Kissaki
@Kissaki@programming.dev
- Comment on CISA: Most exploited vulnerabilities should have been eradicated decades ago 1 week ago:
Looking into the mentioned unforgivable vulnerabilities and stubborn weaknesses published by CISA:
Unforgivable Vulnerabilities (PDF)
Given the above criteria, following are some candidates for unforgivable vulnerabilities that satisfy all (or most) of the criteria for an unforgivable vulnerability. […]
- Buffer overflow using long strings of
“A”characters in:- a. Username/password during authentication
- b. File or directory name
- c. Arguments to most common features of the product or product class
- XSS using well-formed
<script>tags, especially in the:- a. Username/password of an authentication routine
- b. Body, subject, title, or to/from of a message
- SQL injection using
’in the:- a. Username/password of an authentication routine
- b.
“id”or other identifier field - c. Numeric field
- Remote file inclusion from direct input such as:
- a.
include($_GET[‘dir’] . “/config.inc”);
- a.
- Directory traversal using
“…/…”or“/a/b/c”inGETorSENDcommands of frequently-used file sharing functionality (e.g., aGETin a web/FTP server, or a send-file command in a chat client) - World-writable critical files:
- a. Executables
- b. Libraries
- c. Configuration files
- Direct requests of administrator scripts
- Grow-your-own crypto
- Authentication bypass using
“authenticated=1”cookie/form field - TOCTOU race condition – symlink
- Privilege escalation launching
“help”(Windows) - Hard-coded or undocumented account/password
- Unchecked length/width/height/size values passed to
malloc()/calloc()
Stubborn Weaknesses
CWE-ID Description 2023 Rank CWE-787 Out-of-bounds Write 1 CWE-79 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) 2 CWE-89 Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) 3 CWE-416 Use After Free 4 CWE-78 Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) 5 CWE-20 Improper Input Validation 6 CWE-125 Out-of-bounds Read 7 CWE-22 Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) 8 CWE-352 Cross-Site Request Forgery (CSRF) 9 CWE-476 NULL Pointer Dereference 12 CWE-287 Improper Authentication 13 CWE-190 Integer Overflow or Wraparound 14 CWE-502 Deserialization of Untrusted Data 15 CWE-119 Improper Restriction of Operations within Bounds of a Memory Buffer 17 CWE-798 Use of Hard-coded Credentials 18 - Buffer overflow using long strings of
- Comment on CISA: Most exploited vulnerabilities should have been eradicated decades ago 1 week ago:
It’s not the exact thing; it just makes it worse. For many people, it’s personality and psychology; they go the path of least resistance and don’t care about much besides their main goals. Whether you embed it in capitalism or not, these fundamental causes remain.
Do you have an economic or social system in mind where it would be solved or better?
- Submitted 1 week ago to cybersecurity@infosec.pub | 0 comments
- Comment on Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now! 1 month ago:
7-Zip 26.02, released 2026-06-25, undisclosed vulnerability fixes. Quite a while ago, if you keep stuff up to date.
They mention Landon Peng as the one finding the vulnerability, but their blog has only a post about a vulnerability fixed in 25.01.
- Comment on GitHub’s AI Agent Tricked Into Leaking Private Repository Data 2 months ago:
The word “additionally” evading guardrails is comical.
You need structural separation. Separate agents for public vs private. Prompt or context washing is not enough.
- Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks – Krebs on Securitykrebsonsecurity.com ↗Submitted 3 months ago to cybersecurity@infosec.pub | 0 comments
- Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada – Krebs on Securitykrebsonsecurity.com ↗Submitted 3 months ago to cybersecurity@infosec.pub | 0 comments
- Comment on The Newest Instagram "Exploit" is the Goofiest I've Seen 3 months ago:
the original 2FA gets thoroughly bypassed in the process
arstechnica reports that 2FA protects you, also KrebsOnSecurity
On May 31, the pseudonymous open source intelligence researcher ZachXBT posted on X about how “the Meta AI support is garbage and has lots of access perms which allowed you to reset passwords to any user without 2FA and did not verify who you are.”
ambiguous formualtion, can be read both ways; but much more explicit:
The hackers reported their exploit failing against any accounts that had enabled multifactor authentication (MFA), including the “least robust form of MFA that Instagram offers” in the form of one-time codes sent through SMS, according to KrebsOnSecurity.
Securing your various online accounts means taking full advantage of the most secure form of multi-factor authentication (MFA) offered (such as a passkey or security key). In this case, even using the least robust form of MFA that Instagram offers — a one-time code sent via SMS — likely would have blocked the exploit: The hackers who released the video on Telegram said their exploit failed to work against any accounts that had MFA enabled.
- Comment on The Newest Instagram "Exploit" is the Goofiest I've Seen 3 months ago:
I thought multiple exits and retiring in my mid 30s
damn
- Comment on Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked 3 months ago:
I’ve seen a video about an AI company trying out an AI-managed vending machine. It went as well as you would expect. Fun for employees to explore and hack, of course.
- Comment on [deleted] 3 months ago:
Looks like the source - quoted user’s post on !security@lemmy.ml - has been removed. Their profile still lists the comments they posted there.
- Backdoored Cemu release linked to TanStack and Mistral supply chain campaign | Datadog Security Labssecuritylabs.datadoghq.com ↗Submitted 3 months ago to cybersecurity@infosec.pub | 0 comments
- Comment on Vulnerability Garden 4 months ago:
FTP PASV “Pizza Thief” Exploit
😄
- Comment on FBI Extracts Suspect’s Deleted Signal Messages Saved in iPhone Notification Database 4 months ago:
Seems you don’t know how anything on Linux
What makes you think that is what they think? They referenced other people. They didn’t make any claims themselves or made any indications that they agree with those “flipping out” (who misunderstand).
I read it as the opposite. They know and criticize those who don’t and flip out because of that.
- Comment on Adobe modifies hosts file to detect whether Creative Cloud is installed 5 months ago:
Interesting, clever technical workaround for (potentially) real user benefit. But still, they should never do that. Working around safeguards and system component borders for user convenience is a very bad idea and practice.
- Submitted 5 months ago to cybersecurity@infosec.pub | 2 comments
- Comment on 45,000 malicious IP addresses taken down in international cyber operation 5 months ago:
Participating countries and territories: Angola, Argentina, Austria, Bahrain, Bangladesh, Bolivia, Bosnia and Herzegovina, Botswana Brazil, Brunei, Burkina Faso, Burundi, Cameroon, Colombia, Democratic Rep of Congo, Eritrea, Eswatini, France, Gambia, Georgia, Greece, Guatemala, Guinea, Guinea Bissau, Guyana, Honduras, Iceland, India, Iraq, Ireland, Israel, Japan, Jordan, Kazakhstan, Kenya, Kuwait, Latvia, Lebanon, Lesotho, Liechtenstein, Macao (China), Madagascar, Malaysia, Maldives, Moldova, Mongolia, Niger, Nigeria, North Macedonia, Oman, Pakistan, Palestine, Paraguay, Philippines, Poland, Qatar, Singapore, South Africa, South Sudan, Spain, Sri Lanka, Switzerland, Tanzania, Togo, Türkiye, Uganda, Ukraine, United Arab Emirates, United Kingdom, Venezuela, Zambia, Zimbabwe.
Impressive list of countries participating
- Comment on Russian-backed hackers have gained access to Signal and WhatsApp accounts used by officials, military personnel and journalists, as claimed by two intelligence agencies in the Netherlands. 5 months ago:
Classic phishing. Secure channels are only as good as the gate and key handling surrounding them.
For official org-based accounts like that, I could imagine a messaging system where you can only see and share security codes with a second-person factor. If the user wants to access it, at least another authorized trained person must take part, acknowledge, and authorize the action. As long as users can access key information relatively easily, they are phishable.
- Comment on Password managers less secure than promised 6 months ago:
It is impossible for me to remember all my passwords. Maybe I have more accounts than other people. I remember the most important ones, amongst them a very long password manager DB password that is annoying to enter, especially on mobile.
First time I set up keepass I forgot the password. I still have the DB file without access. But the second time, I was more serious and committed to it, and made sure to remember and use the password. 😅
- Comment on The Shadow Campaigns: Uncovering Global Espionage 6 months ago:
It’s crazy how border control and sanctions are normalized political topics, yet I’ve never heard suggestions of applying that to the internet.
Suppressive regimes often control their network and network borders. Everyone outside not doing so is quite asymmetric.
- Comment on Breaking Bitlocker - Bypassing the Windows Disk Encryption 7 months ago:
Thank you for sharing. Very interesting.
We’re currently evaluating and rolling out encryption at work, so being informed about the limits of these setups is quite good - even if it’s not actually my task to work on those.
- Comment on Microsoft Gave FBI BitLocker Encryption Keys, Exposing Privacy Flaw 7 months ago:
It’s possible for users to store those keys on a device they own, but Microsoft also recommends BitLocker users store their keys on its servers for convenience.
Pretty obvious that if you hand over the (recovery) keys that they’d follow court orders.
Of course, the criticism about defaults is warranted. At the same time, even outside of control concerns, it’s fairly obvious why Microsoft would choose user convenience and ability to recover data over loss of data.
It should be a well informed choice that makes the risks clear when setting it up.
- Submitted 7 months ago to cybersecurity@infosec.pub | 6 comments
- Submitted 9 months ago to cybersecurity@infosec.pub | 0 comments
- Comment on Hackers Replace 'm' with 'rn' in Microsoft(.)com to Steal Users' Login Credentials 9 months ago:
I expect some hot Java code on that website 😏
- Comment on Hackers Replace 'm' with 'rn' in Microsoft(.)com to Steal Users' Login Credentials 9 months ago:
rnicrosoft.corn🌽 - Comment on 3.5 Billion Accounts: Complete WhatsApp Directory Retrieved and Evaluated 9 months ago:
We have found no evidence of malicious actors abusing this vector"
“We see no evidence of that which we do not monitor.”
These press releases/responses seem to never include “we track x and y and see no evidence”. I can only assume the worst.
- Submitted 9 months ago to cybersecurity@infosec.pub | 1 comment
- Comment on What are You Working on Wednesday 9 months ago:
I always read the weekly post title and am tempted to write and comment. I’ve written an entire post before. But then I notice it’s in c/cybersecurity - which my work is not in specifically. 😅
- Submitted 9 months ago to cybersecurity@infosec.pub | 0 comments