HNHacker News
TopNewBestAskShowJobs

arusekk

62 karma · joined April 21, 2026

Abusing computers is fun. blog.arusekk.pl
submissionscomments
arusekk··on Sourcehut account takeover via build logs (XSS in ansi2html)
I presume kgraves meant something along either lack of compensation being unfair to me, or me spoiling the market by being sort of fine with it, or both. It's a valid opinion to have.
arusekk··on Sourcehut account takeover via build logs (XSS in ansi2html)
I think you might have misunderstood. The source code of SourceHut itself is hosted on SourceHut, and it has a CI/CD setup that packages the microservices as alpine packages, signs and uploads them automatically to mirror.sr.ht, as files. This is no different than having a pypi-upload action (or similar) on GitHub.

The only material difference is that the deploy keys for *.sr.ht present (by design) on builds.sr.ht also have access to `doas apk upgrade -Ua` and to `doas rc-service *.sr.ht restart` on the production infra. Which is harmless by itself, but might result in Continuous Ownage if a rogue build happens to have access to the keys.

arusekk··on Sourcehut account takeover via build logs (XSS in ansi2html)
Fixed! (You can send me patches for https://git.sr.ht/~arusekk/arusekk.srht.site too)
arusekk··on Sourcehut account takeover via build logs (XSS in ansi2html)
I hope they will one day. I said I'm fine with verbal credit if they don't have money, so I won't nag them unless I end up finding more.
arusekk··on Sourcehut account takeover via build logs (XSS in ansi2html)
That might have been DNS, the website itself is on sourcehut pages. Should be fine now for a while.
arusekk··on Sourcehut account takeover via build logs (XSS in ansi2html)
You're welcome!
arusekk··on Sourcehut account takeover via build logs (XSS in ansi2html)
I would prefer to do a super proper disclosure with coordinated release dates and everything. My first submitting to SourceHut security ML ended up making the vuln existence somewhat public before upstream ever knew.
arusekk··on Libertix installs Linux with 3 mouse clicks for Windows users
Looks similar to mine (but mine has zero vibe code, unlike this one): https://1clicklinux.org
arusekk··on Omarchy Impersonated at Omarchy[.]Net
Is there someone making a list of such incidents? It would be very interesting to take a broader look.
arusekk··on Ask HN: What are you working on? (June 2026)
I'm working on my easy Linux installer and its website. https://1clicklinux.org
arusekk··on Show HN: Linux installer .exe without pendrives (secure-boot compatible)
The worst part I think was getting Qt to link statically, and also forcing Windows commandline utilities to output UTF-8 instead of garbage like cp437 etc.