Profile for joern
About joern
Fields
- Website
- https://0day.click
- Threema
- https://threema.id/K8J68WTX
Bio
Your mom's favorite hacker!
My other account is @joernchen
- Joined
- Posts
- 687
- Followed by
- 1129
- Following
- 261
Stats
Recent public posts
exclude boosts
kauft selbstgemachte Chilisoße 

Wir haben #Chilisoße gemacht & schön verpackt und möchten sie nun an euch verkaufen.
10% #Rabatt: https://shop.k23v.de/discount/CHAOS; andernfalls den Code CHAOS im Checkout eingeben.
Bestellungen können aufm #cccamp23 abgeholt werden (DECT 5238); oder wir versenden, wenn wir vom #Camp wieder da sind.
Der Newsletter weiß es zuerst end ermöglicht, exklusive Sondereditionen zu erwerben: https://k23v.de/newsletter.html
Ein Leben ohne #Lava ist möglich, aber fad.
`open("|command-here")` has officially been deprecated and will be released in the next version. In Ruby 4.0 it will be removed for good, closing a common attack vector for getting remote command execution via `Kenrel.open()`.
https://github.com/ruby/ruby/pull/7915#event-10053443655
https://bugs.ruby-lang.org/issues/19630#change-103966
#ruby #security
The #cccamp23 orga is still looking for 15-20x 2-person sleeping tents for artists during the event - in the best case incl. sleeping mat/sleeping bag (will also be accepted individually).
If you can spare these things temporarily, please get in touch via email with the subject "Tent-for-artists" to camp2023-orga@cccv.de and write what you can bring in which amount for how long /co
Boosting wanted @c3cert @c3auti @jugendhackt @c3assemblies @haecksen @c3loc @C3Kidspace @c3infodesk
Want to help test the #CCCamp23 app for iOS and macOS? Sign up for TestFlight here: https://testflight.apple.com/join/HdrPYxM5
Remember me warning about Jean Pereira, an #infosec fraud? Well, there's a video detailing just how much he is overplaying his hand. https://youtu.be/duLJUpptSik
Muhahahah brilliant
Considering giving a talk titled: „I made my hobby my profession so I needed a new hobby. Now I’m cuddling grown men in pyjamas trying to choke them out or break their limbs - for fun“
Against earlier statements it looks like I'll be at the CCC Camp with my family. See you all there!
#SchreinerManja und den manischen #Radweg-Wahn der #CDU stoppen? Komm morgen an die Demo! Gemeinsam zum roten Rathaus. 14 Uhr, Eberswalder Straße.
#ADFC #ChanginCities #FridaysForFuture #DerKlimablog #Klimakatastrophe #Zukunft #Sicherheit #Gesundheit
Well, I inadvertently discovered a zero-day RCE in acme.sh and got a Chinese CA to shut down overnight: https://github.com/acmesh-official/acme.sh/issues/4659
The other shell I got was via some funky LDAP truncation issue. Check out the write up at https://0day.click/recipe/pash/
Last Christmas I popped a shell¹ on http://hg.mozilla.org
Here's the fix:
https://hg.mozilla.org/hgcustom/version-control-tools/rev/0b02dd442661b4ada84e4c6dea58ab62cb8fbaca
Can you explain the bug?
FAQ:
- This is an authenticated vuln
- I'll post a writeup in the next days
- Yes, RTFM helps ... as usual
¹) actually it was two shells
Unpopular take: .zip domains were a marketing gag targeting security people.
