GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    rats (rats@refusal.biz)'s status on Thursday, 29-Sep-2022 11:30:22 JSTratsrats
    in reply to
    • pistolero :thispersondoesnotexist:
    • Zero :zt_think: :artix:
    • Johnny Peligro
    • spiral
    • netdoll
    • Katherine Faraday, esnoam princess
    @zero @spiral @KayFaraday @p @netdoll @MischievousTomato

    > one small difference, his posts with "direct messages". everything else is exactly the same, he doesn't care about it being exploitable because he can't even fix his own code

    i'll admit i haven't really dug into the code here but from my current understanding of the blockbots and what pete is doing, this doesn't sound exploitable in the same way because it's a single message sent to a single instance (or maybe it doesn't leave the instance if it's just for FSE users?)

    but i'll say that i'd be interested in hearing if this is still exploitable! and a good way to make pete care would be to give him a taste of his own medicine and use it to fuck up FSE and give him a problem he needs to go fix immediately :)

    > one small difference

    this is my fav bug ive seen in a ctf: https://bugs.chromium.org/p/project-zero/issues/detail?id=1710

    the v8 javascript engine's jit had a bug where a range of numbers didn't include a "-0" when it should've included one. who even knows what a -0 is? who cares?

    not including a -0, it turns out, let people write javascript that could execute arbitrary assembly for anyone visiting the page: https://doar-e.github.io/blog/2019/01/28/introduction-to-turbofan/

    small differences - if they are the exact right small difference - can matter a lot
    In conversationThursday, 29-Sep-2022 11:30:22 JST from refusal.bizpermalink

    Attachments

    1. No result found on File_thumbnail lookup.
      1710 - project-zero - Project Zero - Monorail
    2. Domain not in remote thumbnail source whitelist: doar-e.github.io
      Introduction to TurboFan
      from Axel '0vercl0k' Souchet
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.