De-Railing: Smashing the Rails Stack

Location: Portland Ballroom 255 Level: Intermediate
Average rating: ***..
(3.25, 16 ratings)

This talk is intended to help the professional Rails developer. It will give guidance on the do-nots while coding a Rails app as well as the do-nots when setting up a server and choosing the surrounding stack. After the talk there will be a brief demo of what improperly written code can do when in the hands of an attacker. Don’t let yourself make mistakes when people’s livelyhood is on the line. Rails isn’t a toy and we shouldn’t treat it as one. It’s time to start getting serious about security on Rails!

Photo of Aaron Bedra

Aaron Bedra

Relevance, Inc.

Aaron is a developer for Relevance, LLC in Chapel Hill North Carolina. He is a very active member of both the open source and information security communities. Aaron is also involved with the Metasploit Framework, a very large Ruby codebase that provides security researchers the necessary tools to prove new exploits as well as test for existing vulnerabilities. Most of Aaron’s background comes from researching patterns in software development and proper techniques behind design and development. Aaron has worked with a number of fortune 500 companies around the country performing both software architecture services and advanced hacking and penetration testing services.

News and Coverage
co-presented by Ruby Central, Inc. O'Reilly
  • Engine Yard
  • Sun Microsystems
  • FiveRuns
  • GotThingsDone
  • Heroku
  • ThoughtWorks
  • Atlantic Dominion Solutions
  • Blue Box Group
  • CodeGear
  • E-xact
  • ELC Technologies
  • EnterpriseDB
  • GemStone Systems
  • Intridea
  • Morph Labs
  • RightScale
  • TechRepublic

Sponsorship Opportunities

For information on exhibition and sponsorship opportunities at RailsConf, contact Yvonne Romaine.

Download the RailsConf Sponsor/Exhibitor Prospectus

Media and Promotional Opportunities

Download the Media & Promotional Partner Brochure (PDF) for more information on trade opportunities with O'Reilly conferences, or contact mediapartners@

Program Ideas

Post your suggestions for speakers, topics, and activities on the RailsConf wiki or send an email to

Press and Media

For media-related inquiries, contact

Contact Us

View a complete list of RailsConf 2008 contacts.