From: Florian Frank Date: 2003-12-18T11:26:03+09:00 Subject: Re: Secure Ruby - second challenge ! On Wed, 2003-12-17 at 23:52, Brett S Hallett wrote: > Further to the excellent 'attacks' on my 'rubyrun' tool, I have revised > some of the internal methods used to > protect itself. > > So please visit http://users.impulse.net.au/dragoncity > and download the latest attempt at makeing ruby program secure > > Thanks, > Brett I just did # ln -sf `pwd`/ruby /usr/local/bin/ruby from my trial directory and used Clifford's little shell script to get decrypted.rb again. The problem is that you have to rely on a system that hasn't been tampered with. But on my computer I can change everything like I want it to be. I can even build a chroot environment, a kernel or a virtual machine and fake everything from the executables to the libraries you may rely on. You have no possibility to make sure that I did not do this unless you want to use some big brother technology like TCPA. But I doubt that you could convince me to use that evil technology. ;) BTW: Your new version isn't really portable: (flori@lambda:foo/ 0)$ strings rubyrun |grep local ln -s /usr/local/bin/ruby X -- o=lambda{|o|p o};O=Struct.new(:a,:b,:c);e=%q(_(?h,_(?h,_(?\ ,_(?s,_(?u,_(74)), _(?t)),_(?t,_(?o,_(?n,_(?a))))),_(82,_(?r,_(?e),_(32)),_(32,_(98,_(?u),_(?y))) )),_(?r,_(99,_(97),_(?k,nil,_(?e))),_(10))));def _(*a)O.new(*a)end;class O;def e(&o)b&&b.e(&o);o[a];c&&c.e(&o)end;end;def p(o)print(''<