#1 (permalink)  
Old 07-02-2009, 02:52 PM
Registered User
 
Join Date: Feb 2006
Posts: 4
afonic is on a distinguished road
Ruby On Rails error on PCI test

I am running the HackerGuardian PCI Compliance test and I am getting the following security warning:

Code:
Security warning found on port/service "nbx-ser (2095/tcp)"  	
	
		
	Plugin 	 "Ruby on Rails Session Fixation Vulnerability" 	
		
	Category 	 "Web Servers " 	
		
	Priority 	 "Medium Priority "Synopsis :  The remote web server is affected by a session fixation vulnerability.   Description :  The web server on the remote host appears to be a version of Ruby on Rails that supports URL-based sessions.  An unauthenticated remote attacker may be able to leverage this issue to obtain an authenticated session.   Note that Ruby on Rails version 1.2.4 was initially supposed to address this issue, but its session fixation logic only works for the first request, when CgiRequest is first instantiated. 	
	
		
	See also: 	http://weblog.rubyonrails.org/2007/10/5/rails-1-2-4-maintenance-release 	
	http://www.nessus.org/u?2f5b72e6 	
	http://dev.rubyonrails.org/ticket/10048 	
	http://www.nessus.org/u?1eeea9de 	
		
		
	   Solution :  Upgrade to Ruby on Rails version 1.2.6 or later and make sure 'config.action_controller.session_options[:cookie_only]' is set to 'true' in the 'config/environment.rb' file. 	
	
		
		
	   Risk factor :  Medium / CVSS Base Score : 6.8 (CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P) 	
	
		
		
	   CVE: 	CVE-2007-5380 	
		CVE-2007-6077 	
	
	BID : 26096, 26598 Other references : OSVDB:39193, OSVDB:40718 	
		
	      If you think this vulnerability is a false positive, already patched or if  compensating controls exist within your infrastructure please 	
	click here.
However I cannot locate that file or find any information about how I could solve this issue. As a matter of fact I cannot find instructions for removing Ruby from cPanel all together.

Any ideas?

PS. I am using CentOS 5.3
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Metrics PCI compliance - Exim fails test. jols Mail 6 12-12-2008 12:55 AM
Ruby on rails... 4u123 cPanel and WHM Discussions 2 05-30-2008 10:38 AM
Ruby rails gives error : mysql required mak_the_admin cPanel and WHM Discussions 3 04-23-2008 04:02 PM
ruby on rails SACHIN cPanel and WHM Discussions 8 11-20-2006 09:41 AM
Ruby or Rails binding for cPanel? (Manage e-mail addresses through rails) dunnil cPanel Newbies 0 05-12-2006 05:00 PM


All times are GMT -5. The time now is 09:41 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
© cPanel Inc