From: Florian Frank Date: 2003-12-16T20:20:55+09:00 Subject: Re: Secure Ruby On Tue, 2003-12-16 at 07:53, Clifford Heath wrote: > Attached source code. > > As simple as: > $ cat > ruby > #! /bin/sh > cat $@ > decrypted.rb > ^D > $ chmod +x ruby > $ export PATH=".:$PATH" > $ rubyrun addflds.rbx Even using a full path to ruby isn't a fix, because it's easy to steal the source code if you use strace -s 2000 ... Another possibility is to set a breakpoint in gdb and stop the program after it has decrypted the source and written it into the temp file. If one trys to modify the ruby interpreter itself instead, to decrypt files before executing them, this would also be a possible attack: one could easily stop the program and inspect the allocated memory to find the orignial source code. -- o=lambda{|o|p o};O=Struct.new(:a,:b,:c);e=%q(_(?h,_(?h,_(?\ ,_(?s,_(?u,_(74)), _(?t)),_(?t,_(?o,_(?n,_(?a))))),_(82,_(?r,_(?e),_(32)),_(32,_(98,_(?u),_(?y))) )),_(?r,_(99,_(97),_(?k,nil,_(?e))),_(10))));def _(*a)O.new(*a)end;class O;def e(&o)b&&b.e(&o);o[a];c&&c.e(&o)end;end;def p(o)print(''<