oleg_log
Вчера в одном петпрожекте чутьчуть сломал сеть, завернул в докер и пушнул в прод (нет, не стыдно), ну и так вышло, что во время дебага прода и 502 ошибки сломал соседние вещи (чуть меньше не стыдно). В итоге ошибка была смешной, http.Server на 127.0.0.1:8000…
oleg_log
Вчера в одном петпрожекте чутьчуть сломал сеть, завернул в докер и пушнул в прод (нет, не стыдно), ну и так вышло, что во время дебага прода и 502 ошибки сломал соседние вещи (чуть меньше не стыдно). В итоге ошибка была смешной, http.Server на 127.0.0.1:8000…
Собственно и новый личный сайт https://olegk.dev/
Я даже статьи написал и жду запостить. Настолько все серьезно.
Более серьезных вещей я еще не делал.
Осталось utterance для коментов прикрутить https://olegk.dev/posts/hello-world/
Я даже статьи написал и жду запостить. Настолько все серьезно.
Более серьезных вещей я еще не делал.
Осталось utterance для коментов прикрутить https://olegk.dev/posts/hello-world/
Если у вас один и тот же интерфейс определён в 3х местах (блин, это смешно даже писать), то всё таки вы что-то делаете не так.
Натирание фраз аля hexagonal architecture, ddd и какое-то еще буллшит не вылечивают ваш "код".
Я оч жалею, что я в этом сейчас копаюсь. Сейчас я понимаю, что переинтерфейсирование всего в Jave не так уж и плохо, оно даже органично как-то. Но не в Go.
Пост выше правда, как бы там на ХН не ныли.
Натирание фраз аля hexagonal architecture, ddd и какое-то еще буллшит не вылечивают ваш "код".
Я оч жалею, что я в этом сейчас копаюсь. Сейчас я понимаю, что переинтерфейсирование всего в Jave не так уж и плохо, оно даже органично как-то. Но не в Go.
Пост выше правда, как бы там на ХН не ныли.
CVE-2021-22555: Turning \x00\x00 into 10000$
Радует, что комбинации байтов несчётны, всегда весело будет.
https://google.github.io/security-research/pocs/linux/cve-2021-22555/writeup.html
Радует, что комбинации байтов несчётны, всегда весело будет.
https://google.github.io/security-research/pocs/linux/cve-2021-22555/writeup.html
security-research
CVE-2021-22555: Turning \x00\x00 into 10000$
This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
Через 2ч аудиочат сделаем, что-то про Go будет, возможно статьи Расса Кокса и по мелочи.
https://xn--r1a.website/generictalkschat
https://xn--r1a.website/generictalkschat
rust recovery foundation https://rustrecoveryfoundation.neocities.org/
There was a vulnerability in the cdnjs library update server that could execute arbitrary commands, and as a result, cdnjs could be completely compromised.
This allows an attacker to tamper 12.7% of all websites on the internet once caches are expired.
https://blog.ryotak.me/post/cdnjs-remote-code-execution-en/
This allows an attacker to tamper 12.7% of all websites on the internet once caches are expired.
https://blog.ryotak.me/post/cdnjs-remote-code-execution-en/
blog.ryotak.net
Remote code execution in cdnjs of Cloudflare
Preface
(日本語版も公開されています。)
Cloudflare, which runs cdnjs, is running a “Vulnerability Disclosure Program” on HackerOne, which allows hackers to perform vulnerability assessments.
This article describes vulnerabilities reported through this program and published…
(日本語版も公開されています。)
Cloudflare, which runs cdnjs, is running a “Vulnerability Disclosure Program” on HackerOne, which allows hackers to perform vulnerability assessments.
This article describes vulnerabilities reported through this program and published…
oleg_log
There was a vulnerability in the cdnjs library update server that could execute arbitrary commands, and as a result, cdnjs could be completely compromised. This allows an attacker to tamper 12.7% of all websites on the internet once caches are expired. h…
This media is not supported in your browser
VIEW IN TELEGRAM
oleg_log
There was a vulnerability in the cdnjs library update server that could execute arbitrary commands, and as a result, cdnjs could be completely compromised. This allows an attacker to tamper 12.7% of all websites on the internet once caches are expired. h…
<...> and if my reading of the blog post is correct, the current archive/tar behaviour is what enabled the exploit.
https://github.com/golang/go/issues/25849
👀
https://github.com/golang/go/issues/25849
👀
GitHub
archive/zip: sanitize the FileHeader.Name to remove path traversal ("../../") from zip files? · Issue #25849 · golang/go
Go isn't directly affected by path traversal attacks in archives but programs written in Go might be. In particular, if a Go program reads a malicious zip file, the archive/zip package will...
Forwarded from AWS Notes
Лучший редактор кода.
Anonymous Poll
2%
Atom
3%
Notepad++
9%
Sublime Text
15%
Vim
44%
VS Code
15%
Другой
11%
Посмотреть результаты
Forwarded from AWS Notes
Лучший редактор кода (расширенная версия).
Anonymous Poll
2%
Atom
1%
AWS Cloud9
0%
Eclipse
26%
IntelliJ
1%
Notepad++
9%
PyCharm
5%
Sublime Text
12%
Vim
33%
VS Code
12%
Посмотреть результаты
Нельзя вот так делать и давить на больное. Не. Ль. Зя. https://www.youtube.com/watch?v=R3QvniaZ5qM
YouTube
Need For Speed UNDERGROUND 2 | Remaster 2022
Всем привет, вы на канале Odonata Cinema! В этом видео мы показали, как могло бы выглядеть продолжение любимой игры NFS: три иконы из Need For Speed встретились вместе! Легендарные автомобили из каждой части NFS (Underground 1, Underground 2 и Most Wanted)…
Все плохо, NSO Group из Израиля изумительно ломает телефоны и сливает журналистов властям(и не только).
Описание https://www.theguardian.com/world/2021/jul/18/revealed-leak-uncovers-global-abuse-of-cyber-surveillance-weapon-nso-group-pegasus
Тех детали https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/
"ТЛДР" тех деталей https://twitter.com/billmarczak/status/1416801514685796352
Описание https://www.theguardian.com/world/2021/jul/18/revealed-leak-uncovers-global-abuse-of-cyber-surveillance-weapon-nso-group-pegasus
Тех детали https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/
"ТЛДР" тех деталей https://twitter.com/billmarczak/status/1416801514685796352
the Guardian
Revealed: leak uncovers global abuse of cyber-surveillance weapon
Spyware sold to authoritarian regimes used to target activists, politicians and journalists, data suggests
Forwarded from Технологический Болт Генона
Four Attacks and a Proof for Telegram.pdf
967.9 KB
Martin R. Albrecht, Lenka Mareková, Kenneth G. Paterson, Igors Stepanovs. Four Attacks and a Proof for Telegram. 2021.
https://mtpsym.github.io/
+
Ответ от команды Telegram
MTProto Analysis: Accessible Overview
https://telegra.ph/LoU-ETH-4a-proof-07-16
https://mtpsym.github.io/
+
Ответ от команды Telegram
MTProto Analysis: Accessible Overview
https://telegra.ph/LoU-ETH-4a-proof-07-16