Original post on infosec.exchange
Interesting talk from 39c3: https://gpg.fail including my favourite classes of issues ANSI escape spoofing and abusing CR. A response from GnuPG is here https://www.gnupg.org/blog/20251226-cleartext-signatures.html โ although thereโs some other issues that do seem more fixable. IMO better to use [โฆ]
27.12.2025 21:05 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
UNIX - v4
Here's a copy of the filesystem that has been extracted as a .tar file: http://squoze.net/UNIX/v4/
20.12.2025 01:56 โ ๐ 2 ๐ 16 ๐ฌ 1 ๐ 0
Original post on infosec.exchange
@bagder maybe you could offer a fakecurl alternative for other platforms for people who really want it?
Works anywhere with Docker:
$ fakecurl() { docker run mcr.microsoft.com/dotnet/sdk:9.0 pwsh -CommandWithArgs "Invoke-WebRequest $@" }
$ fakecurl invoke-webrequest.haxx.se
StatusCode : 200 [โฆ]
09.12.2025 22:57 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
A screenshot of a shell (on Mac) executing the program รh. Due to normalization this gets translated to ssh, and indeed the shell calls the ssh binary.
Unicode normalization.
26.11.2025 22:03 โ ๐ 33 ๐ 33 ๐ฌ 4 ๐ 0
zstd (Zstandard) content-encoding | Can I use... Support tables for HTML5, CSS3, etc
Can I use has a strange entry for Zstandard on Safari (https://caniuse.com/zstd). I canโt find many references for it but indeed, if you serve Zstd to Safari >= 26 it does work. There doesnโt even seem to be a feature flag to turn on sending it in the Accept-Encoding header.
09.12.2025 06:26 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Iโm experimenting with @bsky.brid.gy so this account is now bridged to Bluesky as @dgl.cx โ there was a previous Bluesky account which that replaces (it now shows as โinvalid handleโ) and Bluesky doesnโt have a a Mastodon like way of migrating followers, so you will need to refollow.
06.12.2025 21:30 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
@whitequark feels like it needs a "Unwarranted chumminess with compiler." comment like Henry Spencer put in the original regexp code (1986) and which has been carried into various other versions (including perl) sinceโฆ
06.12.2025 01:49 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Original post on infosec.exchange
Gcore.com are an interesting provider. It took two separate support tickets over a month to work out their docs are wrong. If anyone is using them, *some* API endpoints need the authentication token to be in mixed case, for example "Authorization: APIKey ..." which is against what their [โฆ]
23.11.2025 09:20 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Original post on infosec.exchange
@webmink the hardest hurdle is that CDNs primary purpose isnโt actually the content part anymore, but pushing DDoS mitigation as close to the edge as possible. That interacts poorly with HTTPS everywhere, as every node ideally needs the certs, meaning there isnโt an easy way to federate trust. I [โฆ]
18.11.2025 12:55 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Original post on infosec.exchange
If you have a bash command line of "exec program ..." and you can control the "..." can you make it not run the exec and do something different? The answer is yes. Even if "..." is somewhat sanitised for shell metacharacters. If you can inject $+] it will make bash error on that line and run the [โฆ]
07.10.2025 06:21 โ ๐ 0 ๐ 4 ๐ฌ 0 ๐ 0
Bash a newline: Exploiting SSH via ProxyCommand, again (CVE-2025-61984)
For those of you who saw my BSides Canberra talk, here's a vulnerability I couldn't talk about in the talk, yet, but is very much in the spirit of it: https://dgl.cx/2025/10/bash-a-newline-ssh-proxycommand-cve-2025-61984
07.10.2025 04:18 โ ๐ 0 ๐ 1 ๐ฌ 0 ๐ 0
Images over DNS
I probably should have polished my @ComfyConAU talk. Instead I got sidetracked into wondering just how much I could tunnel over DNS: https://dgl.cx/2025/09/images-over-dns
20.09.2025 14:00 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Noticed my SLAAC IPv6 address happens to end in :fade. Fade to black?
19.09.2025 07:40 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
I'll be speaking at BSides Canberra: https://cfp.bsidescbr.com.au/bsides-canberra-2025/talk/8TWF8X/ -- this will cover my recent find of an RCE in Git and how that and some other vulnerabilities could be used against developers. #bsides #security
31.07.2025 01:02 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
๐บ๐ธ๐ณ๏ธโ๐๐ณ๏ธโโง๏ธ๐ฅโ๏ธ๐๐ฉ๐ฝโ๐ป in ๐ฆ๐บ๐จ๐ฆ working on ๐ฏโฌข๐ญ
she/it
Some nerd that uses computers | Blogger with 500-ish articles at https://xeiaso.net | @theprincessxena on the bird website | CEO @techaro.lol | Minors DNI
That guy who makes visual essays about software at https://samwho.dev.
Developer Educator @ ngrok.com. Want to pair on something ngrok related? Let's do it! https://cal.com/samwho/workhours
He/him.
Founder at: @piccalil.li and @set.studio
Complete CSS Course: https://complete-css.com
CSS Book: https://every-layout.dev
Newsletter: https://piccalil.li/the-index/
๐ https://bell.bz/links/
๐ https://bell.bz
๐ Cheltenham, UK
I'm that YouTuber who taught you how dishwashers work. Guess I'm tryin' out the whole Bluesky thing now.
he/him
https://www.youtube.com/technologyconnections
Hello, cyberpals. I make @pushover.net and old Macintosh stuff and sometimes OpenBSD stuff for you and me.
Projects here: @klud.ge | @deskto.ps
Oak Park, Illinois
World Wide Web: jcs.org