GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by buherator (buherator@infosec.place)

  1. Embed this notice
    buherator (buherator@infosec.place)'s status on Sunday, 18-May-2025 04:59:41 JST buherator buherator
    • Devine Lu Linvega
    This could be us but you vibe coding

    https://suberic.net/~dmm/projects/mystical/README.html

    h/t @neauoire
    In conversation about 8 days ago from infosec.place permalink

    Attachments


    1. https://media.infosec.place/infosec-place/88b499a5a769f70a10ea488539bd62a110eb59fd208a78b66c06ea7bfa21028b.png
    2. Domain not in remote thumbnail source whitelist: suberic.net
      Mystical
  2. Embed this notice
    buherator (buherator@infosec.place)'s status on Thursday, 15-May-2025 04:47:07 JST buherator buherator
    • buherator
    "Are Pinky and the Brain still trying to take over the world? Because at this point I'm willing to hear them out."
    In conversation about 11 days ago from infosec.place permalink
  3. Embed this notice
    buherator (buherator@infosec.place)'s status on Thursday, 15-May-2025 04:47:04 JST buherator buherator
    Orbán’s Fidesz party proposes Russia-style crackdown on Hungary’s civil society

    https://www.politico.eu/article/viktor-orban-fidesz-party-hungary-russia-democracy-transparency-public-life-civil-society/

    The darkest times of my life in #Hungary.
    In conversation about 11 days ago from infosec.place permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.politico.eu
      Orbán’s Fidesz party proposes Russia-style crackdown on Hungary’s civil society
      The new bill fits into a pattern of democratic backsliding for the Central European country.
  4. Embed this notice
    buherator (buherator@infosec.place)'s status on Thursday, 17-Apr-2025 03:22:22 JST buherator buherator
    Unauthenticated Remote Code Execution in Erlang/OTP SSH

    https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2

    Not much details and unfortunately I don't know much Erlang (yet), but this one seems pretty interesting!

    CVE-2025-32433
    In conversation about a month ago from infosec.place permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      Unauthenticated Remote Code Execution in Erlang/OTP SSH
      ### Summary A serious vulnerability has been identified in the Erlang/OTP SSH server that may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SS...
  5. Embed this notice
    buherator (buherator@infosec.place)'s status on Tuesday, 08-Apr-2025 20:54:51 JST buherator buherator
    • Kevin Beaumont
    • sadarex
    @GossiTheDog @sadarex And managers at the receiving end are complicit because...?
    In conversation about 2 months ago from gnusocial.jp permalink

    Attachments


    1. https://media.infosec.place/infosec-place/c588dcf1744c8de65a0fb365d29b396b43b5444ba3b1eff1b5d308e616a3aaf7.gif
  6. Embed this notice
    buherator (buherator@infosec.place)'s status on Tuesday, 08-Apr-2025 20:54:49 JST buherator buherator
    in reply to
    • Kevin Beaumont
    • sadarex
    @sadarex @GossiTheDog Who is firing them? Is it DOGE? Can they do that?
    In conversation about 2 months ago from gnusocial.jp permalink
  7. Embed this notice
    buherator (buherator@infosec.place)'s status on Tuesday, 08-Apr-2025 19:43:34 JST buherator buherator
    in reply to
    • Kevin Beaumont
    @GossiTheDog Excuse my EU ignorance, but what authority does DOGE have over random agencies HR decisions?
    In conversation about 2 months ago from infosec.place permalink
  8. Embed this notice
    buherator (buherator@infosec.place)'s status on Tuesday, 08-Apr-2025 19:43:32 JST buherator buherator
    in reply to
    • Kevin Beaumont
    • sadarex
    @sadarex @GossiTheDog Ummm OK, so a newly created dept can take away money from DHS bypassing congress/senate/president? And this is constitutional? o.O
    In conversation about 2 months ago from infosec.place permalink
  9. Embed this notice
    buherator (buherator@infosec.place)'s status on Sunday, 06-Apr-2025 03:51:07 JST buherator buherator
    • Vee
    @VeroniqueB99
    In conversation about 2 months ago from infosec.place permalink

    Attachments


    1. https://media.infosec.place/infosec-place/329c741f726233f2b077f00ea35f455e3c6800d01f70daaa0438f6e421b2a226.jpg
  10. Embed this notice
    buherator (buherator@infosec.place)'s status on Friday, 04-Apr-2025 01:25:40 JST buherator buherator
    in reply to
    • cR0w :cascadia:
    @cR0w How can this company still exist?
    In conversation about 2 months ago from infosec.place permalink
  11. Embed this notice
    buherator (buherator@infosec.place)'s status on Friday, 04-Apr-2025 01:25:38 JST buherator buherator
    in reply to
    • Taggart :donor:
    • cR0w :cascadia:
    @mttaggart @cR0w I don't want unicorns, I just would like to see that shitty security QA has consequences on the market, regardless of technology.
    In conversation about 2 months ago from infosec.place permalink
  12. Embed this notice
    buherator (buherator@infosec.place)'s status on Wednesday, 02-Apr-2025 04:17:57 JST buherator buherator
    • Kevin Beaumont
    • CISA KEV Tracker
    @GossiTheDog @cisakevtracker Thanks for the heads up! I'm quite skeptical though given the previous FUD reports, can't wait to see more info about any observed attacks!
    In conversation about 2 months ago from gnusocial.jp permalink
  13. Embed this notice
    buherator (buherator@infosec.place)'s status on Wednesday, 02-Apr-2025 03:02:11 JST buherator buherator
    in reply to
    • cR0w :cascadia:
    • Will Dormann
    @wdormann @cR0w Reminds me of: https://project-zero.issues.chromium.org/issues/42452353#comment2
    In conversation about 2 months ago from infosec.place permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Project Zero
  14. Embed this notice
    buherator (buherator@infosec.place)'s status on Wednesday, 02-Apr-2025 03:02:09 JST buherator buherator
    in reply to
    • cR0w :cascadia:
    • Will Dormann
    @cR0w @wdormann Probably? Gmail definitely does that. Zero-click attack surface ftw!
    In conversation about 2 months ago from infosec.place permalink
  15. Embed this notice
    buherator (buherator@infosec.place)'s status on Saturday, 29-Mar-2025 08:19:54 JST buherator buherator
    in reply to
    • Paul Cantrell
    @inthehands "Safely rewriting that code would take years" is a massive understatement from Wired too.
    In conversation about 2 months ago from infosec.place permalink
  16. Embed this notice
    buherator (buherator@infosec.place)'s status on Thursday, 20-Mar-2025 00:05:22 JST buherator buherator
    in reply to
    • Caitlin Condon
    @catc0n If by single source you mean Wallarm, that one is factually incorrect at multiple points so IMO it's best to dismiss as FUD:

    https://infosec.place/notice/As2Q4VaBioZNySoR6m
    In conversation about 2 months ago from infosec.place permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.infosec.place
      buherator (@buherator@infosec.place)
      This "analysis" by Wallarm - claiming active exploitation of CVE-2025-24813 Tomcat RCE - is wrong in multiple ways (maybe LLM slop?): https://web.archive.org/web/20250314071219/https://lab.wallarm...
  17. Embed this notice
    buherator (buherator@infosec.place)'s status on Friday, 14-Feb-2025 01:09:29 JST buherator buherator
    in reply to
    • Ryan Castellucci :nonbinary_flag:
    @ryanc X-Trust-Me-Bro: {"alg":"nOnE"...} vulns would be pretty funny actually :) let's hope we'll never get there though...
    In conversation about 3 months ago from gnusocial.jp permalink
  18. Embed this notice
    buherator (buherator@infosec.place)'s status on Friday, 14-Feb-2025 00:31:53 JST buherator buherator
    in reply to
    • Ryan Castellucci :nonbinary_flag:
    @ryanc I was actually thinking whether some (not so) fancy crypto could be used to pass some instead of a bool that the attacker can't forge, then realized reverse proxy configs are not exactly designed to implement such transformations in the first place :)

    Nonetheless, this is an illustrative example that unless we point to some robust solution ppl *will* come up with complex but insecure solutions (see also Schneier's Law).
    In conversation about 3 months ago from gnusocial.jp permalink
  19. Embed this notice
    buherator (buherator@infosec.place)'s status on Thursday, 13-Feb-2025 23:40:53 JST buherator buherator
    Re: CVE-2025-0108

    Can we agree that "X-Trust-Me-Bro: $boolean" headers set by reverse proxies are an anti-pattern?

    If so, what is the best practice?
    In conversation about 3 months ago from infosec.place permalink
  20. Embed this notice
    buherator (buherator@infosec.place)'s status on Thursday, 13-Feb-2025 04:44:32 JST buherator buherator
    in reply to
    • silverwizard
    • cR0w :cascadia:
    @cR0w @silverwizard PR has to show their worth, I'm pretty sure this wasn't composed by the offensive team
    In conversation about 3 months ago from infosec.place permalink
  • Before

User actions

    buherator

    buherator

    A drunken debugger

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          105742
          Member since
          9 Mar 2023
          Notices
          49
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.