Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • i thought cloudflare would protect against those no?
  • This website is format is really weird for mobile, I can only read two lines of text. The rest is covered by a big banner. Im on IOS. Anybody else having this issue or is it just me?
  • There are so many CVEs related to upload… and basic user/group/file permissions and proper rules within the web proxy could mitigate them.

    It reeks of people just writing stuff and tossing it up thinking that they’ve crafted something so great they needn’t worry. Get a good platform team.

  • Do you have to have matlab running on your rails server for this to happen?
  • Nice write up, Claude.
  • This post could be 10% as long:

    - There was a bug with a patch

    - We applied it to our clients

    - There were live exploits within eight hours of the patch being released

    - The Rails team had to expedite release of the technical details because POCs obviated the need to embargo

    by tyre
  • Just sent this to my boss. Felt like tossing a grenade over a fence into a party of unsuspecting people.

    We don’t use ActiveStorage but Claude was able create a similar exploit in own our app in the exact same way via our own file upload library in 3 minutes simply by point Opus 5 at our site and asking it if we were vulnerable to an attack similar to KindaRails2Shell.

    What a time to be alive.

Explore Birbla archives