The new #curl CVE-2024-11053 we call "netrc and redirect credential leak"
While graded severity low, it will of course still be relevant to whomever uses the unlucky combination of options.
The new #curl CVE-2024-11053 we call "netrc and redirect credential leak"
While graded severity low, it will of course still be relevant to whomever uses the unlucky combination of options.
#curl 8.11.1 has been released. It includes a fix to #CVE_2024_11053 - a #vulnerability I discovered.
It is a logic flaw in the way curl parses .netrc file. In certain situations, the configured password can be sent to a incorrect host. Luckily the affected configurations should be quite rare and thus the situation is unlikely to occur often.
The issue has existed in the curl source code for almost twenty-five years.
• curl.se/docs/CVE-2024-11053.ht…
• hackerone.com/reports/2829063
No AI tools were used in discovering or reporting the vulnerability.
#curl 8.11.1 is released. About 79 bugfixes, including one CVE addressed.
daniel.haxx.se/blog/2024/12/11…
Welcome to another curl release. This time we do a bugfix only release, five weeks since the previous version shipped. Release Presentation Today at 09:00 UTC I will do a live-streamed video presentation of curl 8.11.1 on Twitch.daniel.haxx.se
daniel:// stenberg:// reshared this.
Projekt OpenWrt nedávno oznámil přechod ze stávajícího formátu balíčků opkg na apk. Co to znamená pro běžného uživatele? Jak se tyto dva formáty a nástroje s nimi pracující vlastně liší?Michal Hrušecký (Internet Info, s.r.o.)
Donald #Trump Controls a Publicly Traded Company. Now He Will Pick Its Regulator.
—
There have been internal concerns that Trump Media could be misleading investors, a source said. But with its largest shareholder about to be president, experts doubt the SEC is up to the job of investigating Truth Social’s parent company.
#News #Government #SEC #Regulation #USPolitics #TrumpMedia #Politics #Business #Finance #DonaldTrump
reshared this
‘Brain rot’ is the Oxford word of the year – a fitting choice, given the startling impact the internet is having on our grey matter, says journalist Siân BoyleSiân Boyle (The Guardian)
A judge granted WP Engine’s request for a preliminary injunction against Automattic and its CEO Matt Mullenweg in their dispute over the WordPress trademark.Emma Roth (The Verge)
Na klar, na? Da soll ich also schnellstens mein Online-Banking unter "klarna-verfahren.com" über den Link in der SMS "aktualisieren". Als ob ich freiwillig einen solchen Service überhaupt nutzen würde. Alles Klar, na?
(PS: Hab solche SMS bislang nie bekommen, sehe so etwas also zum ersten Mal aus erster Hand)
🗑️
🏧Aira Access at Chase Banks, Nationwide 🏦
Aira is now available at every Chase Bank branch in the U.S.! Bank customers can connect with a visual interpreter on-demand while in any branch, using Chase Bank ATMs, or when accessing online banking services. All calls are free of charge with the Chase Bank access offer.
"As a Chase customer and Aira user, I'm excited at the added accessibility this offer gives me! I love that I can call in and get the support I need to use the ATM or navigate the store on my own terms." - Aira Explorer
This full roll-out follows a successful pilot at 46 Chase Bank Innovation Lab locations as Chase expands efforts to meet the needs of its blind and low vision members.
Full Article: aira.io/aira-at-chase/
#accessibility #disability #DisabilityAwareness #inclusion #AccessibleTechnology
Aira is now available at all Chase Bank locations, ATMs, and while using online banking services. Learn more and get started with Aira at Chase today!Aira
reshared this
Welcome to the RB family, Neo Backup 🥳
apt.izzysoft.de/packages/com.m…
Neo Backup is a fork of OAndBackup bringing support for new Android versions & updated looks. It lets you make and restore backups of apps on your device and save app data to a user-accessible location. Needs root.
After figuring how to get the zlib-ng issue disappear (not me!) the app is now RB & the new release tomorrow will have the green shield up 
#reproducibleBuilds #IzzyOnDroid – now at 370 apps (30.2%) & growing
The open-source tool to backup your apps and dataIzzyOnDroid App Repo
reshared this
minimálne za vraždu a sexuálne zneužívanie by nemala byť premlčacia doba a nemal by byť možný podmienečný trest
🔓 dennikn.sk/4351412/riaditel-ch…
Bývalý riaditeľ detského tábora Chachaland Roman Paulíny je vinný zo sexuálneho zneužívania 14-ročnej Kataríny Danovej. Mestský súd Bratislava I ho odsúdil na trest odňatia slobody na dva roky s podmienečným odkladom na dva roky.Ria Gehrerová (Denník N)
Rozhodla sa prehovoriť o sexuálnom zneužívaní, ktoré zažila.Zuzana Kovačič Hanzelová (SME.sk)
Finlandia, Giappone, Norvegia, Olanda e Svezia, i paesi più virtuosi. L'Italia tra gli 11 paesi con risultati al di sotto della media OCSERedazione di Rainews (RaiNews)
𝔻𝕚𝕖𝕘𝕠 🦝🧑🏻💻🍕 likes this.
Microsoft is changing how Copilot works on Windows yet again. A new update includes a quick view UI and a new keyboard shortcut.Tom Warren (The Verge)
reshared this
Here's the problem, right here.
Musk an those like him believe in, and live by, a fundamentally different moral code from the rest of us. They genuinely believe that their greatest moral responsibility is increasing profits for the benefit of shareholders. Everything else, including human life, is peripheral to that central and highest good.
#Catima 2.34.0 is out!
This release adds support for #Passbook (#pkpass) files, commonly used for event tickets and more!
It also contains some other minor fixes and better handling of image thumbnails (especially transparent ones).
On the end-user side, this release probably doesn't look that different, but it contains some major code refactoring. It is also the first release with #Kotlin code in it.
github.com/CatimaLoyalty/Andro…
#IzzyOnDroid #FDroid #GitHub #GooglePlay
Add Passbook (.pkpass) support Fix import of transparent PDF files Improve display of transparent thumbnailsGitHub
Thunderbird ist eine freie E-Mail-Anwendung, die sich leicht einrichten und anpassen lässt – und wir haben viele tolle Funktionen hineingepackt!Thunderbird
𝔻𝕚𝕖𝕘𝕠 🦝🧑🏻💻🍕 likes this.
All'app mancano molte funzionalità, ma non è colpa degli sviluppatori
framablog.org/2024/12/10/peert…
Il post di @Fedi.Tips 🎄
⬇️
Today, at Framasoft (bonjour!), we publish the very first version of the PeerTube Mobile app for android and iOS. A lot of care went into its conception, to help a wider audience watch videos and...Framablog
𝔻𝕚𝕖𝕘𝕠 🦝🧑🏻💻🍕 likes this.
Ich habe, bevor @k9mail von @mozilla für @thunderbird übernommen wurde, immer monatlich über GitHub unterstützt. Da ich k9 weiterhin nutze, ging die Spende dieses Jahr an Mozilla. Das ist echt einfach gemacht in der App, schwupps über G-Pay. Ich konnte endlich mal die Gutscheine einlösen.
Unterstützt Open Source - mich würde auch interessieren was für Chromium Derivate die ganzen Google Hasser nutzen, anstatt Gecko. 🤷
Microsoft has released the Windows 11 KB5048667 and KB5048685 cumulative updates for versions 24H2 and 23H2 to fix security vulnerabilities and issues.
Begins at 10am PTJoin Kevin Weil, Lee Byron, and Alexi Christakis to hear about updates and watch live demos.YouTube
CHINA has unveiled unbreakable, spherical robo-cops which have been seen rolling around cities – ready to catch criminals. The AI-powered bot beasts are capable of not only stopping crime, bu…Annabel Bate (The US Sun)
'Navix' follows OpenELA rules, comes with ten years support, and is already used in production at scaleSimon Sharwood (The Register)
Sara è una donna, una madre. È disoccupata, single e migrante. La sua è un’identità stratificata, unica e irripetibile, eppure queste caratteristiche sociali la renderanno sospetta per tutta la vita. Perché per un modello matematico – e per il governo del suo paese – Sara è solo un insieme di indicatori che, sommati tra loro, generano un alto punteggio di rischio, una previsione statistica che la trasforma in una potenziale criminale. Ma la sua unica colpa è quella di essere se stessa, e di condividere un profilo simile ad altre persone esistite e accusate prima di lei.
A public sector funding initiative should pick up #Mozilla #Firefox and drive it as a community browser indepedent of #Google funding.
A browser is by far the single most impactful gateway to computing resources for people nowadays. (Right after a mobile OS.)
It must not be allowed to fail.
zdnet.com/home-and-office/netw…
#OpenSource #OpenWeb #PublicSector #PublicMoneyPublicCode
Fewer people than ever use the once popular web browser, but Mozilla remains profitable thanks to Google. How long can that trend continue with the Department of Justice coming after Google?Steven Vaughan-Nichols (ZDNET)
I don’t think most people realize how Firefox and Safari depend on Google for more than “just” revenue from default search engine deals and prototyping new webSeirdy’s Home
I can't wait to see how people use default field values in #Rust!
It felt like an eternity to land this (specially if we count the years of discussion before the, I believe, 3rd RFC was accepted), but as of next nightly you will be able to write
struct Foo {
bar: Type = Type::const_method(),
}
Foo { .. } // implicit `bar: Type::const_method()` call
The main difference between github.com/rust-lang/rust/pull… and derive(Default) is that the latter doesn't support having mandatory fields.
#RustLang
Initial implementation of #[feature(default_field_values], proposed in rust-lang/rfcs#3681. We now parse const expressions after a = in a field definition, to specify a struct field default value. ...GitHub
modulux reshared this.
Did you catch the recent ACB Vispero Presentation - Use the Thunderbird Email Client With JAWS? In case you missed it, the archive is now available: acb-community.pinecast.co/epis…
#FreedomScientificTraining #JAWS
as aired on ACB Media 5ACB Community
Ben Zanin
in reply to daniel:// stenberg:// • • •hmm, I think this CVE fix may have broken my use of ~/.netrc with the GitHub REST API. Ran into an issue where my normal usage pattern of curl, which includes a "netrc-optional" entry in ~/.curlrc and a GitHub personal access token in ~/.netrc, no longer adds an "Authorization: ..." header to my requests, correlated in time with installing curl 8.11.1 via homebrew.
I'll see if I can produce a properly reduced test case and bisect down to one commit.
daniel:// stenberg://
in reply to Ben Zanin • • •Ben Zanin
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Ben Zanin • • •Ben Zanin
in reply to daniel:// stenberg:// • • •Issue filed with a reduced replication test!
github.com/curl/curl/issues/15…
While developing that test I discovered an interesting factor: the bug seems to only be triggered in combination with the `--netrc-optional` option, notwithstanding whether that option is passed directly on the command line or whether it appears in `~/.curlrc`.
I wish I could have strace'd into exactly what's happening at file parse time. Hopefully this is useful enough!
curl CLI v8.11.1 fails to offer HTTP Basic auth specified in .netrc when invoked with --netrc-optional · Issue #15767 · curl/curl
GitHubdaniel:// stenberg://
in reply to Ben Zanin • • •daniel:// stenberg://
in reply to Ben Zanin • • •netrc: fix password-only entries by bagder · Pull Request #15768 · curl/curl
GitHubBen Zanin
in reply to daniel:// stenberg:// • • •