GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Dr. Christopher Kunz (christopherkunz@chaos.social)

  1. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Thursday, 04-Jun-2026 23:54:14 JST Dr. Christopher Kunz Dr. Christopher Kunz
    in reply to
    • Will Dormann

    @wdormann https://github.com/0xABCD01/CVE-2026-41089/blob/main/poc.py#L234

    In conversation about 4 days ago from chaos.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      CVE-2026-41089/poc.py at main · 0xABCD01/CVE-2026-41089
      CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL) - 0xABCD01/CVE-2026-41089
  2. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Thursday, 04-Jun-2026 23:54:13 JST Dr. Christopher Kunz Dr. Christopher Kunz
    in reply to
    • Will Dormann

    @wdormann https://chaos.social/@christopherkunz/116676523296824499

    In conversation about 4 days ago from chaos.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Dr. Christopher Kunz (@christopherkunz@chaos.social)
      from Dr. Christopher Kunz
      @FritzAdalis@infosec.exchange @cR0w@infosec.exchange It's a little more complicated (and I have no means to verify the purported PoC, but it looks legit-ish), but apparently you can crash LSASS by sending a CLDAP DC locator ping packet with the username being Ax130 or longer. Code execution seems possible (according to MSRC), but the PoC is just a DoS.
  3. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Thursday, 04-Jun-2026 23:54:11 JST Dr. Christopher Kunz Dr. Christopher Kunz
    in reply to
    • Will Dormann

    @wdormann This writeup *seems* to make sense, were it not for the magic two letters in the TLD: https://aretiq.ai/research/vul260513-cve-2026-41089-microsoft-windows-netlogon-buildsamlogonresponse-stack-based-buffer-overflow-rce/

    In conversation about 4 days ago from chaos.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      CVE-2026-41089 — Microsoft Windows Netlogon BuildSamLogonResponse Stack-based Buffer Overflow RCE
      from Aretiq AI
      1. Overview A stack-based buffer overflow vulnerability exists in the Windows Netlogon service’s DC locator ping response handler. When a domain controller processes a CLDAP search request, it serializes response data including attacker-supplied and server-side strings into a fixed-size stack buffer without adequate bounds checking. An unauthenticated remote attacker can send a single crafted CLDAP packet to a domain controller’s UDP port 389, causing the Netlogon service to crash the LSASS process and force the domain controller to reboot. The exploitability depends on the target domain controller’s DNS naming configuration — domain controllers with longer DNS domain names and hostnames are vulnerable. Microsoft addressed this vulnerability in the May 2026 security update.
  4. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Thursday, 04-Jun-2026 23:54:10 JST Dr. Christopher Kunz Dr. Christopher Kunz
    in reply to
    • Will Dormann

    @wdormann From what I read in the writeup (and the sparse other sources), you need a long enough DNS name on the victim host to trigger the overflow. I think 54 chars or more? This github has a possible explanation why the PoC fails under most normal conditions: https://github.com/ADScanPro/CVE-2026-41089-LongLogon

    In conversation about 4 days ago from chaos.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      GitHub - ADScanPro/CVE-2026-41089-LongLogon: CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller's domain is long enough to crash, without sending the overflow. The binary-verified analysis the public PoCs got wrong.
      CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller's domain is long enough to crash,...
  5. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Thursday, 04-Jun-2026 23:54:07 JST Dr. Christopher Kunz Dr. Christopher Kunz
    in reply to
    • Will Dormann

    @wdormann Of all the writeups, I think I like this one best, especially with it having a human name in the byline: https://adscanpro.com/blog/patch-diffing-cve-2026-41089-netlogon
    "read advisories carefully before deciding how to allocate research time." made me chuckle.

    In conversation about 4 days ago from chaos.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: adscanpro.com
      Patch Diffing CVE-2026-41089: Locating the Netlogon Bug in 4 Hours Without a Public PoC
      Walkthrough of how to bindiff a Patch Tuesday Windows CVE end-to-end — from MSU acquisition to function-level bug identification. CVE-2026-41089 (Netlogon pre-auth RCE) as the running example. Methodology, tooling, and the honest limits of trigger development without weeks of exploit engineering.
  6. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Tuesday, 02-Jun-2026 11:42:27 JST Dr. Christopher Kunz Dr. Christopher Kunz

    So CVE-2026-41089 (CVSS 9.8) in Windows Netlogon can be triggered by sending a username that is AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA or longer.
    How original.

    In conversation about 6 days ago from chaos.social permalink
  7. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Thursday, 28-May-2026 05:17:25 JST Dr. Christopher Kunz Dr. Christopher Kunz
    • daniel:// stenberg://

    I wrote a thing about curl and the woefully underfunded open source universe: https://www.heise.de/en/opinion/Comment-Open-source-developers-are-working-themselves-sick-on-AI-bugs-11308553.html
    @bagder

    In conversation about 11 days ago from chaos.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: heise.cloudimg.io
      Comment: Open-source developers are working themselves sick on AI bugs
      from heise online
      Work intensification leads to overload for developers. Companies make billions thanks to open source and give little back, argues Christopher Kunz.
  8. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Monday, 18-May-2026 22:32:44 JST Dr. Christopher Kunz Dr. Christopher Kunz
    • Metacurity
    • Kevin Beaumont

    @GossiTheDog @metacurity I like "GRACEFUL SPIDER". I think this might be their logo.
    Wait, that looks way too familiar.

    In conversation about 21 days ago from chaos.social permalink

    Attachments


    1. https://assets.chaos.social/media_attachments/files/116/595/811/734/782/266/original/6abccc2ac823982a.png
  9. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Monday, 18-May-2026 22:32:42 JST Dr. Christopher Kunz Dr. Christopher Kunz
    in reply to
    • Metacurity
    • Kevin Beaumont

    @GossiTheDog @metacurity I also lowkey like how Crowdstrike goes from "data theft and exto..." to "Contact sales".

    In conversation about 21 days ago from chaos.social permalink

    Attachments


    1. https://assets.chaos.social/media_attachments/files/116/595/820/397/626/474/original/05a29b161694cdd1.png
  10. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Friday, 15-May-2026 01:09:40 JST Dr. Christopher Kunz Dr. Christopher Kunz
    in reply to
    • Kevin Beaumont

    @GossiTheDog And then, there's this gem. Google ads for ddos.su and Cloudflare, chilling on the result page for "best stresser tool". ddos.su has been advertising on Google for over a year. I have reported the ads but have not heard back yet.
    Of course, ddos.su is behind CF. So I reported ddos.su to Cloudflare who just said "yeah that's no longer on our network". My bad, but www.ddos.su is.

    In conversation about a month ago from chaos.social permalink

    Attachments


    1. https://assets.chaos.social/media_attachments/files/116/573/782/902/159/850/original/9f9c437ca7065469.png

    2. Invalid filename.
  11. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Wednesday, 13-May-2026 00:17:34 JST Dr. Christopher Kunz Dr. Christopher Kunz

    May 11, 2026: The Red Sun still prevails.

    However, I noticed something odd. Either this is purely coincidence, or the exploit has less reliability now (?). On a freshly booted system, it works 100%, but after a couple minutes of runtime, it seems that it doesn't always win the race condition (or it takes longer than the usual ~10 seconds).

    In conversation about a month ago from chaos.social permalink
  12. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Wednesday, 13-May-2026 00:17:29 JST Dr. Christopher Kunz Dr. Christopher Kunz
    in reply to
    • Will Dormann
    • Jan Hendrik

    @wdormann @jhr77 Huh, that's odd. Works fine for me. Same definitions version.

    In conversation about a month ago from chaos.social permalink

    Attachments


    1. https://assets.chaos.social/media_attachments/files/116/562/259/860/271/917/original/6f7da661bb4a5b9a.png
  13. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Friday, 17-Apr-2026 04:44:11 JST Dr. Christopher Kunz Dr. Christopher Kunz

    RE: https://hachyderm.io/@dalias/116411631853678642

    "Does need a few allowlist exceptions for known broken senders, most notably Microsoft."
    Does it? :->

    In conversation about 2 months ago from chaos.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Cassandrich (@dalias@hachyderm.io)
      from Cassandrich
      Spam defense tip for folks self-hosting email: the #1 performing rule I have (accounts for ~75% of blocked messages) is rejecting forged EHLO hostname. That is, client greeting us with EHLO followed by a hostname that does not resolve to the IP address they're sending from. It's dead simple but super effective. Does need a few allowlist exceptions for known broken senders, most notably Microsoft.
  14. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Tuesday, 24-Mar-2026 03:09:03 JST Dr. Christopher Kunz Dr. Christopher Kunz
    • Kevin Beaumont

    OK, I said it first: CitrixBleed3 incoming. @GossiTheDog

    In conversation about 3 months ago from chaos.social permalink
  15. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Thursday, 12-Feb-2026 01:32:56 JST Dr. Christopher Kunz Dr. Christopher Kunz

    So #OpenAI wants to introduce an "adult mode" to ChatGPT so people who are fed up with the boring AI porn over at Grok have more choice.

    And their product policy team pushed back, citing that this would likely be detrimental to users' well-being.

    Being the balanced, well-hinged company they are, OpenAI then proceed to fire the head of said product team, citing sexual discrimination against a male colleague. And proceeds to tout "adult mode".

    Whew.

    In conversation about 4 months ago from chaos.social permalink
  16. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Monday, 09-Feb-2026 22:19:49 JST Dr. Christopher Kunz Dr. Christopher Kunz

    RE: https://fosstodon.org/@yschaeff/116034101861476409

    After "banana for scale" now the new gamechanger use-case: banana for exfil. 😆

    In conversation about 4 months ago from chaos.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cdn.fosstodon.org
      yschaeff (@yschaeff@fosstodon.org)
      from yschaeff
      Attached: 2 images You where all thinking it. And the answer is 'yes!'. Yes you can totally LASER engrave a banana to exfiltrate data from your secured premises. Just out of the machine the text is barely noticable. But the next morning? Clear as day.
  17. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Tuesday, 27-Jan-2026 18:30:20 JST Dr. Christopher Kunz Dr. Christopher Kunz
    • Manawyrm | Sarah
    • Ryan Castellucci (they/them) :nonbinary_flag:
    • mkj

    @mkj @manawyrm @ryanc Mobile phone number address spaces are surprisingly variable, especially in Austria. There are in excess of 500 billion possible phone numbers in Austria alone. This table might be useful for an estimate. (UK's not in it), but a couple dozen billion across all those countries seems like a good enough ballpark.
    Source: https://arxiv.org/pdf/2511.20252

    In conversation about 4 months ago from chaos.social permalink

    Attachments


    1. https://assets.chaos.social/media_attachments/files/115/966/333/053/687/478/original/5ae6ac5a2000ef16.png

  18. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Monday, 26-Jan-2026 19:49:53 JST Dr. Christopher Kunz Dr. Christopher Kunz
    • Kevin Beaumont

    @GossiTheDog They are snorting pulverized DRAM.

    In conversation about 4 months ago from chaos.social permalink
  19. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Tuesday, 13-Jan-2026 21:42:38 JST Dr. Christopher Kunz Dr. Christopher Kunz

    I'm looking for someone who has received one of the ominous unsolicited Instagram password reset e-mails around December 30, last year. I'd like to cross-check their Instagram data with the recent "leak". Appreciate a boost!

    In conversation about 5 months ago from chaos.social permalink
  20. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Sunday, 28-Dec-2025 17:02:08 JST Dr. Christopher Kunz Dr. Christopher Kunz
    in reply to
    • Ryan Castellucci (they/them) :nonbinary_flag:

    @ryanc Oh, so that was you! I think I saw you yesterday.

    In conversation about 5 months ago from chaos.social permalink
  • Before

User actions

    Dr. Christopher Kunz

    Dr. Christopher Kunz

    Security (web, infra, app) nerd, has accepted that VR will never be a mass market, writer @heise Security
All toots are IMHO & not my employer's opinion. PGP fingerprint: C882 8ED1 7DD1 9011 C088  EA50 5CFA 2EEB 397A CAC1

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          230467
          Member since
          8 Jan 2024
          Notices
          78
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.