Posts
2734
Following
681
Followers
1505
"I'm interested in all kinds of astronomy."
@bagder I'm dying to know
- what the problem was
- how did this person end up emailing you (are gasoline sensors queried with curl in Opel Astra??)
1
0
2
repeated

@buherator No, fel is huztam! Rogton 3 cimen is, mert nem tudtam donteni.

Ha lenne hajam, akkor most csinalnek magamnak jofajta punk frizurat. flan_headbang

1
1
1
repeated

yyzkevin.ca has been working on making the first emulator to work with the odd IBM AS/400 drive standard. Here's his AS/400 booting IPL'ing with a BlueSCSI!

Still a lot to do but now even AS/400 users can have a modern, fully opensource, storage solution.

https://youtu.be/J8GztrUvox8?si=mpY88vrSCqVwUFvs&t=608

0
3
0
@algernon ...bár belegondolva (meg megnézve a kódot) ez lényegében egy elosztott cache az EMMA elé, szóval még segíthet is szegény MÁV-os szervereknek!
1
0
0
@algernon Arra célszerű vigyázni h nehogy tényleg DoS legyen belőle amikor már 100 példány fut itt-ott :)
1
0
0
As they say, Hungarian Railways have 5 enemies: the four seasons and the passengers.

This summer started off esp. bad, while official online services allowing the tracking of delays suspiciously started to disappear.

Train enthusiasts however built an unofficial website that showed accurate info about the position and delays of the trains based on scraped data.

Then the Minister of Transportation accused these guys of phishing (he pbbly doesn't know what that means), DoS and of course conspiring the opposition party, so the site was voluntarily taken down...

...but the code is open source, so now we have multiple sites with the same functionality :D

https://github.com/iben12/holavonat

#Hungary #StreisandEffect
3
7
8
repeated
Edited 4 months ago

Pre-auth RCE in CentOS Web Panel (CVE-2025-48703) found by the friends at Fenrisk. This is beyond madness that Shodan finds 200k of these exposed publicly.

(this post is sponsored by strace®, because no one cares about ionCube)

https://fenrisk.com/rce-centos-webpanel

0
3
0
repeated

Finally published today the second blog I'd promised for the 11.4.81 CBE release last month:
https://blogs.oracle.com/solaris/post/whats-new-in-the-solaris-modular-debugger-mdb-in-the-oracle-solaris-11481-cbe

A very deep dive into a narrow topic - what's changed in the Solaris Modular Debugger (mdb) since the previous CBE release in 2022. @cgerhard and others have put an impressive amount of work into making debugging easier and better for the users of this tool.

0
2
0
repeated

Hat tip to thegrugq for featuring this in his newsletter, a 1991 video of Italian hackers purporting to show them hacking a U.S. military system over x25. Has a real gonzo Max Headroom broadcast signal intrusion vibe with the masks & just general weird vibes, love it.
https://www.youtube.com/watch?v=43FyQlaA6YY

2
7
0
repeated

Dear Fedi,

For 3 years, I've been working with friends from the world as a team of freelancers and it's been great: we love what we do and our clients are happy and stay with us for years.

But the terrible state of the world has badly affected our clients financially, and we find ourselves suddenly in need of more

We focus on systems design, development, and administration. We offer SRE-level quality and processes for companies that cannot afford a whole team

Boosts welcomed

0
3
0
@FuzzyAleks life is too short for me to drink leftover coffee
0
0
0
@Canageek This is a documentary, it should be enjoyable with English subs:

https://www.youtube.com/watch?v=Z-keHkcTZD4

Also, lots of samples.
0
1
2
[RSS] You have to tell Get- and Set-Security-Info the object type, you can't make it guess

https://devblogs.microsoft.com/oldnewthing/20250618-00/?p=111281
0
0
0
The trick with making your morning coffee is that you have to manage to make your morning coffee before having your morning coffee
1
1
6
@azonenberg Afaik bottle caps are more valuable than the bottles, there are even dedicated collection campaigns for them around here
0
0
0
repeated

Misfile essential documents.

0
2
0
repeated
@InfoCon Is Off-by-One Conf on your radar already?

https://www.youtube.com/@offbyoneconf
2
0
0
repeated

Insecure defaults can lead to surprises. When creating FIFO sockets with systemd, be sure to note that SocketMode defaults to 0666 - that is world readable and writable. That is: any local user can communicate with the FIFO. If your FIFO is used to perform privileged operations you must ensure that either the FIFO file itself is located in secured location or set SocketMode to stricter value.

I spotted one such insecure use in cloud-init: the hotplug FIFO was world writable. This is CVE-2024-11584 and fixed in cloud-init 25.1.3.

The commit fixing this is in https://github.com/canonical/cloud-init/pull/6265

0
5
0
repeated
Show older