Ruby security news
Keep up with the programming language’s security, too
Keep up with the programming language’s security, too
Complete Rails guide to developing a security strategy
One of the early Rails security books
Some are sent by default in Rails now
Track and throttle requests
RailsConf talk: Introduction to Rails security
The OWASP recommends the least privileges for a DB user
Many examples of what NOT to do
The number 3 in the OWASP Top Ten web application vulnerabilities
A Cross Site Scripting cheat sheet by the Open web application security project