HNHacker News
TopNewBestAskShowJobs

jonaslejon

649 karma · joined March 22, 2011

Web and cyber security geek.

[ my public key: https://keybase.io/jonaslejon; my proof: https://keybase.io/jonaslejon/sigs/CWrMd2vYkWkMYf7XVDm0kpGGtm1-yXbhmqenTcQdCDM ]

submissionscomments
jonaslejon··on Why does SSH send 100 packets per keystroke?
Memories! I was at the hacking conference HAL2001 and listening to Dug Song and Solar Designer, who were talking about their SSH timing analysis: https://download.openwall.net/pub/advisories/OW-003-ssh-traf...

Time flies

jonaslejon··on Build Simple Fuzzer (2020)
Nice tool! Will check it out. I have used jdam in the past to fuzz JSON: https://gitlab.com/michenriksen/jdam
jonaslejon··on RegreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems
OpenSSH 9.8p1 was released July 1, 2024 according to https://www.openssh.com/releasenotes.html#9.8p1
jonaslejon··on Bitwarden: Generate a Username
This was quite funny:

if name == "boring_wozniak" /* Steve Wozniak is not boring */ { goto begin }

jonaslejon··on SSH Bastion Host Best Practices
I personally use OSSEC for File Integrity Monitoring. And it has also actually caught an intruder that modified some PHP-code on a webserver. The attacker forgot to use the prefix @ in the PHP-code so a new error message was sent to the logfile and reported by OSSEC.
jonaslejon··on Masscan: TCP port scanner, scanning entire Internet in under 5 minutes
You need to have a really good relationship with your ISP and get their acknowledge prior to the scanning
jonaslejon··on I am stepping down from Perl Steering Council and Core
I don't really understand the thread. This guy X writes about the harassments and then someone replies and asks about the release versions?
jonaslejon··on TunnelBear Completes Industry-First Consumer VPN Public Security Audit
Great move for transparency
jonaslejon··on CIRCLean – USB key sanitizer
Old: https://news.ycombinator.com/item?id=8216853
jonaslejon··on Firefox exploit found in the wild
Since the vulnerability is in pdf.js, is the Tor Browser Bundle vulnerable?
jonaslejon··on Stored XSS in GMail for iOS
Why is he using Google Analytics for sending the XSS?
jonaslejon··on Show HN: Bootstrap In Practice, my ebook for starters
I bought a copy. Nice book! The format of the book seems kinda odd thought. This is a screenshot from my iPad Mini with Readmill (eBook reader): https://dl.dropboxusercontent.com/u/947269/IMG_0053.PNG
jonaslejon··on Today's Outage Post Mortem
Good idea. There might be a number of rules that can limit their communication with the routers (and even OOB)
jonaslejon··on Ask HN: How do you learn to develop exploits?
The best way is to start from the beginning, in other words read "Smashing the stack for fun and profit". These technics doesn't work on current operating systems but gives to a great start http://insecure.org/stf/smashstack.html
jonaslejon··on Bootstrap 2.0, From Twitter
Bootstrap 2.0 + WordPress = #win ? Anyone knows if there is any theme out there w/ Bootstrap?
jonaslejon··on Bootstrap 2.0, From Twitter
Maybe add or use http://listjs.com/ ?