sensu / sensu-admin

An admin webui for Sensu
MIT License
86 stars 50 forks source link

Remove secret_token.rb from repository #116

Open tomekr opened 8 years ago

tomekr commented 8 years ago

Hey team,

Just wanted to let you know that if your users deploy this server publicly as-is, attackers can execute arbitrary code on their servers.

Here's an example: http://exfiltrated.com/research-Instagram-RCE.php#Ruby_RCE

For more information on why this is the case, see section 2.1 here: http://www.phrack.org/papers/attacking_ruby_on_rails.html

jeanbza commented 8 years ago

+1

z commented 8 years ago

+1

agoddard commented 8 years ago

117 has been merged to clean this up, this project is deprecated in favor of the newer dashboards, so this may need to be clearer in the README also