Eric Sauvageau

7.4K posts

Eric Sauvageau banner
Eric Sauvageau

Eric Sauvageau

@RMerlinDev

IT consultant and computer psychiatrist. Asuswrt-Merlin lead developer.

Canada Katılım Ağustos 2012
13 Takip Edilen10.4K Takipçiler
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
@teo_tsirpanis @Itsfoss Also, I haven't looked at it in details, but it wouldn't surprise me if SOC-2 compliance might make it hard or impossible to use an ACME client.
English
0
0
0
21
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
@teo_tsirpanis @Itsfoss As I said, government and ecommerce, large corporations. They often include financial insurance on top of everything. These types of certificates (I also forgot to mention OV) are for specific types of customers. Might not be you or me, but there are still customers for it.
English
1
0
0
52
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
After a few URL switches, the dnsmasq author now decided to put a "roadblock" in front of the git repo specifically for AI scraper bots. The FOSS community is visibly getting tired of the abuse from these AI providers. I have Cloudflare rejecting AI scrapers as well now.
English
0
1
21
897
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
@ronniepapa3 @_JordanDecker None of these language warriors would be brave enough to tell that to his face, let's be honest :) As for Saku... He already learned a second language (English). How many more to please EVERYBODY?
English
0
0
0
18
ronniepapa
ronniepapa@ronniepapa3·
@_JordanDecker That's a bit unfair to Weber. Always conducted himself with class and commitment.
English
1
0
2
66
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
@Diss0lution For many years now, the Office 365 installer is broken in French, instead of showing something like "90% complété" in the system notification icon, it says "90lformat error! complété" - incorrectly parsing the percent sign as a parameter. Trillon dollars company at work.
English
0
0
8
373
𝕯issolution
𝕯issolution@Diss0lution·
Windows is absolute trash ep 852 : when you configure Windows DHCP Server in french, it adds commas in the middle of error messages to the CSV log file, breaking the whole CSV :
𝕯issolution tweet media
English
64
306
6.1K
265.6K
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
@Love2Code I can get HD audio on a few very select calls, typically on my cell - it depends who I am calling from it. While my VoIP provider does support HD codecs, the remote end virtually never supports it, so they revert back to old PSTN AM radio quality.
English
0
0
0
138
Maxime Chevalier
Maxime Chevalier@Love2Code·
Hard to understand why, in 2026, audio quality on phone calls is so bad. Super heavy compression, ultra low bitrates, often hard to make out what people are saying... In a world where everything works over IP, why is the default 8 kilobits per second or some shit?
English
116
12
617
73.9K
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
Two weeks later, @Google might finally be fixing the broken Gmail Android app? google.com/appsstatus/das… The bigger they are, the slower they are at fixing critical issues in their software. Users should expect better.
English
0
0
6
821
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
Dark mode is coming to the GT-BE19000AI dashboard.
Eric Sauvageau tweet media
English
0
1
16
1.1K
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
@thurrott I know the site you are referring to, and I fully agree. Their article titling has been absolute garbage for a few years now. Which is a shame, I have been following that website for 15+ years now. Increasingly debating stopping to follow them at this stage.
English
0
0
1
526
Paul Thurrott
Paul Thurrott@thurrott·
"If you downloaded this popular software recently, you might have installed malware" And if you knew how to write a headline that wasn't clickbait, I wouldn't be removing you from my feed. Also, if you knew the definition of the word popular. Assclowns.
English
5
0
34
4.3K
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
@davidtranjs @QuinnyPig @Cloudflare A 2FA stored in a password manager is no longer a 2FA. Compromising that 1password account gives the hacker all the necessary keys to your kingom. 2FA does not belong in a password manager (unless it's a separate one).
English
0
0
0
31
David Tran
David Tran@davidtranjs·
@QuinnyPig @Cloudflare I purchase 1Password just for not select saved password and manual fill 2FA code when using Cloudflare Dashboard
English
1
0
0
477
Corey Quinn
Corey Quinn@QuinnyPig·
I wish I could sign into @cloudflare with a passkey only. No "type username and password, then for some reason manually check the box that says I'm not a robot," just the cryptographic handshake then done.
English
10
1
191
22.8K
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
@jrk_811 In Entra ID (Identity on the Admin portal), on the Properties tab of that page: #view/Microsoft_AAD_IAM/TenantOverview.ReactView?Microsoft_AAD_IAM_legacyAADRedirect=true" target="_blank" rel="nofollow noopener">entra.microsoft.com/#view/Microsof…
English
1
0
1
30
Nihan
Nihan@jrk_811·
@RMerlinDev Could you please share the resource link?
English
1
0
0
19
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
I finally found a solution to #Sharepoint #Onedrive sync folder using the org name for the local folder (problematic with extremely long org names). You can no longer rename the org under Org Settings. But you can rename it within Entra ID. That gets used for the folder name.
English
2
1
4
937
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
@yukizokin I've done some 80HC196 (Intel microcontroller) in college, in addition to 6809 and 68000. Intel ASM looked so stupid compared to Motorola, yet here we are today with Motorola CPUs being dead.
English
1
1
6
423
ゆきぞー
ゆきぞー@yukizokin·
自分は8086でプログラムを組んだことがないのだけど、68000でアセンブラでもCでもどちらで書いていても、いつも『セグメントがなくて気持ちいなぁ』となぜか思ってた。
日本語
21
22
201
11.5K
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
Why isn't this documented anywhere? I spent hours doing online searches, they all say "Sorry, can't be done anymore."
English
0
0
0
438
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
@catlikecoding My hoster for asuswrt-merlin.net pre-emptively blocked WHM access right after the reveal, until the patch got published and deployed on their servers. Many providers with slack update practices are going to get owned.
English
1
0
2
261
Jasper Flick
Jasper Flick@catlikecoding·
Why my websites are down: Basically my web host has been obliterated by a cPanel/WHM exploit which took out many websites worldwide. All I can do is wait until they clean things up and then I'll restore the websites.
English
7
2
59
4K
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
@vxunderground cPanel released a script that reveals exploit attempts (and whether they succeeded). In two days I got 83 attempts on my business server, and a bit over 50 on a customer's own server. Thankfully we both got patched quite early. This has the potential to compromise MANY sites.
English
0
0
4
379
vx-underground
vx-underground@vxunderground·
> new cpanel cve thingie > proof of concept released > neat > check on internet degenerates > tons of united states gov thingies compromised > tax places compromised > another day of internet schizophrenia
English
32
124
1.8K
51.7K
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
What a week for security. Bitwarden supply chain compromise, Linux kernel LPE, cPanel password bypass, SNBForums and Linksysinfo flooded by (AI) bots, Ubuntu website also being DDoSed today... The Internet is a complete mess at this stage.
English
0
3
10
778
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
I checked my business server today. Since I patched two days ago, 83 attempts were made to exploit this. Thankfully, most servers should be set to automatically update themselves. If you run an EOL version or you disabled auto updates... you're boned.
International Cyber Digest@IntCyberDigest

🚨 BREAKING: cPanel and WHM, the control panels behind an estimated 70+ million websites, have a critical security flaw that lets anyone become root admin without a password. CVE-2026-41940 affects every supported version. It’s already being exploited in the wild. watchTowr Labs published the full attack today, after the hosting company KnownHost confirmed the bug was already being used to break into a significant chunk of the internet. If you've never heard of cPanel: it's the dashboard that hosting providers and millions of website owners use to manage their servers, domains, email accounts, databases, and SSL certificates. WHM is the admin version that controls the entire server. If someone gets root access to WHM, they get the keys to the kingdom and to every apartment inside it. How the attack works, in plain English: 🔴 Step 1: The attacker sends a deliberately wrong login. cPanel still creates a temporary "you tried to log in" record on disk and gives the attacker a cookie tied to it. 🔴 Step 2: The attacker tweaks the cookie to disable cPanel's password encryption. Normally cPanel encrypts the password field on disk. With one small change to the cookie, cPanel just stores it as plain text instead. 🔴 Step 3: The attacker sends a fake login attempt where the password field secretly contains hidden line breaks. cPanel does not strip these line breaks out, so they get written straight to the session file. Each line break creates a brand new fake record. The attacker uses this to inject lines that say "this user is root" and "this user already authenticated successfully." 🔴 Step 4: The attacker visits one more random page on the site to nudge cPanel into re-reading the file. cPanel then promotes the injected fake lines into its main session memory. 🔴 Step 5: On the next request, cPanel sees a flag that says "this user already passed the password check." cPanel trusts that flag, skips checking the actual password, and lets the attacker in as root. From start to finish, the attack takes a handful of HTTP requests. If you run cPanel or WHM, the patched versions are: 🔴 cPanel/WHM 110.0.x → 11.110.0.97 🔴 cPanel/WHM 118.0.x → 11.118.0.63 🔴 cPanel/WHM 126.0.x → 11.126.0.54 🔴 cPanel/WHM 132.0.x → 11.132.0.29 🔴 cPanel/WHM 134.0.x → 11.134.0.20 🔴 cPanel/WHM 136.0.x → 11.136.0.5 If your version is older than these, assume someone has already broken in and act accordingly. Patch right now, then rotate every password and key the server touched: root passwords, API tokens, SSL private keys, SSH keys, mail passwords, and database passwords.

English
3
3
40
6.5K
Eric Sauvageau
Eric Sauvageau@RMerlinDev·
@thurrott If only they included the New Outlook in that list of apps that were taken out and replaced by something end users actually want to use. (And yes, a list would be nice)
English
0
0
3
688