Skip to content
Ruby on Rails Security Project

Hand-picked Rails security resources

Menu

  • Home
  • New here?
    • About
    • Rails security for beginners
    • Advanced Rails security
    • Essential Rails security links
  • Topics
    • Cross-Site Scripting (XSS) in Rails
    • SQL Injection in Rails
    • Rails configuration security
    • Rails security books
    • Vulnerabilities and threats
    • Cross-Site Request Forgery (CSRF)
    • All resources
  • Feed

Markdown and Textile security

Markdown and Textile are two markup languages, that are often used to accept rich text from the user. Usually thatworks well, especially with another step of sanitization after the conversion. However, sometimes there are bugs in the gems and sometimes the browser accepts strange code:

homograph attack
homograph attack 2
link problems

Redcloth

Example vulnerability
An older, probably outdated article about Redcloth security

Feedback?

Send me an e-mail.

Meta

Rails Security Bi-Weekly
Search
Update Feed
Resources Feed
Suggest a resource

About

Hand-picked quality Rails security resources © 2006-today by bauland42 (relaunch in 2015)
About