GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by buherator (buherator@infosec.place)

  1. Embed this notice
    buherator (buherator@infosec.place)'s status on Wednesday, 28-May-2025 21:12:33 JST buherator buherator
    [RSS] Inside GitHub: How we hardened our SAML implementation

    https://github.blog/security/web-application-security/inside-github-how-we-hardened-our-saml-implementation/
    In conversation about 19 days ago from infosec.place permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: github.blog
      Inside GitHub: How we hardened our SAML implementation
      from Greg Ose
      See how we addressed the challenges of securing our SAML implementation with this behind-the-scenes look at building trust in our systems.
  2. Embed this notice
    buherator (buherator@infosec.place)'s status on Sunday, 18-May-2025 04:59:41 JST buherator buherator
    • Devine Lu Linvega
    This could be us but you vibe coding

    https://suberic.net/~dmm/projects/mystical/README.html

    h/t @neauoire
    In conversation about a month ago from infosec.place permalink

    Attachments


    1. https://media.infosec.place/infosec-place/88b499a5a769f70a10ea488539bd62a110eb59fd208a78b66c06ea7bfa21028b.png
    2. Domain not in remote thumbnail source whitelist: suberic.net
      Mystical
  3. Embed this notice
    buherator (buherator@infosec.place)'s status on Thursday, 15-May-2025 04:47:07 JST buherator buherator
    • buherator
    "Are Pinky and the Brain still trying to take over the world? Because at this point I'm willing to hear them out."
    In conversation about a month ago from infosec.place permalink
  4. Embed this notice
    buherator (buherator@infosec.place)'s status on Thursday, 15-May-2025 04:47:04 JST buherator buherator
    Orbán’s Fidesz party proposes Russia-style crackdown on Hungary’s civil society

    https://www.politico.eu/article/viktor-orban-fidesz-party-hungary-russia-democracy-transparency-public-life-civil-society/

    The darkest times of my life in #Hungary.
    In conversation about a month ago from infosec.place permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.politico.eu
      Orbán’s Fidesz party proposes Russia-style crackdown on Hungary’s civil society
      The new bill fits into a pattern of democratic backsliding for the Central European country.
  5. Embed this notice
    buherator (buherator@infosec.place)'s status on Thursday, 17-Apr-2025 03:22:22 JST buherator buherator
    Unauthenticated Remote Code Execution in Erlang/OTP SSH

    https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2

    Not much details and unfortunately I don't know much Erlang (yet), but this one seems pretty interesting!

    CVE-2025-32433
    In conversation about 2 months ago from infosec.place permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      Unauthenticated Remote Code Execution in Erlang/OTP SSH
      ### Summary A serious vulnerability has been identified in the Erlang/OTP SSH server that may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SS...
  6. Embed this notice
    buherator (buherator@infosec.place)'s status on Tuesday, 08-Apr-2025 20:54:51 JST buherator buherator
    • Kevin Beaumont
    • sadarex
    @GossiTheDog @sadarex And managers at the receiving end are complicit because...?
    In conversation about 2 months ago from gnusocial.jp permalink

    Attachments


    1. https://media.infosec.place/infosec-place/c588dcf1744c8de65a0fb365d29b396b43b5444ba3b1eff1b5d308e616a3aaf7.gif
  7. Embed this notice
    buherator (buherator@infosec.place)'s status on Tuesday, 08-Apr-2025 20:54:49 JST buherator buherator
    in reply to
    • Kevin Beaumont
    • sadarex
    @sadarex @GossiTheDog Who is firing them? Is it DOGE? Can they do that?
    In conversation about 2 months ago from gnusocial.jp permalink
  8. Embed this notice
    buherator (buherator@infosec.place)'s status on Tuesday, 08-Apr-2025 19:43:34 JST buherator buherator
    in reply to
    • Kevin Beaumont
    @GossiTheDog Excuse my EU ignorance, but what authority does DOGE have over random agencies HR decisions?
    In conversation about 2 months ago from infosec.place permalink
  9. Embed this notice
    buherator (buherator@infosec.place)'s status on Tuesday, 08-Apr-2025 19:43:32 JST buherator buherator
    in reply to
    • Kevin Beaumont
    • sadarex
    @sadarex @GossiTheDog Ummm OK, so a newly created dept can take away money from DHS bypassing congress/senate/president? And this is constitutional? o.O
    In conversation about 2 months ago from infosec.place permalink
  10. Embed this notice
    buherator (buherator@infosec.place)'s status on Sunday, 06-Apr-2025 03:51:07 JST buherator buherator
    • Vee
    @VeroniqueB99
    In conversation about 2 months ago from infosec.place permalink

    Attachments


    1. https://media.infosec.place/infosec-place/329c741f726233f2b077f00ea35f455e3c6800d01f70daaa0438f6e421b2a226.jpg
  11. Embed this notice
    buherator (buherator@infosec.place)'s status on Friday, 04-Apr-2025 01:25:40 JST buherator buherator
    in reply to
    • cR0w :cascadia:
    @cR0w How can this company still exist?
    In conversation about 2 months ago from infosec.place permalink
  12. Embed this notice
    buherator (buherator@infosec.place)'s status on Friday, 04-Apr-2025 01:25:38 JST buherator buherator
    in reply to
    • Taggart :donor:
    • cR0w :cascadia:
    @mttaggart @cR0w I don't want unicorns, I just would like to see that shitty security QA has consequences on the market, regardless of technology.
    In conversation about 2 months ago from infosec.place permalink
  13. Embed this notice
    buherator (buherator@infosec.place)'s status on Wednesday, 02-Apr-2025 04:17:57 JST buherator buherator
    • Kevin Beaumont
    • CISA KEV Tracker
    @GossiTheDog @cisakevtracker Thanks for the heads up! I'm quite skeptical though given the previous FUD reports, can't wait to see more info about any observed attacks!
    In conversation about 3 months ago from gnusocial.jp permalink
  14. Embed this notice
    buherator (buherator@infosec.place)'s status on Wednesday, 02-Apr-2025 03:02:11 JST buherator buherator
    in reply to
    • cR0w :cascadia:
    • Will Dormann
    @wdormann @cR0w Reminds me of: https://project-zero.issues.chromium.org/issues/42452353#comment2
    In conversation about 3 months ago from infosec.place permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Project Zero
  15. Embed this notice
    buherator (buherator@infosec.place)'s status on Wednesday, 02-Apr-2025 03:02:09 JST buherator buherator
    in reply to
    • cR0w :cascadia:
    • Will Dormann
    @cR0w @wdormann Probably? Gmail definitely does that. Zero-click attack surface ftw!
    In conversation about 3 months ago from infosec.place permalink
  16. Embed this notice
    buherator (buherator@infosec.place)'s status on Saturday, 29-Mar-2025 08:19:54 JST buherator buherator
    in reply to
    • Paul Cantrell
    @inthehands "Safely rewriting that code would take years" is a massive understatement from Wired too.
    In conversation about 3 months ago from infosec.place permalink
  17. Embed this notice
    buherator (buherator@infosec.place)'s status on Thursday, 20-Mar-2025 00:05:22 JST buherator buherator
    in reply to
    • Caitlin Condon
    @catc0n If by single source you mean Wallarm, that one is factually incorrect at multiple points so IMO it's best to dismiss as FUD:

    https://infosec.place/notice/As2Q4VaBioZNySoR6m
    In conversation about 3 months ago from infosec.place permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.infosec.place
      buherator (@buherator@infosec.place)
      This "analysis" by Wallarm - claiming active exploitation of CVE-2025-24813 Tomcat RCE - is wrong in multiple ways (maybe LLM slop?): https://web.archive.org/web/20250314071219/https://lab.wallarm...
  18. Embed this notice
    buherator (buherator@infosec.place)'s status on Friday, 14-Feb-2025 01:09:29 JST buherator buherator
    in reply to
    • Ryan Castellucci :nonbinary_flag:
    @ryanc X-Trust-Me-Bro: {"alg":"nOnE"...} vulns would be pretty funny actually :) let's hope we'll never get there though...
    In conversation about 4 months ago from gnusocial.jp permalink
  19. Embed this notice
    buherator (buherator@infosec.place)'s status on Friday, 14-Feb-2025 00:31:53 JST buherator buherator
    in reply to
    • Ryan Castellucci :nonbinary_flag:
    @ryanc I was actually thinking whether some (not so) fancy crypto could be used to pass some instead of a bool that the attacker can't forge, then realized reverse proxy configs are not exactly designed to implement such transformations in the first place :)

    Nonetheless, this is an illustrative example that unless we point to some robust solution ppl *will* come up with complex but insecure solutions (see also Schneier's Law).
    In conversation about 4 months ago from gnusocial.jp permalink
  20. Embed this notice
    buherator (buherator@infosec.place)'s status on Thursday, 13-Feb-2025 23:40:53 JST buherator buherator
    Re: CVE-2025-0108

    Can we agree that "X-Trust-Me-Bro: $boolean" headers set by reverse proxies are an anti-pattern?

    If so, what is the best practice?
    In conversation about 4 months ago from infosec.place permalink
  • Before

User actions

    buherator

    buherator

    A drunken debugger

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          105742
          Member since
          9 Mar 2023
          Notices
          50
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.