From: Tim Pease Date: 2007-12-19T01:43:21+09:00 Subject: Re: Networked Marshal Questions On Dec 18, 2007 9:11 AM, Christophe Mckeon wrote: > > > > > If the connection is not encrypted anybody can sniff the traffic and > > probably also reconstruct marshalled objects. > > > > thanks for the reply. i was thinking more along the lines of execution > security, as in `rm -fr /`. > > some malicious class could do damage if instantiated through > marshaling, but then it would already have to exist in the running > executable, so at first glance it seems there is no danger, but just > thought > i'd ask anyway. > You can set the $SAFE level of a ruby script. Any strings that come in from userland (stdin, sockets, pipes, etc.) are tainted by default. When you set a higher safe level, ruby restricts what can be done with those tainted strings. Read the link above -- it's a chapter from the Programming Ruby book (the pick-axe) -- and it goes into much more detail than I could ever hope to type here. Blessings, TwP