Posts
2509
Following
650
Followers
1469
"I'm interested in all kinds of astronomy."
@ryanc I was actually thinking whether some (not so) fancy crypto could be used to pass some instead of a bool that the attacker can't forge, then realized reverse proxy configs are not exactly designed to implement such transformations in the first place :)

Nonetheless, this is an illustrative example that unless we point to some robust solution ppl *will* come up with complex but insecure solutions (see also Schneier's Law).
2
0
0
repeated
Edited 6 months ago

bring back forums

you aren't supposed to have a single identity online

communities shouldn't demand you let a vc-funded company have your mobile phone number

you don't have to pay $100/yr [or whatever it is] for features that every forum had for years, or if it didn't it's for a reason

your group of friends or multiple-thousand-people community won't disappear because of the failure of the aforementioned vc-funded company

even if the group dissolves you will still be able to find the useful tips you used to share

4
5
0
@krypt3ia @Viss They already are, controlling us from the shadows
0
0
1
The more I move to a thin-client model with my workstation (with projects/services moving to VM's) the more I see my dark future as an Emacs user.

TRAMP mode is pretty cool :/
0
0
0
@joxean I bet >10% of tourists have the exact same reasoning.
1
0
1
repeated

As a reminder, I'm uploading hundreds (yes) of Flash games unavailable until now to the internet archive:

https://archive.org/details/@touloutoumou

2
2
0
repeated

Analysis of a Flaw in Microsoft's Patch for "copy2pwn" (CVE-2024-38213)
https://blog.0patch.com/2025/02/analysis-of-flaw-in-microsofts-patch.html

1
3
1
I'm still looking for that brain activity sensor that someone used to make a propeller hat that spins faster when you think harder.
1
0
4
Re: CVE-2025-0108

Can we agree that "X-Trust-Me-Bro: $boolean" headers set by reverse proxies are an anti-pattern?

If so, what is the best practice?
1
1
6
repeated

Microsoft: So you've disabled the advertisements for Microsoft products we put on the lock screen.

Me: Yes

Microsoft: And you've disabled the weather widget in the start bar.

Me: Yes.

Microsoft: So you don't want notices on the start screen OR weather.

Me: Correct

Microsoft: Well good news this is start screen AND weather. You never said you didn't want them TOGETHER.

Me: Can I disable it

Microsoft: Sure, if you can solve this Rubik's cube

6
3
0
[RSS] Nginx/Apache Path Confusion to Auth Bypass in PAN-OS (CVE-2025-0108)

https://www.assetnote.io/resources/research/nginx-apache-path-confusion-to-auth-bypass-in-pan-os

Full analysis
0
2
3
Congrats to the IOActive marketing team for moving their blog to a platform with no RSS :P
0
1
5
[RSS] The Key to COMpromise - Downloading a SYSTEM shell, Part 3

https://neodyme.io/en/blog/com_hijacking_3/
0
0
1
repeated

I don't understand how Windows 10 is discontinued yet Microsoft still finds ways to add new types of advertisements to it

6
2
0
@cR0w @silverwizard PR has to show their worth, I'm pretty sure this wasn't composed by the offensive team
0
0
2
@silverwizard @cR0w To be fair, they could've pushed a silent patch...
0
0
2
@schrotthaufen That would mean there is an unrelated problem in the signing process that would deserve a separate CVE/advisory.
1
0
0
Show older