[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"site-settings":3,"blogpost-web-application-security-practices":72},{"footer":4,"contact_form":6,"chat_widget":11,"accolades":19,"seo_social":63},{"iso_notice":5},"Wolfpack Digital is an ISO 9001:2015, ISO 27001:2013 and ISO 14001:2015 certified company - © _YEAR_ Wolfpack Digital. All rights reserved.",{"budgets":7},[8,9,10],"Under $50.000","Between $50.000 - 200.000","Over $200.000",{"consent":12},{"greeting":13,"title":14,"body":15,"accept_label":16,"decline_label":17,"declined_message":18},"Awoo! I'm Wolfpack Digital's AI assistant. Ask me anything about our services, process, or team, and if you want a project estimate, I can point you to our AI Estimator.","Data Privacy","\u003Cp>Hi there! We would love to talk with you. Under the EU General Data Protection Regulation, we need your approval for our use of personal information (e.g. your name and email address) you may provide as we communicate:\u003C\u002Fp>\n\u003Col>\n  \u003Cli>We'll store your personal information so that we can pick up the conversation if we talk later.\u003C\u002Fli>\n  \u003Cli>We may send you emails to follow up on our discussion here.\u003C\u002Fli>\n  \u003Cli>We may send you emails about our upcoming services and promotions.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Is this okay with you?\u003C\u002Fp>","Yes, I Accept","No, Not Now","No problem. Come back if you change your mind.",{"winnersOfList":20,"awardsList":29,"inHouseAppImages":46,"certificationsList":50},[21,25],{"alt":22,"href":23,"image":24},"European Awards","https:\u002F\u002Fwww.theeuropeanawards.eu\u002Fpremiado\u002Fwolfpack-digital-awarded-in-the-app-development-category","\u002Fimages\u002Fabout-us\u002Fwinners\u002Feuropean.svg",{"alt":26,"href":27,"image":28},"Webby Awards","https:\u002F\u002Fwinners.webbyawards.com\u002F2024\u002Fwebsites-and-mobile-sites\u002Fresponsible-technology\u002Fresponsible-ai\u002F275408\u002Fequality-ai-fair-and-unbiased-algorithms-to-eliminate-discrimination-in-machine-learning-models","\u002Fimages\u002Fabout-us\u002Fwinners\u002Fwebby.svg",[30,34,38,42],{"alt":31,"href":32,"image":33},"Clutch 1000 List Reveals Top-Rated Business Service Providers of 2023","https:\u002F\u002Fclutch.co\u002Fpress-releases\u002Fclutch-1000-fall-2023","\u002Fimages\u002Fabout-us\u002Fawards\u002Fclutch.svg",{"alt":35,"href":36,"image":37},"Clutch Recognizes the 1000 Best B2B Service Providers in its Exclusive 2019 Clutch 1000 List","https:\u002F\u002Fclutch.co\u002Fpress-releases\u002Frecognizes-1000-best-b2b-service-providers-its-exclusive-2019-1000-list","\u002Fimages\u002Fabout-us\u002Fawards\u002Fglobal.svg",{"alt":39,"href":40,"image":41},"Mobile App Daily Award","","\u002Fimages\u002Fabout-us\u002Fawards\u002Fmobile-app-daily.svg",{"alt":43,"href":44,"image":45},"Manifest Award","https:\u002F\u002Fthemanifest.com\u002Fro\u002Fweb-development\u002Fcompanies","\u002Fimages\u002Fabout-us\u002Fawards\u002Fmanifest.svg",[47],{"alt":48,"href":40,"image":49},"Wolfpack Labs","\u002Fimages\u002Fhomepage\u002Fawards\u002Flabs.svg",[51,55,59],{"alt":52,"href":53,"image":54},"ISO 27001 Certification","https:\u002F\u002Fwww.qscert.com\u002Fcs\u002Fissued-certificates\u002F?certID=_7690LD367","\u002Fimages\u002Fabout-us\u002Fcertifications\u002Fiso-27001.svg",{"alt":56,"href":57,"image":58},"ISO 9001 Certification","https:\u002F\u002Fwww.qscert.com\u002Fcs\u002Fissued-certificates\u002F?certID=_7690LBDB0","\u002Fimages\u002Fabout-us\u002Fcertifications\u002Fiso-9001.svg",{"alt":60,"href":61,"image":62},"ISO 14001 Certification","https:\u002F\u002Fwww.qscert.com\u002Fma\u002Fissued-certificates\u002F?certID=_7690LZSGS","\u002Fimages\u002Fabout-us\u002Fcertifications\u002Fiso-14001.svg",{"default_og_image_urls":64,"default_og_image_alt":68,"og_site_name":68,"og_locale":69,"twitter_site":70,"page_type_defaults":71},[65],{"style":66,"url":67},"og","\u002Fimages\u002Fsocial_share_preview.jpg","Wolfpack Digital","en_US","@DigitalWolfpack",{},["Reactive",73],{"title":74,"body":75,"slug":76,"featured_image_urls":77,"meta_tags":102,"reading_time":111,"title_size":112,"tag_list":113,"formatted_published_at":120,"short_description":104,"categories":121,"alt_text":123,"published_at":124,"content_updated_at":125,"formatted_content_updated_at":126,"key_takeaways":127,"faqs":133,"updated_at":146,"canonical_override":40,"no_index":147,"canonical_url":148,"publishers":149},"Web Application Security Best Practices: A Backdoor Case","\u003Cp>At Wolfpack Digital, web application security is a year-round habit, not a once-a-year checklist. Every dependency we ship is a potential door into an app. So when a backdoor turns up in a popular open-source library, we act fast.\u003C\u002Fp>\u003Cp>\r\n\u003C\u002Fp>\u003Cp>This is the story of how we handled one such case, and the web application security best practices that kept our clients safe. It is a useful playbook for any team that builds software.\u003C\u002Fp>\u003Cp>\r\n\u003C\u002Fp>\u003Ch2>What happened: a backdoor in a Ruby gem\u003C\u002Fh2>\u003Cp>\r\n\u003C\u002Fp>\u003Cp>Back in August 2019, security researchers found a backdoor in a widely used Ruby gem. The affected package was the popular \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Frest-client\u002Frest-client\" target=\"_blank\">rest-client\u003C\u002Fa> gem, downloaded more than 100 million times. Attackers had slipped malicious code into versions 1.6.10 through 1.6.13. The code sent data from apps to external servers.\u003C\u002Fp>\u003Cp>\r\n\u003C\u002Fp>\u003Cp>One of the maintainers explained the risk in plain terms:\u003C\u002Fp>\u003Cp>\r\n\u003C\u002Fp>\u003Cp>The data most exposed to this leak is login credentials, used to access databases, payment systems, and other platforms.\u003C\u002Fp>\u003Cp>\r\n\u003C\u002Fp>\u003Cp>Stolen credentials can unlock databases and payment systems, so the stakes were high. We build apps with \u003Ca href=\"https:\u002F\u002Fwww.wolfpack-digital.com\u002Fblogposts\u002Fwhy-use-ruby-on-rails-for-web-app-development\" target=\"_blank\">Ruby on Rails\u003C\u002Fa>, so this news landed close to home. We also cover the basics of secure Rails apps in a \u003Ca href=\"https:\u002F\u002Fwww.wolfpack-digital.com\u002Fblogposts\u002Fdeveloping-secure-web-apps-with-ruby-on-rails\" target=\"_blank\">separate guide\u003C\u002Fa>.\u003C\u002Fp>\u003Cp>\r\n\u003C\u002Fp>\u003Ch2>How we responded: web application security best practices in action\u003C\u002Fh2>\u003Cp>\r\n\u003C\u002Fp>\u003Cp>In under two hours, the whole team knew about the issue. Our Head of Web Development shared clear, quick steps to protect every project we run.\u003C\u002Fp>\u003Cp>\r\n\u003C\u002Fp>\u003Cp>Our engineers ran an X-ray check on all the \u003Ca href=\"https:\u002F\u002Fwww.wolfpack-digital.com\u002Fprojects\" target=\"_blank\">web apps in our portfolio\u003C\u002Fa>. The goal was simple: find every project that used the affected gem.\u003C\u002Fp>\u003Cp>\r\n\u003C\u002Fp>\u003Cp>We need to search all our codebases for Gemfile.lock files that pin one of the malicious versions. If we spot an anomaly, we update to a safe version and ship an immediate release.\u003C\u002Fp>\u003Cp>\r\n\u003C\u002Fp>\u003Cp>The results of our security \u003Ca href=\"https:\u002F\u002Fwww.wolfpack-digital.com\u002Fblogposts\u002Fdesigning-working-with-a-ruby-on-rails-project-audit\" target=\"_blank\">audit\u003C\u002Fa> were reassuring. Every project already ran a safe version, so none were exposed. We then went back to our normal day-to-day work with confidence.\u003C\u002Fp>\u003Cp>\r\n\u003C\u002Fp>\u003Ch2>Web application security best practices for app development teams\u003C\u002Fh2>\u003Cp>\r\n\u003C\u002Fp>\u003Cp>Threats like this one are common. The bigger lesson is that supply chain risk is now a top concern for any team. In fact, the \u003Ca href=\"https:\u002F\u002Fowasp.org\u002FTop10\u002F2025\u002F\" target=\"_blank\">OWASP Top 10 for 2025\u003C\u002Fa> added Software Supply Chain Failures as a new category. It sits high on the list of the most critical web application security risks.\u003C\u002Fp>\u003Cp>\r\n\u003C\u002Fp>\u003Cp>Here are the web application security best practices we recommend to any app development team:\u003C\u002Fp>\u003Cp>\r\n\u003C\u002Fp>\u003Cbr>\u003Cp>\r\n\u003C\u002Fp>\u003Cp>Open-source maintainers can help too. If you publish gems, turn on multi-factor authentication for your \u003Ca href=\"http:\u002F\u002Frubygems.org\u002F\" target=\"_blank\">rubygems.org\u003C\u002Fa> account. That one step makes it much harder for anyone to push a malicious update.\u003C\u002Fp>\u003Cp>\r\n\u003C\u002Fp>\u003Ch2>What we learned\u003C\u002Fh2>\u003Cp>\r\n\u003C\u002Fp>\u003Cp>This case is a good example of how a software development team can react fast and shield its clients. Our \u003Ca href=\"https:\u002F\u002Fwww.wolfpack-digital.com\u002Fblogposts\u002Fiso27001-security-management-certification\" target=\"_blank\">ISO 27001\u003C\u002Fa> and ISO 9001 certifications back this up. They mean security and quality are built into how we work, not bolted on later.\u003C\u002Fp>\u003Cp>\r\n\u003C\u002Fp>\u003Cp>Solid web application security practices help us handle any cyber threat with a clear head. Looking for a trusted partner to \u003Ca href=\"https:\u002F\u002Fwww.wolfpack-digital.com\u002Fcontact\" target=\"_blank\">build a secure web or mobile app\u003C\u002Fa>? Get in touch, and we will take care of your idea from start to finish.\u003C\u002Fp>","web-application-security-practices",[78,81,84,87,90,93,96,99],{"style":79,"url":80},"640","https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fblogpost\u002F31\u002Ffeatured_image\u002F640\u002FRuby_on_Rails_apps_wolfpack_digital_cyber_month_backdoor.webp",{"style":82,"url":83},"768","https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fblogpost\u002F31\u002Ffeatured_image\u002F768\u002FRuby_on_Rails_apps_wolfpack_digital_cyber_month_backdoor.webp",{"style":85,"url":86},"1024","https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fblogpost\u002F31\u002Ffeatured_image\u002F1024\u002FRuby_on_Rails_apps_wolfpack_digital_cyber_month_backdoor.webp",{"style":88,"url":89},"1366","https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fblogpost\u002F31\u002Ffeatured_image\u002F1366\u002FRuby_on_Rails_apps_wolfpack_digital_cyber_month_backdoor.webp",{"style":91,"url":92},"1600","https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fblogpost\u002F31\u002Ffeatured_image\u002F1600\u002FRuby_on_Rails_apps_wolfpack_digital_cyber_month_backdoor.webp",{"style":94,"url":95},"1920","https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fblogpost\u002F31\u002Ffeatured_image\u002F1920\u002FRuby_on_Rails_apps_wolfpack_digital_cyber_month_backdoor.webp",{"style":97,"url":98},"thumb","https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fblogpost\u002F31\u002Ffeatured_image\u002Fthumb\u002FRuby_on_Rails_apps_wolfpack_digital_cyber_month_backdoor.webp",{"style":100,"url":101},"original","https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fblogpost\u002F31\u002Ffeatured_image\u002Foriginal\u002FRuby_on_Rails_apps_wolfpack_digital_cyber_month_backdoor.webp",{"title":103,"description":104,"keywords":105,"contact_form:title":106,"contact_form:cta":107,"og:site_name":68,"og:type":108,"og:locale":69,"twitter:card":109,"twitter:site":70,"twitter:creator":70,"image":110,"og:image":40,"og:title":74,"og:video":40,"twitter:title":74,"og:description":104,"twitter:player":40,"twitter:image:src":40,"twitter:description":104},"Web Application Security Best Practices | Wolfpack Digital","See how Wolfpack Digital handled a Ruby gem backdoor and the web application security best practices that keep client apps safe.","web application security, web application security best practices, secure web application, software supply chain security, OWASP Top 10, open source dependency security","contact us","send message","article","summary_large_image","Open door with a light beam and red shards symbolizing a web application security backdoor - Wolfpack Digital","3",32,[114,115,116,117,118,119],"apps","Cyber","Month","web","ruby","backdoor","Sep 5, 2019",[122],"web-development","Open door with a light beam and red shards symbolizing a web application security backdoor","2019-09-05T08:44:54.000Z","2026-07-02T06:59:25.935Z","Jul 2, 2026",[128,129,130,131,132],"Web application security is an ongoing practice, not a one-off audit.","The 2019 rest-client Ruby gem backdoor leaked credentials from apps using versions 1.6.10 to 1.6.13.","Wolfpack Digital scanned every project in under two hours and confirmed all ran safe versions.","The OWASP Top 10 for 2025 lists Software Supply Chain Failures as a new critical risk category.","Core best practices: test often, use multi-factor authentication, audit dependencies, monitor the supply chain, and keep an incident plan.",[134,137,140,143],{"answer":135,"question":136},"Key practices include testing products regularly for vulnerabilities, using strong multi-factor authentication, auditing open-source dependencies, monitoring your software supply chain, and keeping a clear incident response plan so your team can react quickly to threats.","What are web application security best practices?",{"answer":138,"question":139},"In August 2019, attackers inserted malicious code into versions 1.6.10 to 1.6.13 of the popular rest-client Ruby gem. The code sent data, including login credentials, to external servers.","What was the 2019 Ruby gem backdoor?",{"answer":141,"question":142},"A software supply chain attack targets the third-party libraries, tools, or dependencies an app relies on. The 2025 OWASP Top 10 added Software Supply Chain Failures as a dedicated risk category because these attacks are increasingly common.","What is a software supply chain attack?",{"answer":144,"question":145},"Wolfpack Digital follows ISO 27001 and ISO 9001 certified processes, audits dependencies, tests regularly, and responds to emerging threats within hours. Security and quality are built into how the team works.","How does Wolfpack Digital keep client apps secure?","2026-07-02T06:59:25.936Z",false,"https:\u002F\u002Fwww.wolfpack-digital.com\u002Fblogposts\u002Fweb-application-security-practices",[150],{"id":151,"author":152,"short_description":153,"role":154,"avatar_urls":155,"cover_urls":175,"linkedin_link":194,"instagram_link":40,"x_link":40,"meta_tags":195,"last_published_at":199,"same_as":200},130,"Ramona Rohan","\u003Cp>Ramona is the Head of Quality Assurance at Wolfpack Digital, leading QA strategy and agile delivery practices with over 15 years of experience ensuring digital products meet the highest standards of quality, reliability, and performance. With a Ph.D. in Mathematics and degrees in Mathematics &amp; Computer Science, she brings exceptional analytical rigor, structured thinking, and problem-solving capabilities to quality assurance.\u003C\u002Fp>\u003Cbr>\u003Cp>Her unique academic background provides a foundation for approaching QA with mathematical precision and systematic methodology. Ramona excels at identifying edge cases, designing comprehensive test strategies, and implementing quality processes that scale with product complexity. She understands that effective quality assurance goes beyond finding bugs—it requires understanding user behavior, anticipating failure scenarios, and building quality into every stage of the development lifecycle.\u003C\u002Fp>\u003Cbr>\u003Cp>As a QA leader, Ramona's approach is characterized by adaptability and continuous improvement. She views each project as an opportunity for learning and growth, fostering a culture where quality is everyone's responsibility.\u003C\u002Fp>\u003Cbr>\u003Cp>Ramona brings both discipline and adaptability to her role, balancing the structure needed for thorough testing with the agility required in fast-paced product development. She leads cross-functional collaboration between QA, development, design, and product teams, ensuring quality considerations are integrated from initial planning through post-launch monitoring.\u003C\u002Fp>\u003Cbr>\u003Cp>Her expertise spans manual and automated testing, performance testing, security testing, test automation frameworks, agile and DevOps methodologies, and building quality-focused development cultures. Ramona has played a crucial role in delivering 250+ digital products that consistently earn high user satisfaction ratings.\u003C\u002Fp>\u003Cbr>\u003Cp>Through her blog contributions, Ramona shares insights on QA best practices, test automation strategies, integrating quality into agile workflows, building effective QA teams, and the evolving role of AI in quality assurance. Her writing reflects a commitment to elevating quality standards across the software industry.\u003C\u002Fp>\u003Cbr>\u003Cp>\u003Cstrong>Areas of expertise:\u003C\u002Fstrong> Quality assurance strategy, test automation, agile methodologies, manual and automated testing, performance testing, security testing, continuous integration\u002Fcontinuous delivery (CI\u002FCD), QA team leadership, process optimization, risk assessment, quality metrics\u003C\u002Fp>","Head of Quality Assurance",[156,158,160,162,164,166,168,170,173],{"style":79,"url":157},"https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Favatar\u002F640\u002FRamona.webp",{"style":82,"url":159},"https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Favatar\u002F768\u002FRamona.webp",{"style":85,"url":161},"https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Favatar\u002F1024\u002FRamona.webp",{"style":88,"url":163},"https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Favatar\u002F1366\u002FRamona.webp",{"style":91,"url":165},"https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Favatar\u002F1600\u002FRamona.webp",{"style":94,"url":167},"https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Favatar\u002F1920\u002FRamona.webp",{"style":97,"url":169},"https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Favatar\u002Fthumb\u002FRamona.webp",{"style":171,"url":172},"medium","https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Favatar\u002Fmedium\u002FRamona.webp",{"style":100,"url":174},"https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Favatar\u002Foriginal\u002FRamona.webp",[176,178,180,182,184,186,188,190,192],{"style":79,"url":177},"https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Fcover_image\u002F640\u002FRamona.webp",{"style":82,"url":179},"https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Fcover_image\u002F768\u002FRamona.webp",{"style":85,"url":181},"https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Fcover_image\u002F1024\u002FRamona.webp",{"style":88,"url":183},"https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Fcover_image\u002F1366\u002FRamona.webp",{"style":91,"url":185},"https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Fcover_image\u002F1600\u002FRamona.webp",{"style":94,"url":187},"https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Fcover_image\u002F1920\u002FRamona.webp",{"style":97,"url":189},"https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Fcover_image\u002Fthumb\u002FRamona.webp",{"style":171,"url":191},"https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Fcover_image\u002Fmedium\u002FRamona.webp",{"style":100,"url":193},"https:\u002F\u002Fcdn.wolfpack-digital.com\u002Fstore\u002Fpublisher\u002F130\u002Fcover_image\u002Foriginal\u002FRamona.webp","https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Frohanramona\u002F",{"title":196,"description":197,"keywords":40,"contact_form:title":106,"contact_form:cta":107,"og:site_name":68,"og:type":198,"og:locale":69,"twitter:card":109,"twitter:site":70,"twitter:creator":70},"Ramona - Head of QA | Wolfpack Digital Blog","Quality assurance leader with Ph.D. in Mathematics and 15+ years experience. Expert insights on QA strategy, test automation, agile methodologies, and continuous improvement.","website","2026-04-21T12:37:05.000Z",[194]]