[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"site-settings":3,"blogpost-web-application-security-practices":72},{"footer":4,"contact_form":6,"chat_widget":11,"accolades":19,"seo_social":63},{"iso_notice":5},"Wolfpack Digital is an ISO 9001:2015, ISO 27001:2013 and ISO 14001:2015 certified company - © _YEAR_ Wolfpack Digital. All rights reserved.",{"budgets":7},[8,9,10],"Under $50.000","Between $50.000 - 200.000","Over $200.000",{"consent":12},{"greeting":13,"title":14,"body":15,"accept_label":16,"decline_label":17,"declined_message":18},"Awoo! I'm Wolfpack Digital's AI assistant. Ask me anything about our services, process, or team, and if you want a project estimate, I can point you to our AI Estimator.","Data Privacy","\u003Cp>Hi there! We would love to talk with you. Under the EU General Data Protection Regulation, we need your approval for our use of personal information (e.g. your name and email address) you may provide as we communicate:\u003C\u002Fp>\n\u003Col>\n  \u003Cli>We'll store your personal information so that we can pick up the conversation if we talk later.\u003C\u002Fli>\n  \u003Cli>We may send you emails to follow up on our discussion here.\u003C\u002Fli>\n  \u003Cli>We may send you emails about our upcoming services and promotions.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Is this okay with you?\u003C\u002Fp>","Yes, I Accept","No, Not Now","No problem. Come back if you change your mind.",{"winnersOfList":20,"awardsList":29,"inHouseAppImages":46,"certificationsList":50},[21,25],{"alt":22,"href":23,"image":24},"European Awards","https:\u002F\u002Fwww.theeuropeanawards.eu\u002Fpremiado\u002Fwolfpack-digital-awarded-in-the-app-development-category","\u002Fimages\u002Fabout-us\u002Fwinners\u002Feuropean.svg",{"alt":26,"href":27,"image":28},"Webby Awards","https:\u002F\u002Fwinners.webbyawards.com\u002F2024\u002Fwebsites-and-mobile-sites\u002Fresponsible-technology\u002Fresponsible-ai\u002F275408\u002Fequality-ai-fair-and-unbiased-algorithms-to-eliminate-discrimination-in-machine-learning-models","\u002Fimages\u002Fabout-us\u002Fwinners\u002Fwebby.svg",[30,34,38,42],{"alt":31,"href":32,"image":33},"Clutch 1000 List Reveals Top-Rated Business Service Providers of 2023","https:\u002F\u002Fclutch.co\u002Fpress-releases\u002Fclutch-1000-fall-2023","\u002Fimages\u002Fabout-us\u002Fawards\u002Fclutch.svg",{"alt":35,"href":36,"image":37},"Clutch Recognizes the 1000 Best B2B Service Providers in its Exclusive 2019 Clutch 1000 List","https:\u002F\u002Fclutch.co\u002Fpress-releases\u002Frecognizes-1000-best-b2b-service-providers-its-exclusive-2019-1000-list","\u002Fimages\u002Fabout-us\u002Fawards\u002Fglobal.svg",{"alt":39,"href":40,"image":41},"Mobile App Daily Award","","\u002Fimages\u002Fabout-us\u002Fawards\u002Fmobile-app-daily.svg",{"alt":43,"href":44,"image":45},"Manifest Award","https:\u002F\u002Fthemanifest.com\u002Fro\u002Fweb-development\u002Fcompanies","\u002Fimages\u002Fabout-us\u002Fawards\u002Fmanifest.svg",[47],{"alt":48,"href":40,"image":49},"Wolfpack Labs","\u002Fimages\u002Fhomepage\u002Fawards\u002Flabs.svg",[51,55,59],{"alt":52,"href":53,"image":54},"ISO 27001 Certification","https:\u002F\u002Fwww.qscert.com\u002Fcs\u002Fissued-certificates\u002F?certID=_7690LD367","\u002Fimages\u002Fabout-us\u002Fcertifications\u002Fiso-27001.svg",{"alt":56,"href":57,"image":58},"ISO 9001 Certification","https:\u002F\u002Fwww.qscert.com\u002Fcs\u002Fissued-certificates\u002F?certID=_7690LBDB0","\u002Fimages\u002Fabout-us\u002Fcertifications\u002Fiso-9001.svg",{"alt":60,"href":61,"image":62},"ISO 14001 Certification","https:\u002F\u002Fwww.qscert.com\u002Fma\u002Fissued-certificates\u002F?certID=_7690LZSGS","\u002Fimages\u002Fabout-us\u002Fcertifications\u002Fiso-14001.svg",{"default_og_image_urls":64,"default_og_image_alt":68,"og_site_name":68,"og_locale":69,"twitter_site":70,"page_type_defaults":71},[65],{"url":66,"style":67},"\u002Fimages\u002Fsocial_share_preview.jpg","og","Wolfpack Digital","en_US","@DigitalWolfpack",{},["Reactive",73],{"title":74,"body":75,"slug":76,"featured_image_urls":77,"meta_tags":102,"reading_time":109,"title_size":110,"tag_list":111,"formatted_published_at":118,"short_description":103,"categories":119,"alt_text":121,"published_at":122,"content_updated_at":121,"formatted_content_updated_at":121,"key_takeaways":123,"faqs":124,"updated_at":125,"canonical_override":121,"no_index":126,"canonical_url":127,"publishers":128},"Best web application security practices to apply if a backdoor is found","\u003Cp dir=\"ltr\">Here at Wolfpack Digital, we are all into Cyber Month Prep. Suddenly in the middle of August, when nobody was expecting it, a backdoor was found in a Ruby gem. It was like seeing Santa in your backyard wearing Hawaii flower-power clothes - very unexpected for our web application security!\u003C\u002Fp>\r\n\r\n\u003Cp dir=\"ltr\">We use \u003Ca href=\"https:\u002F\u002Frubyonrails.org\u002F\" target=\"_blank\">Ruby on Rails\u003C\u002Fa> for building apps, and in case you are not familiar with it, we have written an article about \u003Ca href=\"https:\u002F\u002Fmedium.com\u002Fwolfpack-digital\u002Fruby-on-rails-what-the-hack-is-this-and-why-is-it-important-for-your-product-8a8cb32c0cef\" target=\"_blank\">what the &lt;hack&gt; is Ruby on Rails \u003C\u002Fa>and why is it important for your product.\u003C\u002Fp>\r\n\r\n\u003Cp dir=\"ltr\"> \u003C\u002Fp>\r\n\r\n\u003Ch2 dir=\"ltr\">1.   What’s up with this latest Ruby Backdoor  - the threat and possible damages\u003C\u002Fh2>\r\n\r\n\u003Cp dir=\"ltr\">The Ruby backdoor identified in August 2019 refers to one of the ruby gems that have been widely used by developers worldwide (113 million downloads) when building web apps. \u003C\u002Fp>\r\n\r\n\u003Cp dir=\"ltr\">The gem that has been affected is \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Frest-client\u002Frest-client\" target=\"_blank\">REST- client.\u003C\u002Fa> And it seems that hackers have inserted malicious code in order to send data from apps to external servers. The versions that were affected are REST- client 1.6.10 to \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Frest-client\u002Frest-client\u002Fissues\u002F713\" target=\"_blank\">REST -client 1.6.13.\u003C\u002Fa> \u003C\u002Fp>\r\n\r\n\u003Cp dir=\"ltr\"> \u003C\u002Fp>\r\n\r\n\u003Cp dir=\"ltr\">One of the ruby sustainers has explained what kind of information hackers can collect. \u003C\u002Fp>\r\n\r\n\u003Cp dir=\"ltr\"> \u003C\u002Fp>\r\n\r\n\u003Cblockquote>\r\n\u003Cp dir=\"ltr\">“The data most exposed to this leak is login credentials, used to access databases, payment systems, among other platforms.” \u003C\u002Fp>\r\n\r\n\u003Cp dir=\"ltr\">- Jan Dintel\u003C\u002Fp>\r\n\u003C\u002Fblockquote>\r\n\r\n\u003Cp dir=\"ltr\"> \u003C\u002Fp>\r\n\r\n\u003Ch2 dir=\"ltr\">2.   Implementing best web application security practices \u003C\u002Fh2>\r\n\r\n\u003Cp dir=\"ltr\">Here is how we kept our web apps safe. In less than 2 hours, the entire \u003Ca href=\"https:\u002F\u002Fwww.wolfpack-digital.com\u002Fteam\" target=\"_blank\">Wolfpack Digital team\u003C\u002Fa> knew about the issue. Florin, our Head of Web Development has provided instructions with quick steps to ensure web application security of our projects. \u003C\u002Fp>\r\n\r\n\u003Cp dir=\"ltr\">Our technical team did an ‘X-ray’ check on all the \u003Ca href=\"https:\u002F\u002Fwww.wolfpack-digital.com\u002Fprojects\" target=\"_blank\">web apps from our portfolio\u003C\u002Fa> in order to detect the projects where the Rest Client Ruby gem has been used. \u003C\u002Fp>\r\n\r\n\u003Cp dir=\"ltr\"> \u003C\u002Fp>\r\n\r\n\u003Cblockquote>\r\n\u003Cp dir=\"ltr\">“It’s a serious situation. We need to search for Gemfile.lock files containing one of the malicious versions in all codebases we are responsible for. Check the versions that have been used. In case you identify an anomaly, we have to update to a safe version and do an immediate release.” \u003C\u002Fp>\r\n\r\n\u003Cp dir=\"ltr\">- Florin, Head of Web Development\u003C\u002Fp>\r\n\u003C\u002Fblockquote>\r\n\r\n\u003Cp dir=\"ltr\"> \u003C\u002Fp>\r\n\r\n\u003Cp dir=\"ltr\">The results of our security audit have shown that all our web projects were safe. We used the updated versions that weren't affected by the hackers. \u003C\u002Fp>\r\n\r\n\u003Cp dir=\"ltr\">Now we can be at peace since we acted by the book and we can continue our normal day-to-day coding.\u003C\u002Fp>\r\n\r\n\u003Cp dir=\"ltr\"> \u003C\u002Fp>\r\n\r\n\u003Ch2 dir=\"ltr\">3.   Cybersecurity tips for app development companies \u003C\u002Fh2>\r\n\r\n\u003Cp dir=\"ltr\">Cyber attacks are on the daily agenda of the world’s leaders. They are starting to affect us in all the daily life aspects: personal data privacy, business, and government systems security, together with terrorist cyber attacks. \u003C\u002Fp>\r\n\r\n\u003Cp dir=\"ltr\">Here are some of the cybersecurity tips that app development companies should consider: \u003C\u002Fp>\r\n\r\n\u003Cul>\r\n\t\u003Cli dir=\"ltr\">\r\n\t\u003Cp dir=\"ltr\" role=\"presentation\">Always make sure you regularly test the products you are building in order to \u003Cstrong>detect vulnerabilities\u003C\u002Fstrong> ahead of time; \u003C\u002Fp>\r\n\t\u003C\u002Fli>\r\n\t\u003Cli dir=\"ltr\">\r\n\t\u003Cp dir=\"ltr\" role=\"presentation\">Adopt \u003Cstrong>strong authentication\u003C\u002Fstrong> measures for your web and mobile apps to keep the intruders away; \u003C\u002Fp>\r\n\t\u003C\u002Fli>\r\n\t\u003Cli dir=\"ltr\">\r\n\t\u003Cp dir=\"ltr\" role=\"presentation\">Check the issues of the \u003Cstrong>open-source library\u003C\u002Fstrong> you're about to use and make sure to keep up with the \u003Cstrong>security updates\u003C\u002Fstrong>.\u003C\u002Fp>\r\n\t\u003C\u002Fli>\r\n\u003C\u002Ful>\r\n\r\n\u003Cp dir=\"ltr\">A little piece of advice for the \u003Cstrong>ruby gems maintainers\u003C\u002Fstrong> - you should consider enabling two-factor authentication on your \u003Ca href=\"http:\u002F\u002Frubygems.org\u002F\" target=\"_blank\">rubygems.org\u003C\u002Fa> account. Also, make sure nobody will ever release an update containing malicious code.  \u003Ca href=\"https:\u002F\u002Fguides.rubygems.org\u002Fsetting-up-multifactor-authentication\u002F\" target=\"_blank\">Check this guide\u003C\u002Fa> on how to do it.\u003C\u002Fp>\r\n\r\n\u003Cp dir=\"ltr\"> \u003C\u002Fp>\r\n\r\n\u003Ch2 dir=\"ltr\">What we've learned\u003C\u002Fh2>\r\n\r\n\u003Cp dir=\"ltr\">The story with the August 2019 Ruby backdoor is just an example of how an \u003Cstrong>app development company\u003C\u002Fstrong> can react quickly on fixing an issue that could have affected directly its clients. \u003C\u002Fp>\r\n\r\n\u003Cp dir=\"ltr\">The best thing about being in the tech field is that we have the right expertise and resources to fix immediately any malicious threat. Our responsibility is to make sure that the clients that have chosen to work with us won’t be affected by the hackers. \u003C\u002Fp>\r\n\r\n\u003Cp dir=\"ltr\">We are back to developing powerful web and mobile apps. Please be sure that our web application security practices will always help us deal with any cyber threat. \u003C\u002Fp>\r\n\r\n\u003Cp>Looking for a trustful partner to \u003Ca href=\"http:\u002F\u002Fwww.wolfpack-digital.com\u002Fcontact\" target=\"_blank\">build a secure mobile or web app\u003C\u002Fa> for your business? Give us a sign and we’ll take care of the safety of your idea.\u003C\u002Fp>\r\n","web-application-security-practices",[78,81,84,87,90,93,96,99],{"style":79,"url":80},"640","https:\u002F\u002Fwolfpack-digital-attachments-staging.s3.eu-west-2.amazonaws.com\u002Fstore\u002Fblogpost\u002F31\u002Ffeatured_image\u002F640\u002Fimage_processing20220615-4-xdxzhm.webp",{"style":82,"url":83},"768","https:\u002F\u002Fwolfpack-digital-attachments-staging.s3.eu-west-2.amazonaws.com\u002Fstore\u002Fblogpost\u002F31\u002Ffeatured_image\u002F768\u002Fimage_processing20220615-4-xdxzhm.webp",{"style":85,"url":86},"1024","https:\u002F\u002Fwolfpack-digital-attachments-staging.s3.eu-west-2.amazonaws.com\u002Fstore\u002Fblogpost\u002F31\u002Ffeatured_image\u002F1024\u002Fimage_processing20220615-4-xdxzhm.webp",{"style":88,"url":89},"1366","https:\u002F\u002Fwolfpack-digital-attachments-staging.s3.eu-west-2.amazonaws.com\u002Fstore\u002Fblogpost\u002F31\u002Ffeatured_image\u002F1366\u002Fimage_processing20220615-4-xdxzhm.webp",{"style":91,"url":92},"1600","https:\u002F\u002Fwolfpack-digital-attachments-staging.s3.eu-west-2.amazonaws.com\u002Fstore\u002Fblogpost\u002F31\u002Ffeatured_image\u002F1600\u002Fimage_processing20220615-4-xdxzhm.webp",{"style":94,"url":95},"1920","https:\u002F\u002Fwolfpack-digital-attachments-staging.s3.eu-west-2.amazonaws.com\u002Fstore\u002Fblogpost\u002F31\u002Ffeatured_image\u002F1920\u002Fimage_processing20220615-4-xdxzhm.webp",{"style":97,"url":98},"thumb","https:\u002F\u002Fwolfpack-digital-attachments-staging.s3.eu-west-2.amazonaws.com\u002Fstore\u002Fblogpost\u002F31\u002Ffeatured_image\u002Fthumb\u002Fimage_processing20220615-4-xdxzhm.webp",{"style":100,"url":101},"original","https:\u002F\u002Fwolfpack-digital-attachments-staging.s3.eu-west-2.amazonaws.com\u002Fstore\u002Fblogpost\u002F31\u002Ffeatured_image\u002Foriginal\u002Fimage_processing20220615-4-xdxzhm.webp",{"title":74,"description":103,"keywords":40,"contact_form:title":104,"contact_form:cta":105,"og:site_name":68,"og:type":106,"og:locale":69,"twitter:card":107,"twitter:site":70,"twitter:creator":70,"image":108,"og:image":40,"og:title":74,"og:video":40,"twitter:title":74,"og:description":103,"twitter:player":40,"twitter:image:src":40,"twitter:description":103},"Learn how the Wolfpack Digital team took care of our web application security when a Ruby backdoor was found. Happy Cyber Month! ","contact us","send message","article","summary_large_image","Web application security practices to deal with backdoor found in Ruby library, Ruby on Rails web apps by Wolfpack Digital","3 min",32,[112,113,114,115,116,117],"Cyber","Month","backdoor","web","ruby","apps","Sep 5, 2019",[120],"web-development",null,"2019-09-05T08:44:54.041Z",[],[],"2022-06-16T08:58:52.552Z",false,"https:\u002F\u002Fwd-fe-stage.herokuapp.com\u002Fblogposts\u002Fweb-application-security-practices",[129],{"id":130,"author":131,"short_description":132,"role":133,"avatar_urls":134,"cover_urls":121,"linkedin_link":121,"instagram_link":121,"x_link":121,"meta_tags":142,"last_published_at":144,"same_as":145},4,"Valentina","Startup world stalker and innovation hunter, former chess player with a soft spot for history of art. ","Marketing Specialist ",[135,137,140],{"style":97,"url":136},"https:\u002F\u002Fwolfpack-digital-attachments-staging.s3.eu-west-2.amazonaws.com\u002Fstore\u002Fpublisher\u002F4\u002Favatar\u002Fthumb\u002FValentina_biciuc_marketing_specialist_at_wolfpack_digital.webp",{"style":138,"url":139},"medium","https:\u002F\u002Fwolfpack-digital-attachments-staging.s3.eu-west-2.amazonaws.com\u002Fstore\u002Fpublisher\u002F4\u002Favatar\u002Fmedium\u002FValentina_biciuc_marketing_specialist_at_wolfpack_digital.webp",{"style":100,"url":141},"https:\u002F\u002Fwolfpack-digital-attachments-staging.s3.eu-west-2.amazonaws.com\u002Fstore\u002Fpublisher\u002F4\u002Favatar\u002Foriginal\u002FValentina_biciuc_marketing_specialist_at_wolfpack_digital.webp",{"title":40,"description":40,"keywords":40,"contact_form:title":104,"contact_form:cta":105,"og:site_name":68,"og:type":143,"og:locale":69,"twitter:card":107,"twitter:site":70,"twitter:creator":70},"website","2021-09-16T08:39:12.000Z",[]]