ERICRAFALOFF.COM SERVER
We revealed that a lone root page on ericrafaloff.com took one thousand one hundred and thirteen milliseconds to come up. We detected a SSL certificate, so I consider this site secure.
WEBSITE ICON
![](/f/z9ji4keeeroljgh5ovpfggjj/256/ericrafaloff.com.png)
SERVER SOFTWARE
We discovered that ericrafaloff.com is employing the Apache/2.4.7 (Ubuntu) operating system.SITE TITLE
Eric Rafaloff My personal blog on software development and securityDESCRIPTION
My personal blog on software development and security. From YAML Deserialization to RCE in Ruby on Rails Applications. If defined. If an object of a particular class were to be cleverly serialized with a particular set of instance variables then maybe, just maybe, a callback made on deserialization will end up executing dangerous code. This is why it is unsafe to pass user input to YAML. Of a payload he and several others wrote. This was especially interesting at the time because of CVE-2013-0156, wh.PARSED CONTENT
The domain has the following in the web page, "My personal blog on software development and security." I observed that the web site also stated " From YAML Deserialization to RCE in Ruby on Rails Applications." They also stated " If an object of a particular class were to be cleverly serialized with a particular set of instance variables then maybe, just maybe, a callback made on deserialization will end up executing dangerous code. This is why it is unsafe to pass user input to YAML. Of a payload he and several others wrote. This was especially interesting at the time because of CVE-2013-0156, wh."