HNHacker News
TopNewBestAskShowJobs

pentestercrab

2,279 karma · joined August 11, 2015

submissionscomments
pentestercrab··on Richard Dawkins concludes AI is conscious, even if it doesn't know it
(63 points, 4 days ago, 431 comments) https://news.ycombinator.com/item?id=47972481
pentestercrab··on Google's shortened goo.gl links will stop working next month
There seems to have been a recent uptick in phishers using goo.gl URLs. Yes, even without new URLs being accepted by registering expired domains with an old reference.
pentestercrab··on Former cybersecurity chief Chris Krebs leaves SentinelOne after executive order
The risky.biz podcast episode got pulled too: https://bsky.app/profile/patrick.risky.biz/post/3lmioqiobks2...
pentestercrab··on Ruby 3.4 Universal RCE Deserialization Gadget Chain
Once again GTFOBins[0] proving to be a valuable resource.

[0] https://gtfobins.github.io/

pentestercrab··on Ruby's String Slice is Broken
Thanks for the feedback, fixed!
pentestercrab··on Insecurity Through Censorship: Vulnerabilities Caused by the Great Firewall
From the article:

Our leading theory is that the Great Firewall inside China is manipulating DNS responses due to blacklisted or blocked keywords. This affects any system that has to pass through the Great Firewall before it reaches the end-user/client. Most of the keywords relate to VPN software, proxies, adult sites, file and text sharing and torrents. This is consistent with the kinds of material that China is known to censor within its borders.

pentestercrab··on Ruby's official documentation just got a new look
I have to agree with you. It is a shame the classic style isn’t available at an alternate subdomain or directory.

Has anyone tried rendering the current docs with the old theme?

pentestercrab··on Ask HN: Static site generator that can cope with octopus juggling geysers?
One idea, maybe using file instead of virtual will avoid the bug and not require your added code.

    <!--#include file="issue-0001.html" -->
Also, be careful of any moves to supporting dynamic content as Server Side Includes can (sometimes?) lead to code exec even with IncludesNoExec.
pentestercrab··on Google Sues Glupteba botnet [pdf]
https://blockstream.com/satellite/ - The Bitcoin blockchain from space. No internet required.
pentestercrab··on The search for the “perfect” Advent Calendar (involves Python and Processing)
Previous discussion from 2018: - https://news.ycombinator.com/item?id=18659809
pentestercrab··on A proof P = NP was accidentally published in TOCT
The fivefold repetition rule requires no claim by the players.
pentestercrab··on OpenSSH 8.6 Released
Security ========

* sshd(8): OpenSSH 8.5 introduced the LogVerbose keyword. When this option was enabled with a set of patterns that activated logging in code that runs in the low-privilege sandboxed sshd process, the log messages were constructed in such a way that printf(3) format strings could effectively be specified the low-privilege code.

   An attacker who had sucessfully exploited the low-privilege
   process could use this to escape OpenSSH's sandboxing and attack
   the high-privilege process. Exploitation of this weakness is
   highly unlikely in practice as the LogVerbose option is not
   enabled by default and is typically only used for debugging. No
   vulnerabilities in the low-privilege process are currently known
   to exist.

   Thanks to Ilja Van Sprundel for reporting this bug.
pentestercrab··on Hacking with environment variables
The second sentence of the blog post states:

   We were also unable to control the contents of a file on disk, and bruteforcing process identifiers (PIDs) and file descriptors found no interesting results, eliminating remote LD_PRELOAD exploitation.
pentestercrab··on Breached Data Indexer ‘Data Viper’ Hacked
https://intelx.io/?did=25626760-7371-4872-be87-68c350f7baac
pentestercrab··on Hacking with environment variables
Sounds very interesting, thanks for sharing. Do you have any more information or perhaps a URL to a write-up for this? Or do you remember the challenge name?
pentestercrab··on Hacking with environment variables
It does not require opening a browser, it can cause a browser to open.
pentestercrab··on Hacking with environment variables
Yes, that works fine. The hard part is finding a suitable .so already on the system. The following (credit to Tavis Ormandy) creates /tmp/testing

  $ RUBYOPT="-r/usr/lib64/libpcprofile.so" PCPROFILE_OUTPUT="/tmp/testing" ruby /dev/null
pentestercrab··on Fwupd – S3 bucket takeover and CVE-2020-10759 signature verification bypass
From TFA: These vulnerabilities would have allowed an attacker who claimed the S3 bucket to offer malicious firmware updates to Linux desktops and servers running legacy versions of fwupd.

Some extra discussion can be found in a Twitter thread[0] from the person who discovered the issues.

[0] https://twitter.com/justinsteven/status/1270113960021209088

pentestercrab··on Fwupd – S3 bucket takeover and CVE-2020-10759 signature verification bypass
Some extra details can be found in the relevant Twitter thread[0] relating to affected Linux distributions.

[0] https://twitter.com/justinsteven/status/1270113960021209088

pentestercrab··on DeepFaceDrawing Generates Photorealistic Portraits from Freehand Sketches
http://geometrylearning.com/DeepFaceDrawing/ says "[Coming Soon]" for the code.
pentestercrab··on Five Intel Microcode (UCode) Sequencer's Arrays
Extra context can be found in tweets by @_markel___[1].

[1] https://twitter.com/_markel___/status/1262697756805795841

pentestercrab··on /I Considered Harmful
On the topic of case and unicode, it's also important to remember that, somewhat surprisingly, the number of characters can change when a change in case occurs:

  $ irb
  >> puts RUBY_VERSION
  2.6.5
  >> "ß".chars.size
  => 1
  >> "ß".upcase.chars.size
  => 2
pentestercrab··on Forgot2kEyXCHANGE CVE-2020-0688: Remote Code Execution Microsoft Exchange Server
A great video on exploiting .NET deserialization was presented at Insomni'hack 2018 and can be found on YouTube[1].

[1] https://www.youtube.com/watch?v=eDfGpu3iE4Q

pentestercrab··on Ruby 2.x Universal RCE Deserialization Gadget Chain (2018)
The same gadget chain can alsobe used to exploit YAML.load [0] with the following:

    --- !ruby/object:Gem::Requirement
    requirements:
      !ruby/object:Gem::DependencyList
      specs:
      - !ruby/object:Gem::Source::SpecificFile
        spec: &1 !ruby/object:Gem::StubSpecification
          loaded_from: "|id 1>&2"
      - !ruby/object:Gem::Source::SpecificFile
          spec:
[0] https://staaldraad.github.io/post/2019-03-02-universal-rce-r...
pentestercrab··on The Incompatible Food Triad
This brought back memories of CAP theorem[1] and Zooko's triangle[2], but this time with flavors.

[1] https://en.wikipedia.org/wiki/CAP_theorem

[2] https://en.wikipedia.org/wiki/Zooko%27s_triangle

pentestercrab··on Search for an Airbnb apt on desktop, get mobile FB ad for same village and date
Follow up thread here[0] that discussed how Facebook's "Advanced Matching for Web" works.

[0] https://twitter.com/thezedwards/status/1204965655482527744

pentestercrab··on Request smuggling between Amazon ALBs and Go net/HTTP
More information on desynchronization attacks that can allow request smuggling can be found on the Portswigger blog[0].

[0] https://portswigger.net/research/http-desync-attacks-request...

pentestercrab··on Sushi Roll: A CPU research kernel with minimal noise for microarch introspection
Interesting comment from the author over on reddit[1] discussing using the research kernel to "find 0-day in software and hardware for about 2 years".

[1] https://old.reddit.com/r/programming/comments/csfj53/sushi_r...

pentestercrab··on ABC Sydney HQ Raided by Australian Federal Police over Afghan Files Stories
Live tweeting of the raid can be found here: https://twitter.com/TheLyonsDen
pentestercrab··on Bugs in Grandstream Gear Lay Open SMBs to Range of Attacks
The original advisory can be found here[0] and a Github repository with PoCs here[1].

[0] https://www.trustwave.com/en-us/resources/security-resources...

[1] https://github.com/scarvell/grandstream_exploits

Page 1 of 2Next →