Audit your gems (excellent blog post)

In which Evan W. successfully changes his root password with a gem
called Malice.