Live data from Hacker News

Show HN: Rubystub.com Run/Save Ruby Online

rubystub.com

1–8 of 8 posts

Re: Show HN: Rubystub.com Run/Save Ruby Online

#4
post #3

I would take this offline right away: system("ls -l /");

You can safely use that as the Ruby is run in a limited contained env. Feel free to run `rm -rf` too

I don't think you're going to be happy when somebody uses you to launch a DDOS:

  system("ping -c 2 8.8.8.8");

  PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data.
  64 bytes from 8.8.8.8: icmp_req=1 ttl=55 time=1.98 ms
  64 bytes from 8.8.8.8: icmp_req=2 ttl=55 time=1.75 ms

Re: Show HN: Rubystub.com Run/Save Ruby Online

#6
post #3

Earlier quoted context omitted.

You can safely use that as the Ruby is run in a limited contained env. Feel free to run `rm -rf` too

I don't think you're going to be happy when somebody uses you to launch a DDOS: system("ping -c 2 8.8.8.8"); PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data. 64 bytes from 8.8.8.8: icmp_req=1 ttl=55 time=1.98 ms 64 bytes from 8.8.8.8: icmp_req=2 ttl=55 time=1.75 ms

Unless he's running this in an incredibly powerful machine on an incredible well connected network, nobody will be DOS'ing anyone worse from that machine than they could do by spinning up a single VM somewhere.

Re: Show HN: Rubystub.com Run/Save Ruby Online

#7
post #6

Earlier quoted context omitted.

I don't think you're going to be happy when somebody uses you to launch a DDOS: system("ping -c 2 8.8.8.8"); PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data. 64 bytes from 8.8.8.8: icmp_req=1 ttl=55 time=1.98 ms 64 bytes from 8.8.8.8: icmp_req=2 ttl=55 time=1.75 ms

Unless he's running this in an incredibly powerful machine on an incredible well connected network, nobody will be DOS'ing anyone worse from that machine than they could do by spinning up a single VM somewhere.

When it comes to netsec, any hole's a goal.

And as rikkus pointed out, there's no timeout on runs too. This is just asking for trouble.

Re: Show HN: Rubystub.com Run/Save Ruby Online

#8
post #6

Earlier quoted context omitted.

Unless he's running this in an incredibly powerful machine on an incredible well connected network, nobody will be DOS'ing anyone worse from that machine than they could do by spinning up a single VM somewhere.

When it comes to netsec, any hole's a goal. And as rikkus pointed out, there's no timeout on runs too. This is just asking for trouble.

There is a timeout.