Trend Micro Deep Security Guards Users from Ruby on Rails Exploit | Security Intelligence Blog | Trend Micro(情報元のブックマーク数)

TrendmicroのDeepSecurityを使うと、Ruby on Rails脆弱性を防御できるらしい。

Last January, we talked about a critical vulnerability in Ruby on Rails (CVE-2013-0156). At the time, we pointed out that there was no known attack, but because its code had been released as part of the Metasploit exploit framework and that this would increase risks of an attack moving forward. It was only a matter of time before this can be used in an attack in the wild. We strongly urged server administrators to patch their Ruby on Rails software to the latest, patched versions.
At the time, we noted that Trend Micro Deep Security has protected users from the said vulnerability via the following DPI rules:
1005331 Ruby On Rails XML Processor YAML Deserialization DoS
1005328 Ruby On Rails XML Processor YAML Deserialization Code Execution Vulnerability
These rules allow Deep Security to block network traffic that is related to this vulnerability, preventing any exploitation of the security flaw.

Trend Micro Deep Security Guards Users from Ruby on Rails Exploit - TrendLabs Security Intelligence Blog

screenshot