<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Blog do Tino Gomes &#187; segurança</title>
	<atom:link href="http://blog.tinogomes.com/tag/seguranca/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.tinogomes.com</link>
	<description>Nenhum de nós é tão bom quanto TODOS nós juntos!</description>
	<lastBuildDate>Fri, 03 Feb 2012 21:34:18 +0000</lastBuildDate>
	<language>pt-br</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.tinogomes.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/67a2349adf8ea6e4963082bfa1424d44?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Blog do Tino Gomes &#187; segurança</title>
		<link>http://blog.tinogomes.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.tinogomes.com/osd.xml" title="Blog do Tino Gomes" />
	<atom:link rel='hub' href='http://blog.tinogomes.com/?pushpress=hub'/>
		<item>
		<title>Senha no arquivo de log</title>
		<link>http://blog.tinogomes.com/2008/01/03/senha-no-arquivo-de-log/</link>
		<comments>http://blog.tinogomes.com/2008/01/03/senha-no-arquivo-de-log/#comments</comments>
		<pubDate>Thu, 03 Jan 2008 12:33:03 +0000</pubDate>
		<dc:creator>Celestino Gomes</dc:creator>
				<category><![CDATA[ruby]]></category>
		<category><![CDATA[log]]></category>
		<category><![CDATA[rails]]></category>
		<category><![CDATA[segurança]]></category>

		<guid isPermaLink="false">http://tinogomes.wordpress.com/2008/01/03/senha-no-arquivo-de-log/</guid>
		<description><![CDATA[Relembrando o post de Carlos Brando em seu blog, vou aproveitar para incrementar um pouco mais ;) Você não gostaria de encontrar isso no seu arquivo de log: Processing AcessoController#login (for 10.0.0.1 at 2007-11-13 18:01:05) [POST] Session ID: 65f5dff4cb6382df7ff867058577577b Parameters: {"commit"=&#62;"Submit", "action"=&#62;"login", "controller"=&#62;"access", "login"=&#62;"user.name", "password"=&#62;"user.name.password"} Redirected to http://www.mydomain.com/ Completed in 0.01000 (100 reqs/sec) &#124; DB: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.tinogomes.com&amp;blog=2362964&amp;post=11&amp;subd=tinogomes&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Relembrando o <a href="http://www.nomedojogo.com/2007/08/16/todo-mundo-pode-ver-minha-senha-nos-arquivos-de-log-do-rails/" target="_blank">post</a> de <a href="http://workingwithrails.com/person/8137-carlos-brando" target="_blank">Carlos Brando</a> em seu <a href="http://www.nomedojogo.com/" target="_blank">blog</a>, vou aproveitar para incrementar um pouco mais ;)</p>
<p>Você não gostaria de encontrar isso no seu arquivo de log:</p>
<p><code>Processing AcessoController#login (for 10.0.0.1 at 2007-11-13 18:01:05) [POST]<br />
Session ID: 65f5dff4cb6382df7ff867058577577b<br />
Parameters: {"commit"=&gt;"Submit", "action"=&gt;"login", "controller"=&gt;"access", "login"=&gt;"user.name", "password"=&gt;"<strong>user.name.password</strong>"}<br />
Redirected to http://www.mydomain.com/<br />
Completed in 0.01000 (100 reqs/sec) | DB: 0.00000 (0%) | 302 Found [http://www.mydomain.com/login]</code><br />
<span id="more-11"></span><br />
Olha que lindo, a senha é &#8220;user.name.password&#8221; , muito bem protegido, não?</p>
<p>Então, para solucionar esse problema, coloque o filtro no seu controller. (eu sugiro o ApplicationController)</p>
<p><code>class ApplicationController &lt; ActionController::Base<br />
#...<br />
filter_parameter_logging :senha, :password<br />
#...<br />
end</code></p>
<p>O que isso faz? Bom, qualquer campo que contenha os termos /senha|password/1</p>
<p>Tem mais na <a href="http://api.rubyonrails.org/classes/ActionController/Base.html#M000441" target="_blank">API</a>.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/tinogomes.wordpress.com/11/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/tinogomes.wordpress.com/11/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/tinogomes.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/tinogomes.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/tinogomes.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/tinogomes.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/tinogomes.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/tinogomes.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/tinogomes.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/tinogomes.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/tinogomes.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/tinogomes.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/tinogomes.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/tinogomes.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/tinogomes.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/tinogomes.wordpress.com/11/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.tinogomes.com&amp;blog=2362964&amp;post=11&amp;subd=tinogomes&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.tinogomes.com/2008/01/03/senha-no-arquivo-de-log/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9742692d8f4eb9997301de35395e5460?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">Tino</media:title>
		</media:content>
	</item>
	</channel>
</rss>
