GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Micah Lee (micahflee@infosec.exchange)'s status on Monday, 08-Sep-2025 21:30:27 JST Micah Lee Micah Lee

    I told Joshua Aaron, developer of ICEBlock, that he was running a vulnerable version of Apache on his server. He ignored my vulnerability report and blocked me, and his service is still vulnerable today https://micahflee.com/iceblock-handled-my-vulnerability-report-in-the-worst-possible-way/

    In conversation about a year ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: micahflee.com
      ICEBlock handled my vulnerability report in the worst possible way
      Last week, I wrote about how Joshua Aaron's ICEBlock app, which allows people to anonymously report ICE sightings within a 5-mile radius, is – unfortunately, and despite apparent good intentions – activism theater. This was based on Joshua's talk at HOPE where he made it clear that he isn't taking the advice
    • Rich Felker repeated this.
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Monday, 08-Sep-2025 21:30:26 JST Rich Felker Rich Felker
      in reply to

      @micahflee Can you clarify whether you have any reason to believe it's actually vulnerable to anything? Most of those vulns only affect wacky configurations, commercial hosting environments where the customers are untrusted and may be running malicious serverside code, and particular types of web application stuff (vs static content).

      Personally I tend to look unkindly on vuln reporters who assert that something of mine is vulnerable based on some checklist for the version they find running rather than actual analysis.

      In conversation about a year ago permalink
    • Embed this notice
      MR.e (mr_e@infosec.exchange)'s status on Monday, 08-Sep-2025 21:31:47 JST MR.e MR.e
      in reply to

      @micahflee
      For someone just trying to help their neighbors. I want to make sure I understand that I should advise them to not use the app and let others in their community know?

      I've read your other blogs about the ecosystem problems with the app and I this should be an, "Oh, duh." Sort of thing but I want to be very sure what I'm communicating before I send a message to folks who are already scared and not technology saavy.

      Its more that I don't have experience with how to help folks in this situation and I want to make sure I'm not knee jerk doing something that compounds other issues they are facing that I'm ignorant to. Thank you for your and anyone else's patients in educating me.

      In conversation about a year ago permalink
    • Embed this notice
      buherator (buherator@infosec.place)'s status on Monday, 08-Sep-2025 21:33:02 JST buherator buherator
      in reply to
      • Hans-Martin Münch
      @h0ng10 @micahflee This is a fairly common mistake too and causes a lot of bullshit work for security teams. A banner string (*especially* in case of Apache HTTPd) doesn't mean anything, so unless you can demonstrate the presence of a vulnerability this is nothing (aka PoC||GTFO).

      (edited) In addition the cited CVE-2024-38476 requires a *malicious backend* to be exploitable:

      https://devco.re/blog/2024/08/09/confusion-attacks-exploiting-hidden-semantic-ambiguity-in-apache-http-server-en/
      In conversation about a year ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: devco.re
        Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server! | DEVCORE 戴夫寇爾
        from d3vc0r3
        This article explores architectural issues within the Apache HTTP Server, highlighting several technical debts within Httpd, including 3 types of Confusion Attacks, 9 new vulnerabilities, 20 exploitation techniques, and over 30 case studies. The content includes, but is not limited to: 1. How a single ? can bypass Httpd's built-in access control and authentication. 2. How unsafe RewriteRules can escape the Web Root and access the entire filesystem. 3. How to leverage a piece of code from 1996 to transform an XSS into RCE.
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Hans-Martin Münch (h0ng10@infosec.exchange)'s status on Monday, 08-Sep-2025 21:33:05 JST Hans-Martin Münch Hans-Martin Münch
      in reply to

      @micahflee Please note that installing the latest Ubuntu security updates for Apache httpd does not necessarily upgrade Apache to the latest available version. Instead, security fixes are typically backported to the version included with the distribution. As a result, the displayed version remains unchanged.

      For example, even after fully updating Ubuntu 22.04 LTS, the Apache version shown in the Server header still appears as 2.4.52, despite being patched with the latest security fixes.

      In conversation about a year ago permalink
      Rich Felker repeated this.
    • Embed this notice
      Jess👾 (jesstheunstill@infosec.exchange)'s status on Monday, 08-Sep-2025 22:11:19 JST Jess👾 Jess👾
      in reply to
      • Rich Felker

      Yeah, an unauthenticated nmap scan getting back a banner header is essentially worthless as an actual vulnerability detection. I get beg bounties for that shit constantly. And a lot of times it's just shit on the load balancer anyways.
      @dalias @micahflee

      In conversation about a year ago permalink
      Rich Felker repeated this.
    • Embed this notice
      Jess👾 (jesstheunstill@infosec.exchange)'s status on Monday, 08-Sep-2025 22:11:19 JST Jess👾 Jess👾
      in reply to

      Furthermore, that particular CVE only creates a vulnerable configuration if they're running Apache httpd with mod_rewrite or mod_proxy. Which means if you aren't running those modules, that vuln isn't a vuln. LOTS of vulns with big scary CVSS numbers aren't actually a vulnerability unless you're using the software with specific configurations enabled.

      For fucks sake, at least read the goddamn CVE links.

      https://nvd.nist.gov/vuln/detail/CVE-2024-38476

      https://httpd.apache.org/security/vulnerabilities_24.html

      I'd block you too if you showed up smearing my app with no more evidence than a low effort nmap.

      @dalias @micahflee

      In conversation about a year ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Monday, 08-Sep-2025 22:11:59 JST Rich Felker Rich Felker
      in reply to
      • Jess👾

      @JessTheUnstill @micahflee Exactly. I ignore "vuln reporters" who copy & paste drivel from scanners, and block if they keep being annoying about it.

      In conversation about a year ago permalink
    • Embed this notice
      xyhhx 🔻 (xyhhx@nso.group)'s status on Tuesday, 09-Sep-2025 00:39:29 JST xyhhx 🔻 xyhhx 🔻
      in reply to
      • Rich Felker
      • Jess👾

      @JessTheUnstill can't tell if "beg bounties" is a typo or a funni play on words

      @dalias @micahflee

      In conversation about a year ago permalink
      Haelwenn /элвэн/ :triskell: likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.