Posts
2467
Following
661
Followers
1486
"I'm interested in all kinds of astronomy."
repeated

Thinking of participating in Automotive? ZDI's Connor Ford provides a detailed look at the internals of the DMX958XR. This is the first in a series detailing the attack surface of the IVI. Read all the details (and gander at the pics) at https://www.zerodayinitiative.com/blog/2024/11/18/looking-at-the-internals-of-the-kenwood-dmx958xr-ivi

0
2
0
repeated

ZDI-24-1514|CVE-2024-11393] (0Day) Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVSS 8.8; Credit: The_Kernel_Panic) https://www.zerodayinitiative.com/advisories/ZDI-24-1514/

0
1
0
repeated

Hello! I've written 22,000+ words on "Safe" C++

https://izzys.casa/2024/11/on-safe-cxx/

7
7
0
repeated

Paged Out! is out! Enjoy!
https://pagedout.institute/
And if you like the cover, check out the 8K wallpaper by Mark Graham (downloadable on our website)!

https://bird.makeup/@pagedout_zine/1858799166505234848

0
3
0
repeated

Finally got to publish the CVE for a "forever-day" path traversal in the .NET library DotNetZip affecting all releases since 2018. Enjoy, the PoC is in the patch! blobcatsuit

https://www.cve.org/CVERecord?id=CVE-2024-48510

0
5
0
Edited 10 months ago
I try to reconstruct the design process of PAN-OS web services:
- Let's require authentication on all interfaces, because security!
- ...but we need some stuff to be accessible pre-auth 🤔
- Let's define a skeleton key that can be passed to us by another parser that have 0 concept of what needs to be authenticated!

Am I missing something?

#PaloAlto
2
0
9
[RSS] Pluralistic: Canada's ground-breaking, hamstrung repair and interop laws (15 Nov 2024)

https://pluralistic.net/2024/11/15/radical-extremists/#sex-pest
0
0
0
repeated

Boost this toot if you're planning on sticking around Mastodon whether or not it's more popular than Bluesky.

14
48
0
repeated

If only Sun Microsystems had purchased Apple when it had the chance, we could have had this magnificent device
https://alecmuffett.com/article/110670

0
2
0
repeated

Pots and Pans, AKA an SSLVPN - Palo Alto PAN-OS CVE-2024-0012 and CVE-2024-9474 - watchTowr Labs https://labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/

0
2
0
repeated

We’ve just published on the @hnsec blog the seventh article on the creation of extensions for @burp_suite "Extending Burp Suite for fun and profit - The Montoya way", by @apps3c.

Topic: using the in plugins

https://security.humanativaspa.it/extending-burp-suite-for-fun-and-profit-the-montoya-way-part-7/

1
2
0
repeated

Extending Burp Suite for fun and profit - The Montoya way - Part 7 (Using the Collaborator) https://security.humanativaspa.it/extending-burp-suite-for-fun-and-profit-the-montoya-way-part-7/

0
2
0
[RSS] Heather 'Razzlekhan' Morgan sentenced to 18 months in prison, ending Bitfinex saga

https://therecord.media/razzlekhan-bitfinex-sentenced-18-months-bitcoin-laundering

The Crocodile of Wall Street spends some time in the sewers... https://www.youtube.com/watch?v=_DIuPPmY9mw
1
0
1
repeated

This week my brain is completely stuck on wanting an Alphasmart Neo. Half of my brain knows that buying tech to write a novel with is not actually the same as writing my novel. The other half of my brain... wants the tech. But also, just look at it, isn't it perfect?

0
1
1
repeated
[RSS] Salamander/MIME - Just because it's encrypted doesn't mean it's secure | Lutra Security

https://lutrasecurity.com/en/articles/salamander-mime/
0
1
0
CVE-2024-52316: Apache Tomcat: Authentication bypass when using Jakarta Authentication API

https://seclists.org/oss-sec/2024/q4/103

Sounds pretty esoteric, but I may be wrong:

"If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail"
0
0
0
CVE-2024-52317: Apache Tomcat: Request/response mix-up with HTTP/2

https://seclists.org/oss-sec/2024/q4/104

This looks fun! /cc @albinowax
1
0
3
repeated
Edited 10 months ago

This starts to look coordinated:
"Following Finnish media reports that an unexplained failure of an undersea telecommunications cable has disrupted communication services between Finland and Germany, Telia’s Chief Technology Officer Andrius Šemeškevičius says that the communications cable between Lithuania and Sweden was also damaged." (via @ErikJonker)
https://www.lrt.lt/en/news-in-english/19/2416006/undersea-cable-between-lithuania-and-sweden-damaged-telia

1
2
0
repeated

Fixing a Bunch of Scripting Engine Vulnerabilities by Disabling Just-In-Time Compiler (CVE-2024-38178) https://blog.0patch.com/2024/11/fixing-bunch-of-scripting-engine.html

1
2
0
Show older