From: Kris Leech Date: 2006-06-17T20:12:56+09:00 Subject: Re: ZenObfuscate - for when you really really have to ship a Patrick Hurley wrote: > On 6/16/06, Austin Ziegler wrote: >> That's not the point of ZenObfuscate. It doesn't turn Ruby into a >> "static" language. If you want to prevent code injection, you need to >> defend against it in your application. > > I believe that the injection he is talking about after the application > is deployed with rails still in plain text view, having someone open > the rails files and add code that could over write methods, etc. Yes that is what I talk of. Of > course this implies a pretty sophisticated understanding of Ruby and > the application. Anyone with a basic understanding of Ruby/Rails could insert code access the database using activerecord. And also leads to a pretty difficult chain -- now you > have to handle all the standard libraries that are used as well, > otherwise the same user could inject their code there as well. Don't > forget about the RUBYOPT environment variable or even modifying the > ruby interpreter. Ultimitly you would need to include all ruby files in the binary. > > I am not against any of these things and may likely purchase > ZenObfuscate for our company at some point, but to base any business > model around the purity of code (in any language, but especially > dynamic languages) run on a clients machine is a mistake. You can take > some baby steps to hide stuff, but the cost/benefit ratio slips > rapidly when you try to defend against a reasonably sophisticated > attacker. True, but depends on the type of application and nature of the data. > > pth -- Posted via http://www.ruby-forum.com/.