Show newer
I made a list of cool things people do with their blogs: https://brainbaking.com/post/2022/04/cool-things-people-do-with-their-blogs/
Hopefully it'll inspire some.
More suggestions welcome!

Fedi, the great thing about posting a #drawing like this around here is that if we play "name that teletype" I'll get a correct answer in < 10 minutes, very likely from one of my #SDF comrades.

Posted this on Instagram a while ago and ... it's a different crowd over there. :)

#illustration #cartoon #unix #teletype #JurassicPark

you cannot conformantly parse email addresses with regular expressions

BSides SATX conference talk proposal submitted - A Log4Shell Practice Exploitation Range in the Cloud. Fingers crossed to share some cool fun stuff.

Done in Blender's Grease Pencil at Hack and Craft. The first draft was here: octodon.social/@cwebber/107906

This is the first 2d animation thing I've ever done. I feel pretty good about it!

Show thread

I made a current sensor to email me when a heater was not working at a remote location.

blog.notmet.net/2022/02/power-

> Putin orders "peacekeeping operation" in eastern Ukraine's two breakaway regions

what do i even say

(and yes, it changes nothing, everyone knew they were already there, yet is changes everything too)

Dang. Sorry, gotta share this one. My first in only two.

247 2/6

🟩🟨⬛🟨🟨
🟩🟩🟩🟩🟩

Gotta check this out as a replacement for Adtiga. I want a music streaming platform that can feed a Subsonic protocol app from s3 navidrome.org/about/

@healyn you know how the web site start with www. that is web 3. there are three w, one for each web

Guacamole is the interface I deploy to let folks interact with the range easily. It is not easy to configure automatically... There's a simple user config file, but it is intentionally extremely simple. If you want to deploy Guacamole via configuration as code, you need something more powerful. I created this to do that:
github.com/kc0bfv/guacamoleRES

Show thread

Jetty is kinda vulnerable... It doesn't use log4j logging by default, but it does come with a drop-in logging replacement module that uses log4j. By default... Even the current versions of Jetty for download will, when enabling this module, download vulnerable log4j. The people making Jetty don't seem to realize this yet. I have no idea if anyone uses the replacement module. But I did!

Show thread

Solr is vulnerable if you grab the right version from Docker Hub (8.8.0 works nicely). But - the Java executable in there is from within the last few years, and those all disallow remote code includes via JNDI... So by default it's not going to give you RCE - at least not with the method commonly cited.

Show thread
Show older
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.