GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    abadidea (0xabad1dea@infosec.exchange)'s status on Tuesday, 13-May-2025 19:09:24 JST abadidea abadidea

    Incredible: if you voice-dictate a message about adult chuck-e-cheese alternative Dave & Busters into iMessage, it gets flagged as a potential hacking attempt by the other iMessage client and never arrives. Because the voice-to-text detects it as a known phrase with a special typography (with the "&", not "and"), but the substitution is happening at the wrong layer and so it gets encoded as a raw '&' in the message HTML rather than an '&'. The other end correctly detects malformed HTML and panics.

    Presumably, you could also run into this problem with other brands such as Simon & Schuster.

    https://rambo.codes/posts/2025-05-12-cracking-the-dave-and-busters-anomaly

    In conversation about a month ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: rambo.codes
      Cracking The Dave & Buster’s Anomaly | Rambo Codes
      Gui Rambo writes about his coding and reverse engineering adventures.
    • Haelwenn /элвэн/ :triskell: likes this.
    • Rich Felker repeated this.
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Tuesday, 13-May-2025 20:41:02 JST Rich Felker Rich Felker
      in reply to

      @0xabad1dea This is such amateur hour shit that wouldn't even be possible without things being deeply wrong at multiple layers...

      In conversation about a month ago permalink
    • Embed this notice
      Andrew Zonenberg (azonenberg@ioc.exchange)'s status on Tuesday, 13-May-2025 20:41:55 JST Andrew Zonenberg Andrew Zonenberg
      in reply to

      @0xabad1dea I used an XML-esque passphrase (something along the lines of <FooBarBaz/>) on PlentyOfFish circa 2013 because they demanded special characters even for absurdly long passphrases.

      It worked fine.

      Until my now-wife and I got serious enough I decided to delete my account. I had to type my password on the "delete account" page and for whatever reason on that page only (but not the login form or the creation page), it tripped the WAF and blocked the deletion.

      I ended up experimenting a bit and discovered that I could still *change* my password and as soon as I had a password without angle brackets in it, I was able to delete the account.

      In conversation about a month ago permalink

      Attachments


      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      tom jennings (tomjennings@tldr.nettime.org)'s status on Wednesday, 14-May-2025 08:36:22 JST tom jennings tom jennings
      in reply to
      • jack

      @jackeric @0xabad1dea

      Panicking on malformed payload is very last century.

      In conversation about a month ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      jack (jackeric@beige.party)'s status on Wednesday, 14-May-2025 08:36:23 JST jack jack
      in reply to

      @0xabad1dea Input validation is so last century

      In conversation about a month ago permalink
    • Embed this notice
      Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 14-May-2025 08:38:29 JST Haelwenn /элвэн/ :triskell: Haelwenn /элвэн/ :triskell:
      in reply to
      • tom jennings
      • jack
      @tomjennings @jackeric @0xabad1dea I so wish I would actually be a previous millennium thing.
      In conversation about a month ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.