Search

Items tagged with: CURL


on the fourth day of the year and we have already disclosed 6 Hackerone reports against #curl

This can only end one way.

#curl


#curl


First day of new year: two #curl vulnerability reports received. Both identified real bugs, neither is a security problem.
#curl


#curl


#curl


26 years ago, on December 28 1999, we migrated the main #curl source code from self-hosted to Sourceforge.

It was the new hot thing. Imagine the idea of a dedicated service devoted to nothing but hosting code!

We then kept the code there for ten years (on CVS). A period when the distributed version control systems really exploded.

#curl


No strcpy either.

daniel.haxx.se/blog/2025/12/29…

#curl

#curl


#curl hackerone update: one more vulnerability was confirmed legit and we have six pending CVEs now.

Only one of the submitted issues remains in triage but I'm advocating closing as N/A.

#curl


I'm submitting lovingly hand-crafted 100% organic reports to #curl #hackerone


I’ve heard #curl is a thing among Fediverse inhabitants. Will this help me get accepted to your tribe?
#curl


One right doesn't fix 100 wrongs. I'm happy for you and for #curl, but this doesn't change my opinion about #github and #microsoft in the slightest.


Not sure, I know there was this one time when the employees got to vote for projects to sponsor and #curl was one of them.
#curl


Number of hackerone reports on #curl doubled since last year
#curl


I spent many hours yesterday debunking another hackerone report against #curl.

It's such a good sigh of relief when the ultimate conclusion is that it is not a vulnerability. (disclosed soon of course)

#curl


GitHub is a top sponsor of #curl. They make a real difference. Can you say the same about whoever you work for?
#curl


@bagder should make phonecovers for #curl

  • Yes (0%, 0 votes)
  • Absolutely (0%, 0 votes)
  • Absolut! (0%, 0 votes)
  • Where to I buy it (100%, 1 vote)
  • Fan också! (0%, 0 votes)
1 voter. Poll end: 1 week ago


Probably old news but my mind is always blown by all the stuff #curl can do. I had zero idea that curl has a —form argument that lets you simulate filling out a form, complete with a file upload. Let me automate a super annoying task for a friend with a dead simple bash script.
#curl


#curl


#curl @cpu


#curl


Microsoft: „1 engineer, 1 month, 1 million lines of code“

That would mean @bagder
rewriting 5 #curl projects into Rust in a month.

Microsoft revising the „rewrite over a weekend“ meme to it actually taking them 6 days. For a person they have not hired yet. With tools they still have to invent.

If you are a MS customer, you‘d better start putting more money into Copilot right away!

theregister.com/2025/12/24/mic…


If you have ideas for a new #curl sticker design, let me know. I'm about to order a new batch soon.

Logo images to play with: curl.se/logo/

#curl


Basically the only way to get #curl stickers (without printing your own set) is to approach me when I show up somewhere to talk.

The next big chance is at #FOSDEM where I usually give away **thousands** of curl stickers.

It is always fine to pick a few extra to hand out to your friends and grandparents.


#curl


1. User complains to #hackerone that I named his *previous* name when he renamed himself to a silly name after I banned them in a #curl report filed back in October.

2. Hackerone asks me to respond on their support forum, on which I have no account. Grrr. I refuse to.

3. Replying to the hackerone email about this instead, I get a bounce saying they don't accept emails on support@hackerone ...

Kill me now.


Joshua Rogers on his bug bounty experiences in 2025.

Positive for #curl, kafka-esque for all others mentioned. ‚BugCrowd‘ seems to a typical level-1 support company living on denials.

(Joshua also reported on Apache and pbly other projects where he could talk to the maintainers. I take #curl here as an example for FOSS projects interested in actually securing things.)

joshua.hu/2025-bug-bounty-stor…

#curl


I added a sentence to the #curl hackerone submission page:

"Please present your case briefly and to the point. Do not use an AI to help you blab hundreds of lines that will exhaust us to death instead of making us understand your claim."

#curl


We end the year with 6 more #curl command line options than we had last new year's eve; now at 273 in total.
#curl


#curl


*Twelve* Hackerone submissions against #curl within the last seven days.

Zero of them turned out a confirmed vulnerability.

Several of them found, reported, phrased-in-far-too-many-words and mislead by stupid word completion machines.

#curl


If your company needs #curl support for OpenSSL 1.1 in 2026, just say so and we can have you covered in no time.

OpenSSL 1 support is dropped from the regular #curl releases but is available as a commercial offer.

#curl


This is not working. The number of #hackerone report submissions for #curl in 2025 is going through the roof, while the quality is going through the floor.

And the year isn't over yet.


#curl


When you‘re low on RAM, I recommend using a recent #curl for your internet transfers.

It can shuffle gigabytes back and forth using a few MB of your memory (mostly used by openssl).

If you develop an application, you can use #libcurl to gain its benefits.

Need to shape your traffic? For example bc you run a streaming service? #libcurl does that for you for all HTTP versions.