Jay Linski 🐿

395 posts

Jay Linski 🐿 banner
Jay Linski 🐿

Jay Linski 🐿

@jay_linski

›› web enthusiast with a strong interest in privacy and security

Austria Katılım Haziran 2016
286 Takip Edilen119 Takipçiler
Jay Linski 🐿 retweetledi
Fabio De Masi 🦩
Fabio De Masi 🦩@FabioDeMasi·
Man fragt sich wie die Vorratsdatenspeicherung bei einem Täter geholfen hätte, der alles öffentlich angekündigt hat und vor dem Behörden gewarnt wurden?
Julius Betschka@JuliusBetschka

"Natürlich hätte die Bundesregierung mehr tun müssen, um den "Wilden Westen" in den sozialen Medien zurückzudrängen", sagt CDU-Innenexperte Thorsten Frei im @stern-Interview, verspricht Vorratsdatenspeicherung & mehr Kontrolle der Öffentlichkeit.#Magdeburg stern.de/politik/deutsc…

Deutsch
36
95
544
19.8K
Jay Linski 🐿
Jay Linski 🐿@jay_linski·
@0xntrm The "register_argc_argv" is "On" by default in the official PHP image, since it uses the defaults: #L128" target="_blank" rel="nofollow noopener">github.com/php/php-src/bl… You have to manually set the production-ini file to be secure against this CVE. I actually documented this 6 years ago. 😅 github.com/docker-library…
English
1
0
1
44
Martin Haunschmid | @ntrm@infosec.exchange
I'm starting from the PHP docker container and copy all the relevant methods from above, get rid of dependencies and unnecessary stuff and check, whether I can control the value returned in the environment check. Please excuse my PHP, it's not my first language 😶‍🌫️
Martin Haunschmid | @ntrm@infosec.exchange tweet mediaMartin Haunschmid | @ntrm@infosec.exchange tweet media
English
2
0
0
381
Martin Haunschmid | @ntrm@infosec.exchange
Well, I'm ✨brainfried✨ from this workday anyways and it's Friday evening here, so why not analyze the newly dropped Laravel Vulnerability (CVE-2024-52301). If I got something wrong, let me know!
English
1
1
4
910
Jay Linski 🐿 retweetledi
Forum Informationsfreiheit
Forum Informationsfreiheit@amtsgeheimnisAT·
Happy Right to Know Day! Auch dieses Jahr vergeben wir „Die Mauer des Schweigens“ für „besondere Verdienste um die Verweigerung amtlicher Antworten“. 🥁 … 1/
Deutsch
1
4
10
3.7K
Adrian Reed
Adrian Reed@UKAdrianReed·
@jay_linski Yep, that was my thought too. Or alternatively, spear-phishing or direct social engineering at the hotels. E.g. an email that looks genuine, hotel logs in via a link, attacker then has password. Doesn't seem as though Booking are taking it as seriously as they should...
English
3
0
1
135
Adrian Reed
Adrian Reed@UKAdrianReed·
It appears @bookingcom has a security issue. Phishing messages via their own internal messaging system. Received this today. The phishing domain was registered today. Informed hotel, Booking .com and the domain registrar. Seems I'm not the only one (see quoted tweet below)
Adrian Reed tweet media
✨ Bianca Toeps ✨@biancatoeps

Jezus wat slecht dit, @bookingcom! Phishing via hun eigen app en mailsysteem. Niet ingetrapt gelukkig, maar wtf.

English
7
5
4
4.9K
Jay Linski 🐿 retweetledi
M.F
M.F@DerFichtl·
Pünktlich zum Staatsfeiertag ist mein kleines Sideproject: tu-felix.at fertig geworden. Analyse von 1,3 Mio. .at-Domains, IPs, Ports, DNS-Records, HTTP-Headern und HTML ...
Deutsch
1
5
16
1.3K
Jay Linski 🐿
Jay Linski 🐿@jay_linski·
I periodically run a PHP script that makes >100 HTTP requests in sequence. After upgrading from PHP 8.0 to 8.2, CPU usage and execution time more than doubled. Turns out that reusing the cURL handle (instead of doing "curl_init()" for each request) improves performance A LOT. 🚀
Jay Linski 🐿 tweet media
English
0
0
3
122
Christoph
Christoph@technicallife·
Angenommen ich hab Bock auf eine Spielkonsole aktuell, was kauft man da so?
Deutsch
2
0
0
0
Jay Linski 🐿
Jay Linski 🐿@jay_linski·
@BBleimschein Serious question: with the knowledge from today, do you still think that Bitcoin will reach $100k/BTC this year?
English
1
0
0
0
3ene
3ene@BBleimschein·
In roughly a year from now, I'm pretty certain #Bitcoin will have broken the ATH and be above $100k/BTC. Many people will be surprised, how this happened as it's in such a bear market right now. Do your own research.
English
2
0
1
0
Sebastian Bicchi
Sebastian Bicchi@secresDoge·
#ALPHV (#BlackCat) hat begonnen Daten des Landes #Kärnten zu veröffentlichen. Darunter finden sich E-Mails, Corona-Tests, jede Menge Ausweise, ausgestellte VISA(!), politische Positionspapiere, ein großer Folder zu Hypo, Bankomat-Karten und vieles mehr.
Deutsch
15
32
73
0
Aaron Grattafiori
Aaron Grattafiori@dyn___·
Now would be a great time for Russians to be able to have encrypted SNI options beyond FF+Cloudflare. The IETF seems to be plodding along given the RFC is almost four years old at this point.
English
1
0
1
0
Jay Linski 🐿 retweetledi
CCC Updates
CCC Updates@chaosupdates·
Chaos Computer Club meldet 6,4 Millionen Datensätze in über 50 Leaks. Betroffen waren staatliche Institutionen und Unternehmen (mit „Elasticsearch“, ungeschützten MySQL-Servern, Symfony Profilern) ccc.de/de/updates/202…
Deutsch
4
100
241
0
Jen Simmons
Jen Simmons@jensimmons·
Everyone in my mentions saying Safari is the worst, it’s the new IE… Can you point to specific bugs & missing support that frustrate you, inhibit you making websites/apps. Bonus points for links to tickets. Specifics we can fix. Vague hate is honestly super counterproductive.
English
1.2K
242
2.1K
0
Stephen Rees-Carter
Stephen Rees-Carter@valorin·
So, I've hacked an app, and hacker a server... what's next?
English
3
0
1
0