Matthias Luft

2.1K posts

Matthias Luft banner
Matthias Luft

Matthias Luft

@uchi_mata

Infosec Enthusiast & Practiconer. Account mostly inactive. @[email protected] https://t.co/9zKRHWb1pH

Katılım Şubat 2009
453 Takip Edilen843 Takipçiler
Matthias Luft retweetledi
Abhay Bhargav
Abhay Bhargav@abhaybhargav·
Eliminate entire classes of security flaws with these Python libraries * PyNacl for Cryptography * Pydantic for input validation * Casbin for Object/Function Level AuthZ * Passlib for Password Management
English
0
2
1
389
Matthias Luft retweetledi
Forrest Brazeal
Forrest Brazeal@forrestbrazeal·
I wanted to solve my problem, so I built a distributed app. Now problems have two I.
Forrest Brazeal tweet media
English
0
65
340
21.5K
Matthias Luft retweetledi
Supabase
Supabase@supabase·
light it up
Supabase tweet media
English
39
195
2.1K
92.6K
Matthias Luft retweetledi
Michael Schwarz
Michael Schwarz@misc0110·
With the #GhostWrite CPU vulnerability, all isolation boundaries are broken - sandbox/container/VM can't prevent GhostWrite from writing and reading arbitrary physical memory on affected RISC-V CPUs. Deterministic, fast, and reliable - no side channels. ghostwriteattack.com
Michael Schwarz tweet media
English
8
157
499
95.6K
Matthias Luft retweetledi
Matt Fuller
Matt Fuller@matthewdfuller·
AWS wishlist: a single IAM API that returns the policies attached to a user/role. Today, it involves 4-5 calls: • listRolePolicies • listAttachedRolePolicies • getRolePolicy • getPolicy • getPolicyVersion
English
7
3
39
3.1K
Matthias Luft retweetledi
sergey bratus
sergey bratus@sergeybratus·
It's great to see Multiplier by @trailofbits being open-sourced! github.com/trailofbits/mu… I believe it exemplifies the kind of foundational, next-generation tools we need for proper software understanding, maintenance, and sustainment.
English
1
33
129
14.2K
Matthias Luft
Matthias Luft@uchi_mata·
@cji You realize the real boomer thing was taking the quiz, right? 😀
English
1
0
4
25
Matthias Luft retweetledi
lcamtuf
lcamtuf@lcamtuf·
OpenSSH bug: yes, it takes forever to exploit against a single host. But you're mostly waiting for a timeout, so you can massively parallelize across internet targets w/o needing a botnet. Assume that this - and not targeted exploitation - is going to be the initial approach.
English
4
34
144
47.8K
Matthias Luft retweetledi
Rory McCune
Rory McCune@raesene·
The next part of our #Kubernetes #Security fundamentals video series is out now! This time we're looking at the Kubelet API. talking about the ports it makes available and some of the potential for information leakage. youtu.be/OdkFPL7d73E?si…
YouTube video
YouTube
English
1
14
31
1.6K
Matthias Luft retweetledi
Charlie Miller
Charlie Miller@0xcharlie·
Regarding the SSH bug 1) First OpenSSH vuln discovered in almost 20 years - wow 2) Bug was (re)introduced almost 4 years ago. So remote root in OpenSSH for 4 years and nobody found it? 3) Exploit takes hours/days to run. Watch your logs!
English
7
111
454
68.1K
Matthias Luft retweetledi
Colin Percival
Colin Percival@cperciva·
If you launch a new FreeBSD (13.2|13.3|14.0|14.1)-RELEASE instance and don't change the default behaviour via EC2 user-data, it will download and install the patch for this before sshd is launched. I decided many years ago that installing updates on first boot was important.
Colin Percival@cperciva

I should probably provide context for people who haven't seen it yet: A pre-auth RCE in OpenSSH was announced a short time ago. Exploitable on Linux; not exploitable on OpenBSD; unclear if exploitable on FreeBSD but we have an advisory out just in case. qualys.com/2024/07/01/cve…

English
3
12
50
3.7K
Matthias Luft retweetledi
Colin Percival
Colin Percival@cperciva·
Today seems like a good day to mention that on my servers I use spiped to protect access to OpenSSH -- you can't even send a single byte to sshd unless you have the spiped secret key. daemonology.net/blog/2012-08-3…
English
2
28
96
13K
Matthias Luft retweetledi
fwd:cloudsec
fwd:cloudsec@fwdcloudsec·
All the talks from last week have been published to our Youtube channel! Here's a playlist with all of them: youtube.com/playlist?list=…
English
0
20
50
4.3K
Florian Magin
Florian Magin@0x464D·
Not sure what someone from 30 years ago would consider the greater miracle: - Cheap Affordable Wifi on a transatlantic flight that's sufficient to use a web based LaTeX editor like Overleaf - existence of Overleaf, which makes the collaborative LaTeX experience almost tolerable
English
1
0
0
141