Hacker News new | ask | show | jobs
by CGamesPlay 2625 days ago
Everything in the first line is a diversion to make the code look complicated but realistic. The eval is what the backdoor does, which means it looks at a cookie with some basic encoding, and runs it as ruby code. There’s no authentication or anything here, the backdoor will work for anyone who cares to set that cookie.