HNHacker News
TopNewBestAskShowJobs

vin10

337 karma · joined September 11, 2023

https://vin01.github.io/piptagole/
submissionscomments
vin10··on SecurityBaseline.eu
There should be a metric for sites hosting malicious content!

https[:]//erasmus-plus.ec.europa.eu/sites/default/files/2026-05/mortal-kombat-2-cs.pdf

vin10··on Vm.overcommit_memory=2 is the right setting for servers
it's a (then-)safe default from the age when having 1GB of RAM and 2GB of swap was the norm: https://linux-kernel.vger.kernel.narkive.com/U64kKQbW/should...
vin10··on Vm.overcommit_memory=2 is the right setting for servers
> he way stuff fails when it runs out of memory is really confusing

have you checked what your `vm.overcommit_ratio` is? If its < 100%, then you will get OOM kills even if plenty of RAM is free since the default is 50 i.e. 50% of RAM can be COMMITTED and no more.

curious what kind of failures you are alluding to.

vin10··on Vm.overcommit_memory=2 is the right setting for servers
For anyone feeling brave enough to disable overcommit after reading this, be mindful that default `vm.overcommit_ratio` is 50% which means that if no swap is available, on a system with 2GB of total RAM, more than 1GB of RAM can't be allocated and requests will fail with preemptive OOMs. (e.g. postgresql servers typically disable overcommit)

- https://github.com/torvalds/linux/blob/master/mm/util.c#L753

vin10··on Al-LLM powered eBPF based security platform
Nice usability features definitely. Apart from that how would you say it compares against something like sysdig falco / cilium + tetragon?

Apart from this a major issue is DNS based dynamic filtering which is way batter to get right in a Kubernetes environment with something like Cilium. IP lists are impossible to manage with modern level of third party integrations.

vin10··on How to harden GitHub Actions
Interesting project, I think I just found a way to crash the sandbox, just reported via an advisory.
vin10··on How are cyber criminals rolling in 2025?
I would have expected at least Virustotal to flag them if that were the case. It does more than just looking up in a database of known malicious URLs and I think the reputation of the domains is the key factor here.

https://www.virustotal.com/gui/url/6dd23e90ee436e1ff066725aa...

> BitDefender - government

> Sophos - government

> Forcepoint ThreatSeeker - government

- https://docs.virustotal.com/docs/how-it-works

vin10··on How are cyber criminals rolling in 2025?
It is the same for nested links as well. They mostly have a chain of links, each one taking you to a new one with hop count ranging anywhere from 5 up to 10 or more.
vin10··on Unfashionably secure: why we use isolated VMs
> If you wouldn't trust running it on your host, you probably shouldn't run it in a container as well.

- From a Docker/Moby Maintainer

vin10··on Abusing url handling in iTerm2 and Hyper for code execution
It is guarded by a warning and requires explicit approval similar to browsers but yes, it does broaden the attack surface: https://gitlab.com/gnachman/iterm2/-/commit/fc9ae5c90f53cb1e...
vin10··on Abusing url handling in iTerm2 and Hyper for code execution
It is the first one, they need to be printed and clicked.
vin10··on You cannot simply publicly access private secure links, can you?
This is a very well formulated suggestion. Nicely written!
vin10··on You cannot simply publicly access private secure links, can you?
You are right about short expiry times but another catch here is that if pre-signed URLs are being leaked in an automated fashion, these services also keep the downloaded content from these URLs around. I found various such examples where links no longer work, but PDFs downloaded from pre-signed URLs were still stored by scanning services.

From https://urlscan.io/blog/2022/07/11/urlscan-pro-product-updat...

> In the process of scanning websites, urlscan.io will sometimes encounter file downloads triggered by the website. If we are able to successfully download the file, we will store it, hash it and make it available for downloading by our customers.

vin10··on SSH ProxyCommand == unexpected code execution (CVE-2023-51385)
OP here. Another interesting attack vector I have been working on is OSC 8 for hyperlink support in terminals. Mostly they allow arbitrary url schemes including "ssh://" without any prompt or user interaction to consent to open an external tool like ssh client in this case.

A good discussion on this: https://gist.github.com/egmontkob/eb114294efbcd5adb1944c9f3c...