Not related to the latest MongoDB vulnerability (since it doesn't require authentication), but does anyone know of a good MongoDB honeypot? You know, one that masquerades as a real MongoDB database server and logs the login attempts while returning a "bad credentials" error? (It clearly won't be able to log the passwords because of SCRAM but anything else would be useful.)
All I could find was a logging proxy to a real MongoDB server or a MongoDB server running in a Docker image - but I don't want that.
Hey #39c3, Come see my lightning talk on a safe variant for `.innerHTML ` that is built right into the browser. https://events.ccc.de/congress/2025/hub/event/detail/lightning-talks-tag-2 on Day 2.
Ah Saturday morning! What a great time to...
...write a 1-page article for Paged Out! zine!
Deadline is 4th Jan - just a week away.
The documentation for this image processing library by @vruba is one of the most interesting things I've read in weeks:
https://github.com/celoyd/potato/blob/main/docs/personal.md
https://github.com/celoyd/potato/blob/main/README.md
https://github.com/celoyd/potato/blob/main/docs/concepts.md
Philosophical discussion of the nature of seeing and what am image is vs a map, fascinating technical details about how satellite imaging works and why it looks as bad as it often does, a lot of really thoughtful conversation about engineering and aesthetic process, and even an amusing unit of measurement β grams per terrapixel.
Oh. yay.
"mongobleed" β https://github.com/joe-desimone/mongobleed/blob/main/mongobleed.py
CVE-2025-14847
"Exploits zlib decompression bug to leak server memory via BSON field names.β
"Technique: Craft BSON with inflated doc_len, server reads field names from leaked memory until null byte.β
"What if Bitcoin was one big mining company?":
https://no01.substack.com/p/what-if-bitcoin-was-one-big-mining
You'd be insane buying its shares.
Do you or somebody you know have a Windows 10 that isn't fit for a Windows 11 upgrade? (e.g. no TPM)
setup /product serverEnjoy your Windows 11 with no coerced Microsoft Account, TPM features, etc.