Posts
2425
Following
592
Followers
1314
"I'm interested in all kinds of astronomy."
@da_667 I'm a fan of static site generators. Jekyll is an obvious option but Ruby is guaranteed Dependency Hell in the long run (I remember some fuckery even with Docker...). Hugo seems similar without the mess but I don't have experience with that one.
0
0
1
repeated

One the twelfth day of Christmas, the true goat gave to thee: https://infosec.press/screaminggoat/patch-tuesday , which is a list of vendors' security advisory landing pages and their schedule.

Disclaimer: Not every vendor is listed, and their patching cycle may be different than what I categorized them as, but it's a good starting point. Ideally, you'd be tracking the ones you care about using RSS anyway.

Merry Christmas Infosec Mastodon

3
7
0
@teotwaki @DerFetzer thanks, I'm quite picky about such things anyway :) I'm more puzzled about the knobs&dials one has to be familiar with to do things properly.
0
0
1
[RSS] A design flaw in the Windows 3D Pipes screen saver pointed out by a customer

https://devblogs.microsoft.com/oldnewthing/20241224-00/?p=110675
0
0
1
@DerFetzer Thank you, thiserror is actually part of the material I'm working on, but comparing alternatives has been on my TODO list!
1
0
1
[RSS] An Initial Analysis of Adobe ColdFusion CVE-2024-53961

https://www.hoyahaxa.com/2024/12/an-initial-analysis-of-cve-2024-53961.html
0
2
0
[RSS] ghidralib - A Pythonic Ghidra standard library

https://github.com/msm-code/ghidralib

#Ghidra
0
1
3
[RSS] A functionally complete decompilation of LEGO Island (1997)

https://github.com/isledecomp/isle
0
0
1
[RSS] Starship, Star Fox 64 recompilation project

https://github.com/HarbourMasters/Starship
0
0
0
OK, this is my summary for today

#Rust
1
1
9
repeated

Hewlett Packard report that they are spotting AI-generated malware in the wild, not through complex analysis or watermarking, but because
 it is weirdly well-commented. https://threatresearch.ext.hp.com/wp-content/uploads/2024/09/HP_Wolf_Security_Threat_Insights_Report_September_2024.pdf

2
10
0
I'm at about third of the 100 #Rust exercises and I think we just got to the "Draw the rest of the fucking owl" part 🖊
0
1
13
I find CVE-2024-40896 (Raptor/libxml2 XXE) very educational:

Based on the analysis[1] it's a nice example of Chesterton’s Fence[2], while its discovery[3] underlines the importance of automated testing for regressions and known dangerous behavior.

[1] https://www.openwall.com/lists/oss-security/2024/12/25/2 (thx @alexandreborges for sharing!)
[2] https://fs.blog/chestertons-fence/
[3] https://gitlab.gnome.org/GNOME/libxml2/-/issues/761
0
2
5
repeated
repeated

7/ Finland has visually confirmed that the ship Eagle S had it's anchor down and is now missing it's anchor.

1
1
0
repeated

6/ Finnish Police have boarded the Eagle S oil tanker and a 3km no-fly zone has been announced in the area.

Finland suspects that the oil tanker caused the damage to the Estlink 2 cable and other cables.

https://yle.fi/a/74-20133526

1
4
0
repeated

3/ Finnish police said on Thursday they are investigating whether a foreign ship was involved in the damage of an undersea power cable connecting and following a sudden outage on Wednesday.

https://www.reuters.com/world/europe/finland-police-investigate-role-foreign-ship-after-power-cable-outage-2024-12-26/

1
2
0
Show older