :(
- tptacek 14y agoIf the whole world is pulling backdoored gems off a compromised Rubygems.org, panic seems like a reasonable first reaction. This isn't the Rails bug; there was nothing to be gained here from secrecy.
- benmmurphy 14y agoI became aware of this problem this morning when it was discussed on a public github issue. I think the problem has been known for a couple of weeks. I checked latest rack and active_support gem (would seem to be good targets...) to see if they had been backdoored but they were clean. Not sure if these gems are still clean or if any others have been compromised.
- vinhboy 14y agoconsider me a fan of your work!
- timdorr 14y agoNow would be a good time to build up a quick script to compare the last modification time of the files on S3 against the updated_at of any gem record in the system. If the delta is too long, that would be a candidate for deeper investigation.
- nirvdrum 14y agoHopefully they use S3 bucket versioning. Rolling back would be pretty easy then.
- daveungerer 14y agoI'd be interested in seeing this github issue. Link please?
- benmmurphy 14y agohttps://github.com/tenderlove/psych/issues/119#issuecomment-12875715 https://github.com/tenderlove/psych/issues/119#issuecomment-...
- daveungerer 14y agoAh, so were were supposed to look at the .yml files included in your exploit gem? Which contained some injected code that would then run on the rubygems server?
- benmmurphy 14y agonot my exploit gem. the code was in the metadata part and I believe someone else has posted it in this thread.
- deleted 14y ago[deleted]
- rmc 14y agoto see if they had been backdoored but they were clean You can never be too sure. There's a whole contest (http://underhanded.xcott.com/ http://underhanded.xcott.com/) whose goal is "make something that looks legit, but actually does something evil / has an exploit). Nuke from orbit.
- benmmurphy 14y agoi diffed the rack gem and active_resource gem from the versions built from git. i'm fairly sure the versions i downloaded were not compromised.
- ddunkin 14y agoIf someone compromised a package repository and replaced OpenSSH with a backdoored version, I would want to know immediately, and relay that message as quickly as possible to as many other users as possible before it spreads. It is better to be paranoid about it and get the word out before someone actually gets hurt. If the users get to it before the maintainer gets to it, at least someone got the word out.
- tomjen3 14y agoYour users need to know if their systems have been compromised .