RubyGems DNS flaw now patched after second try
A revised patch has been released for a flaw in the distribution platform for Ruby applications, RubyGems, which could be used to deliver malware to someone trying to download a program.RubyGems lets people search for a “gem,” which is a packaging format for Ruby applications and code libraries. Ruby developers publish a gem when an application is ready.Security researchers from Trustwave found a problem with the platform. When people search for a gem, RubyGems uses a DNS (Domain Name System) SRV record request to find a server hosting a particular gem.The request, however, “does not require that DNS replies come from the same security domain as the original gem source,” according to a writeup, which Trustwave plans to release on its blog on Tuesday.To read this article in full or to leave a comment, please click here
Docker is overhauling its Network platform to integrate with other data-center networking and virtualization products.
If you missed out on the 6WIND DemoFriday, no worries. 6WIND was nice enough to give us a quick Q&A following the demo.