HNHacker News
TopNewBestAskShowJobs

n3mes1s

186 karma · joined April 21, 2015

submissionscomments
n3mes1s··on Forgejo <=16.0.3 Critical RCE
I'm working on a tool to reproduce stuff like this exactly.

Yep this is an RCE with the forgejo user on the host.

https://www.pruva.dev/reproductions/REPRO-2026-00345 for details.

you can even start your version of the repro using github codespaces

========================================

REPRO-2026-00345

========================================

Title: Forgejo <16.0.4 RCE via crafted template repository (.forgejo/template expansion recreates .git folder adopted by git init)

Severity: CRITICAL

CVE: CVE-2026-89094

========================================

[pruva] Working directory: /workspaces/pruva-sandbox/pruva-results/REPRO-2026-00345

[pruva] Found script artifact: bundle/repro/reproduction_steps.sh

[pruva] Downloaded 4 repro artifact(s), script: 324 lines

[pruva] ==========================================

[pruva] WARNING: This will execute code that

[pruva] exploits a real vulnerability.

[pruva] ==========================================

[pruva] Auto-confirming in sandbox environment...

[pruva] Running reproduction script...

--- REPRODUCTION OUTPUT ---

[09:39:29] ensuring container images are present

[09:39:42] vulnerable image digest: sha256:214f4ae63ee78be1e445e58573c88dc7215e72091210852e0df94eaac1a25685

[09:39:42] fixed image digest: sha256:a263a1298e89e0bdf019005ce1927e9aadaa8f1bd2a94a3e66ad94e2a89e19ce

[09:39:42] [vuln-1] starting container (codeberg.org/forgejo/forgejo:16.0.3-rootless)

[09:39:52] [vuln-1] service healthy on 127.0.0.1:4011

[09:39:53] [vuln-1] admin user + token ready

[09:39:55] [vuln-1] malicious template pushed

[09:40:03] [vuln-1] generate API returned 201

[09:40:15] [vuln-1] marker=**** hook_id=**** hostdata=**** readme_ok=**** gen=201

[09:40:15] [vuln-2] starting container (codeberg.org/forgejo/forgejo:16.0.3-rootless)

[09:40:25] [vuln-2] service healthy on 127.0.0.1:4012

[09:40:26] [vuln-2] admin user + token ready

[09:40:28] [vuln-2] malicious template pushed

[09:40:32] [vuln-2] generate API returned 201

[09:40:36] [vuln-2] marker=**** hook_id=**** hostdata=**** readme_ok=**** gen=201

[09:40:36] [fixed-1] starting container (codeberg.org/forgejo/forgejo:16.0.4-rootless)

[09:40:40] [fixed-1] service healthy on 127.0.0.1:4111

[09:40:40] [fixed-1] admin user + token ready

[09:40:41] [fixed-1] malicious template pushed

[09:40:46] [fixed-1] generate API returned 201

[09:40:50] [fixed-1] marker=false hook_id=false hostdata=false readme_ok=**** gen=201

[09:40:50] [fixed-2] starting container (codeberg.org/forgejo/forgejo:16.0.4-rootless)

[09:40:52] [fixed-2] service healthy on 127.0.0.1:4112

[09:40:53] [fixed-2] admin user + token ready

[09:40:54] [fixed-2] malicious template pushed

[09:40:58] [fixed-2] generate API returned 201

[09:41:02] [fixed-2] marker=false hook_id=false hostdata=false readme_ok=**** gen=201

[09:41:02] vuln markers: **** / **** ; hook-id: **** / **** ; hostdata: **** / **** ; gen: 201 / 201

[09:41:02] fixed markers: false / false ; readme-ok: **** / **** ; gen: 201 / 201 runtime_manifest.json written with 44 proof artifacts

[09:41:02] VERDICT: CONFIRMED - remote code execution reproduced on Forgejo 16.0.3 via crafted template repository; fixed 16.0.4 unaffected

--- END REPRODUCTION OUTPUT ---

[pruva] ==========================================

[pruva] VERIFICATION SUCCESSFUL

[pruva] Duration: 93s

[pruva] ==========================================

[pruva] Logs: /workspaces/pruva-sandbox/pruva-results/REPRO- 2026-00345/logs/ - fixed-1 - fixed-2 - reproduction_steps.log - vuln-1 - vuln-2

[pruva] Results saved to: /workspaces/pruva-sandbox/pruva-results/REPRO-2026-00345

[pruva] Keeping work directory: /workspaces/pruva-sandbox/pruva-results/REPRO-2026-00345 Outcome: success User: vscode WorkspaceFolder: /workspaces/pruva-sandbox

n3mes1s··on On Apple’s “Expanded Protections for Children” – A Personal Story
You can find technical details here:

https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...

n3mes1s··on Ask HN: Who is hiring? (June 2021)
ReaQta (https://www.reaqta.com ) | Amsterdam, Remote EU | Full-Time

ReaQta started with a mission to 10x the performance of security teams defending against next-generation threats. ReaQta is changing the game for endpoint security with its award-winning technology and user experience. Our platform is a force-multiplier which enables organizations to future-proof themselves at scale, at a fraction of the cost. The company continues to drive research and innovation around artificial intelligence, machine learning, and behavioral-based analysis and defense to deliver cutting-edge cybersecurity to organizations and governments worldwide. We are the one of the most disruptive and fast growing companies in the rapidly expanding endpoint security market.

- Endpoint Detection Engineer (Linux): https://reaqta.com/team/join-us/3975

- DevOps Engineer: https://reaqta.com/team/join-us/3994

- Cloud Detection Engineer: https://reaqta.com/team/join-us/3974

- Software Engineer (Integrations): https://reaqta.com/team/join-us/3793

n3mes1s··on Landlock merged in mainline for Linux 5.13
There is a sort of opensnitch based on ebpf but not sure is fully feature completed as you intended:

https://github.com/harporoeder/ebpfsnitch

n3mes1s··on Fly’s Prometheus Metrics
More info about this in the blogpost Docker without Docker[0]

[0] https://fly.io/blog/docker-without-docker/

n3mes1s··on Ask HN: Who is hiring? (May 2021)
ReaQta (https://www.reaqta.com ) | Amsterdam, Remote EU | Full-Time

ReaQta started with a mission to 10x the performance of security teams defending against next-generation threats. ReaQta is changing the game for endpoint security with its award-winning technology and user experience. Our platform is a force-multiplier which enables organizations to future-proof themselves at scale, at a fraction of the cost.

The company continues to drive research and innovation around artificial intelligence, machine learning, and behavioral-based analysis and defense to deliver cutting-edge cybersecurity to organizations and governments worldwide. We are the one of the most disruptive and fast growing companies in the rapidly expanding endpoint security market.

- Endpoint Detection Engineer (Linux): https://reaqta.com/team/join-us/3975

- DevOps Engineer: https://reaqta.com/team/join-us/3994

- Cloud Detection Engineer: https://reaqta.com/team/join-us/3974

- Software Engineer (Integrations): https://reaqta.com/team/join-us/3793

n3mes1s··on VMware now supports Hyper-V mode
Just a note that I think could be important for someone here, the nested virtualization is not currently supported. What this means ? You will not be able to run another hypervisor inside the guest vm.
n3mes1s··on Shipping a Linux Kernel with Windows
This is how hypervisor nesting works, a lot of issues, trust me.
n3mes1s··on Shipping a Linux Kernel with Windows
Just adding that virtualbox 6 works(ish) [1] with hyper-v thanks to the use of the virtualization API [2] to setup the VM.

[1] https://forums.virtualbox.org/viewtopic.php?f=6&t=90853 [2] https://docs.microsoft.com/en-us/virtualization/api/

n3mes1s··on Kaspersky OS
some interesting finding:

- https://twitter.com/gN3mes1s/status/798992790436933632

- RU slides http://osday.ru/presentations/duhvalov/9jun.rifinnopolis16-1...

- RU presentation https://www.youtube.com/watch?v=_iEaY_CGcy8

n3mes1s··on Hacker Shows Us How to Unlock a Laptop Using an NSA Tool [video]
some links related:

- https://www.defcon.org/images/defcon-22/dc-22-presentations/...

- https://www.youtube.com/watch?v=OD2Wxe4RLeU

n3mes1s··on St. Jude Heart Devices Vulnerable to Hacks
paper: http://d.muddywatersresearch.com/wp-content/uploads/2016/08/...
n3mes1s··on Chocolatey and oneget under win 10 (apt-get for windows)
maybe....

- http://www.hanselman.com/blog/AptGetForWindowsOneGetAndChoco...

n3mes1s··on Robigalia: seL4 and Rust
some useful links on rust + rump kernel:

https://gandro.github.io/2015/09/27/rust-on-rumprun/

https://polyfractal.com/post/adding-a-disk-to-a-rust-rumprun...

n3mes1s··on OpenBSD gets a hypervisor
just to be clear, the hypervisor's code is this one : http://cvsweb.openbsd.org/cgi-bin/cvsweb/~checkout~/src/sys/...
n3mes1s··on Clear Linux Project
read the hypervisor part of the lwn article: https://lwn.net/SubscriberLink/644675/5be656c24083e53b/

quote: "With kvmtool, we no longer need a BIOS or UEFI; instead we can jump directly into the Linux kernel. Kvmtool is not cost-free, of course; starting kvmtool and creating the CPU contexts takes approximately 30 milliseconds."

n3mes1s··on Introducing FIDO: Automated Security Incident Response
panel at rsa https://www.youtube.com/watch?v=qzK9Mj2V6BA
n3mes1s··on Artificial Intelligence has crushed all human records in 2048
discussion on stackoverflow:

https://stackoverflow.com/questions/22342854/what-is-the-opt...