<nowhereFast>
p.15 points to a remote code execution vulnrability in JRuby
<nowhereFast>
^incase that hasn't already come up
<headius>
nowhereFast: that's not a vulnerability, it's a feature
<headius>
it's supposed to execute remote code
<headius>
it's no more an exploit than loading a Java jar file over a URL and executing the code in it
<headius>
and that's a pretty standard Java thing to do
<nowhereFast>
:) yup, pasted it more for what it's being presented
<nowhereFast>
as
claudiuinberlin has joined #jruby
<headius>
yeah I commented on his blog post about the paper, we'll see what he says
<headius>
I don't consider it an exploit because you'd have to be able to modify a user's code to load this remote URL
<headius>
yeah I call shenanigans on this
<headius>
he basically writes code that attempts to load something off a remote server and then when it does so he calls that an exploit
<headius>
he explicitly tries to make it load that URL
<nowhereFast>
yeh, that makes sense, seems like a bit of a publicity stunt on his part too, yet many sites will jump on this and put it out there as gospel
subbu is now known as subbu|lunch
<headius>
ugh
claudiuinberlin has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
<headius>
I'm already seeing blog posts about his results
<headius>
why wouldn't he contact us before publishing this?
<fidothe>
Hey, I'm seeing something odd with Process.spawn (well, specifically, Open3.capture3) where, once I've called out to it a bunch (i don't have exact numbers but I can figure it out), the call starts failing with unable-to-allocate errors, despite there being plenty of memory available according to top
<headius>
fidothe: sounds like something you should open an issue for
<headius>
provide as much info as you can, ideally a simple reproduction
<fidothe>
i'll do that
rrutkowski has quit [Quit: rrutkowski]
rrutkowski has joined #jruby
rrutkowski has quit [Quit: rrutkowski]
rrutkowski has joined #jruby
zph has quit [Ping timeout: 258 seconds]
flavorjones has quit [Ping timeout: 258 seconds]
codefinger has quit [Ping timeout: 258 seconds]
amitchellbullard has quit [Ping timeout: 258 seconds]