GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by buherator (buherator@infosec.place)

  1. Embed this notice
    buherator (buherator@infosec.place)'s status on Monday, 22-Sep-2025 05:31:16 JST buherator buherator
    in reply to
    • Paul Cantrell
    • Tim Bray
    @inthehands @timbray my first thought too, but if electron is compromised obsidian would not be among our primary concerns (esp. because according to this policy they would likely not update before the incident is noticed). So I think electron is more of an attack surface problem than a supply chain one.
    In conversation about 2 months ago from infosec.place permalink
  2. Embed this notice
    buherator (buherator@infosec.place)'s status on Monday, 08-Sep-2025 21:33:02 JST buherator buherator
    in reply to
    • Micah Lee
    • Hans-Martin Münch
    @h0ng10 @micahflee This is a fairly common mistake too and causes a lot of bullshit work for security teams. A banner string (*especially* in case of Apache HTTPd) doesn't mean anything, so unless you can demonstrate the presence of a vulnerability this is nothing (aka PoC||GTFO).

    (edited) In addition the cited CVE-2024-38476 requires a *malicious backend* to be exploitable:

    https://devco.re/blog/2024/08/09/confusion-attacks-exploiting-hidden-semantic-ambiguity-in-apache-http-server-en/
    In conversation about 2 months ago from infosec.place permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: devco.re
      Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server! | DEVCORE 戴夫寇爾
      from d3vc0r3
      This article explores architectural issues within the Apache HTTP Server, highlighting several technical debts within Httpd, including 3 types of Confusion Attacks, 9 new vulnerabilities, 20 exploitation techniques, and over 30 case studies. The content includes, but is not limited to: 1. How a single ? can bypass Httpd's built-in access control and authentication. 2. How unsafe RewriteRules can escape the Web Root and access the entire filesystem. 3. How to leverage a piece of code from 1996 to transform an XSS into RCE.
  3. Embed this notice
    buherator (buherator@infosec.place)'s status on Tuesday, 02-Sep-2025 21:22:41 JST buherator buherator
    • Kevin Beaumont
    • Misuse Case
    @GossiTheDog @MisuseCase I mean CTXS stock
    In conversation about 2 months ago from gnusocial.jp permalink
  4. Embed this notice
    buherator (buherator@infosec.place)'s status on Tuesday, 02-Sep-2025 20:47:58 JST buherator buherator
    • Kevin Beaumont
    • Misuse Case
    @GossiTheDog @MisuseCase Neat! It'd be cool to show threats drive down product use predictably! Stocks on the other hand seem pretty stable, so I still don't know what this all tells about the market...
    In conversation about 2 months ago from gnusocial.jp permalink
  5. Embed this notice
    buherator (buherator@infosec.place)'s status on Tuesday, 02-Sep-2025 20:32:48 JST buherator buherator
    in reply to
    • Kevin Beaumont
    • Misuse Case
    @MisuseCase @GossiTheDog I also think this is the true cause of the decline, vulns probably just correlate (evidence: every other product with frequent ItW vulns)
    In conversation about 2 months ago from gnusocial.jp permalink
  6. Embed this notice
    buherator (buherator@infosec.place)'s status on Tuesday, 19-Aug-2025 11:21:16 JST buherator buherator
    Can You Write A Web Server in PURE BASH?! (no socat, no netcat, no external tools) 🍿

    https://www.youtube.com/watch?v=L967hYylZuc
    In conversation about 3 months ago from infosec.place permalink

    Attachments

    1. Can You Write A Web Server in PURE BASH?! (no socat, no netcat, no external tools)
      from You Suck at Programming
      Support me on https://patreon.com/YouSuckatProgrammingFinal code → https://github.com/bahamas10/bash-web-server- $ whoamiYo what's up everyone my name's dave...
  7. Embed this notice
    buherator (buherator@infosec.place)'s status on Friday, 01-Aug-2025 02:43:59 JST buherator buherator
    in reply to
    • Jan Schaumann
    @jschauma maybe that's why furries are overrepresented in reliable IT projects?
    In conversation about 3 months ago from infosec.place permalink
  8. Embed this notice
    buherator (buherator@infosec.place)'s status on Tuesday, 17-Jun-2025 02:51:22 JST buherator buherator
    [oss-security] CVE-2025-4748: Erlang/OTP 17.0–28.0.0 absolute-path traversal in zip:unzip/zip:extract

    https://www.openwall.com/lists/oss-security/2025/06/16/5

    Exquisite bug!
    In conversation about 5 months ago from infosec.place permalink

    Attachments


    1. https://media.infosec.place/infosec-place/58e6d9d2e2443572365c350fc73072580bfaeef31c4fd4d1359e84b736c9bdc2.gif
    2. Domain not in remote thumbnail source whitelist: www.openwall.com
      oss-security - CVE-2025-4748: Erlang/OTP 17.0–28.0.0 absolute-path traversal in zip:unzip/zip:extract
  9. Embed this notice
    buherator (buherator@infosec.place)'s status on Wednesday, 28-May-2025 21:12:33 JST buherator buherator
    [RSS] Inside GitHub: How we hardened our SAML implementation

    https://github.blog/security/web-application-security/inside-github-how-we-hardened-our-saml-implementation/
    In conversation about 5 months ago from infosec.place permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: github.blog
      Inside GitHub: How we hardened our SAML implementation
      from Greg Ose
      See how we addressed the challenges of securing our SAML implementation with this behind-the-scenes look at building trust in our systems.
  10. Embed this notice
    buherator (buherator@infosec.place)'s status on Sunday, 18-May-2025 04:59:41 JST buherator buherator
    • Devine Lu Linvega
    This could be us but you vibe coding

    https://suberic.net/~dmm/projects/mystical/README.html

    h/t @neauoire
    In conversation about 6 months ago from infosec.place permalink

    Attachments


    1. https://media.infosec.place/infosec-place/88b499a5a769f70a10ea488539bd62a110eb59fd208a78b66c06ea7bfa21028b.png
    2. Domain not in remote thumbnail source whitelist: suberic.net
      Mystical
  11. Embed this notice
    buherator (buherator@infosec.place)'s status on Thursday, 15-May-2025 04:47:07 JST buherator buherator
    • buherator
    "Are Pinky and the Brain still trying to take over the world? Because at this point I'm willing to hear them out."
    In conversation about 6 months ago from infosec.place permalink
  12. Embed this notice
    buherator (buherator@infosec.place)'s status on Thursday, 15-May-2025 04:47:04 JST buherator buherator
    Orbán’s Fidesz party proposes Russia-style crackdown on Hungary’s civil society

    https://www.politico.eu/article/viktor-orban-fidesz-party-hungary-russia-democracy-transparency-public-life-civil-society/

    The darkest times of my life in #Hungary.
    In conversation about 6 months ago from infosec.place permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.politico.eu
      Orbán’s Fidesz party proposes Russia-style crackdown on Hungary’s civil society
      The new bill fits into a pattern of democratic backsliding for the Central European country.
  13. Embed this notice
    buherator (buherator@infosec.place)'s status on Thursday, 17-Apr-2025 03:22:22 JST buherator buherator
    Unauthenticated Remote Code Execution in Erlang/OTP SSH

    https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2

    Not much details and unfortunately I don't know much Erlang (yet), but this one seems pretty interesting!

    CVE-2025-32433
    In conversation about 7 months ago from infosec.place permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      Unauthenticated Remote Code Execution in Erlang/OTP SSH
      ### Summary A serious vulnerability has been identified in the Erlang/OTP SSH server that may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SS...
  14. Embed this notice
    buherator (buherator@infosec.place)'s status on Tuesday, 08-Apr-2025 20:54:51 JST buherator buherator
    • Kevin Beaumont
    • sadarex
    @GossiTheDog @sadarex And managers at the receiving end are complicit because...?
    In conversation about 7 months ago from gnusocial.jp permalink

    Attachments


    1. https://media.infosec.place/infosec-place/c588dcf1744c8de65a0fb365d29b396b43b5444ba3b1eff1b5d308e616a3aaf7.gif
  15. Embed this notice
    buherator (buherator@infosec.place)'s status on Tuesday, 08-Apr-2025 20:54:49 JST buherator buherator
    in reply to
    • Kevin Beaumont
    • sadarex
    @sadarex @GossiTheDog Who is firing them? Is it DOGE? Can they do that?
    In conversation about 7 months ago from gnusocial.jp permalink
  16. Embed this notice
    buherator (buherator@infosec.place)'s status on Tuesday, 08-Apr-2025 19:43:34 JST buherator buherator
    in reply to
    • Kevin Beaumont
    @GossiTheDog Excuse my EU ignorance, but what authority does DOGE have over random agencies HR decisions?
    In conversation about 7 months ago from infosec.place permalink
  17. Embed this notice
    buherator (buherator@infosec.place)'s status on Tuesday, 08-Apr-2025 19:43:32 JST buherator buherator
    in reply to
    • Kevin Beaumont
    • sadarex
    @sadarex @GossiTheDog Ummm OK, so a newly created dept can take away money from DHS bypassing congress/senate/president? And this is constitutional? o.O
    In conversation about 7 months ago from infosec.place permalink
  18. Embed this notice
    buherator (buherator@infosec.place)'s status on Sunday, 06-Apr-2025 03:51:07 JST buherator buherator
    • Vee
    @VeroniqueB99
    In conversation about 7 months ago from infosec.place permalink

    Attachments


    1. https://media.infosec.place/infosec-place/329c741f726233f2b077f00ea35f455e3c6800d01f70daaa0438f6e421b2a226.jpg
  19. Embed this notice
    buherator (buherator@infosec.place)'s status on Friday, 04-Apr-2025 01:25:40 JST buherator buherator
    in reply to
    • cR0w 🦃
    @cR0w How can this company still exist?
    In conversation about 7 months ago from infosec.place permalink
  20. Embed this notice
    buherator (buherator@infosec.place)'s status on Friday, 04-Apr-2025 01:25:38 JST buherator buherator
    in reply to
    • Taggart
    • cR0w 🦃
    @mttaggart @cR0w I don't want unicorns, I just would like to see that shitty security QA has consequences on the market, regardless of technology.
    In conversation about 7 months ago from infosec.place permalink
  • Before

User actions

    buherator

    buherator

    A drunken debugger

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          105742
          Member since
          9 Mar 2023
          Notices
          58
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.