Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
terom
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
121.
▲
by
terom
5y ago
If the Mozilla telemetry service can trigger a HTTP/3 DoS bug, then I would assume that any server can trigger the same HTTP/3 DoS bug. I think I'll keep http3 disabled for now, until this is figured out and fixed. EDIT: htt
122.
▲
by
terom
5y ago
Did you have telemetry disabled? It sounds like users with telemetry disabled were not affected. EDIT: https://bugzilla.mozilla.org/show_bug.cgi?id=1749908#c19 this is seemingly not the case, other HTTP/3 services can
123.
▲
by
terom
5y ago
But your infected lungs will be very simple and cheap to analyze, because they will glow in the dark.
124.
▲
by
terom
5y ago
Ansible connection plugins provide the same, e.g. https://docs.ansible.com/ansible/latest/collections/communit...
125.
▲
by
terom
5y ago
This feels oddly relevant as someone just starting to port an ESP8266-RTOS-SDK based application to ESP-IDF (ESP-32), and wondering what the best strategy for targeting both platforms is going to be. The vanilla `taskENTER_CRITICAL()` [1] v
126.
▲
by
terom
5y ago
Particularly with the `${ctx:...}` vs `%X{...}` distinction. For a plain DoS, which only affects `${ctx:...}` usage? I wouldn't panic, fix it if someone manages to actually exploit it... It's goods new so far that with more people
127.
▲
by
terom
5y ago
For most public-facing deployed services, I tend to run docker in `--iptables=false` mode with `--net=host` containers. Then you can just use normal iptables INPUT rules with your choice of firewall tooling. Works great with IPv6 as well, a
128.
▲
by
terom
5y ago
That applies to the <2.15 mitigation for disabling message lookups. That mitigation for message lookups does not affect context lookups. Nor does the 2.15 fix for disabling, nor the 2.16 fix for removing message lookups. But 2.16 disable
129.
▲
by
terom
5y ago
They still work in the CVE-2021-45046 context lookup vector.
130.
▲
by
terom
5y ago
Further details on the most relevant part here: https://github.com/apache/logging-log4j2/pull/608#issuecomme... Applications using log4j pattern layouts including `${ctx:...}` lookups with versions < 2.15
131.
▲
Log4j remains vulnerable when using attacker-controlled thread context lookups
(github.com)
2 points
by
terom
5y ago
|
0 comments
132.
▲
by
terom
5y ago
Per ESA-2021-31 [1] the common mitigation is not sufficient for logstash: > The widespread flag -Dlog4j2.formatMsgNoLookups=true is NOT sufficient to mitigate the vulnerability in Logstash in all cases, as Logstash uses Log4j in a way wh
133.
▲
by
terom
5y ago
yay! Now the same for Hetzer Cloud servers as well. Could they get the price for an IPv6-only cloud instance down to 2-3€/month + VAT?
134.
▲
by
terom
5y ago
Was X some randomly generated number, not based on any actual inventory?
135.
▲
by
terom
5y ago
But 254 in hexadecimal is 0xfe :/ 0x0254 is 596, or .2.84 in IPv4 notation.
136.
▲
by
terom
5y ago
I wonder what this means. Are they going to go the RedHat route and replace Docker with something else? The following features will be introduced to Amazon Linux 2022 before it is released for general availability. * Container runt
137.
▲
by
terom
5y ago
I don't think so, https://dnsviz.net/d/spotify.com/YHUfXQ/dnssec/ shows that spotify.com resolved to the same 35.186.224.25 as it does now.
138.
▲
by
terom
5y ago
But the Chinese fakes still have plenty of availability :)
139.
▲
by
terom
5y ago
Choice quotes from their PR piece: https://www.hashicorp.com/case-studies/roblox > We didn’t want to choose any technology that requires the company to drive deep expertise, almost to the point where you have to be
140.
▲
by
terom
5y ago
The rationale in OMB memo M-18-23 for withdrawing the DNSSEC requirement in M-08-23 doesn't seem very convincing: we don't need this anymore because everyone should already have DNSSEC by now? > M-08-23, Securing the Federal Go
141.
▲
by
terom
5y ago
A good question, and apparently enough to elict a response: No! > This issue was caused by our own change and not related to any third-party DNS software and services.
142.
▲
by
terom
5y ago
https://dnsviz.net/d/slack.com/YVXX_g/dnssec/ the dnsviz analysis showing the slack.com zone DNSKEY existing at 12:55, followed by the the .com zone DS record at 15:30. However, the next analysis at 17:2
143.
▲
by
terom
5y ago
It's worth noting that the AWS EC2 99.99% SLA is a regional SLA, i.e. it only covers a situation where multiple AZs are down simultaneously. One AZ going down is not covered by the 99.99% SLA. AFAIK there isn't any per-AZ SLA, onl
144.
▲
by
terom
5y ago
https://mobile.twitter.com/Namecheap/status/1440896036487245... indeed bitcoin.org. 86400 IN NS dummysecondary.pleasecontactsupport.com. bitcoin.org. 86400 IN NS
145.
▲
by
terom
5y ago
I wonder if the people commenting "I want one" would still agree if they knew how much it would cost to produce and assemble in small quantities. Would 1000€/piece even be enough to cover costs?
146.
▲
by
terom
5y ago
This is a good change. The default CREATE privileges on the `public` schema are very surprising.
147.
▲
by
terom
5y ago
https://www.python.org/dev/peps/pep-0420/ Python 3.3+ no longer requires the `__init__.py` file to make a package. > You would then `import .foo` The `import .foo` is a syntax error, and `from . import foo
148.
▲
by
terom
5y ago
So if AWS ALB HTTP/2 listener -> HTTP/1.1 target downgrade was vulnerable, and the recommendation is to use HTTP/2 end to end... am I reading the AWS docs [1] correctly that ALB only supports HTTP/2 -> HTTP/1
149.
▲
by
terom
5y ago
http://webcache.googleusercontent.com/search?q=cache%3Ahttps... Google cache still has the malicious package visible FWIW > This Module Optimises your PC For Python
150.
▲
by
terom
5y ago
My understanding of the comments is that the week 2180 code was supposed to be 2022-12-31, but the code is actually 2021-10-24 (end of week 2180). In other words, the heading is correct.
More ›