Make sure you install the latest 1.0.x or 1.1.x release of Mongrel. There is a security hole in the DirHandler that allows read access to the file system. sudo gem install mongrel You should be running at least 1.05 or 1.1.3. Per Zed and others on the mailing list, here are the details: 1) If [...]
Subscribe