bagder, (edited )
@bagder@mastodon.social avatar

I was reminded of the great security fix of 2019

kfh,
@kfh@chaos.social avatar

@bagder This is sorta what imgur does for wget as well, to "stop" scraping I guess...

(it has returned 429 "too many requests" every time I've tried, so I assumme it's an ingress rule for the user agent)

bagder,
@bagder@mastodon.social avatar

I posted this image on LinkedIn as well, and the stats there tells me that Cisco is in fact now the third most common employing company among the viewers... (only beaten by AWS and Microsoft)

https://www.linkedin.com/posts/danielstenberg_curl-activity-7185597818894512130-kHFS

spmatich,
@spmatich@ioc.exchange avatar

@bagder does this qualify as code bloat? the user agent header is completely arbitrary and can be set to anything.
I mean why single out curl. Shouldn’t the nmap default user agent be in there too? etc etc

bagder,
@bagder@mastodon.social avatar

@spmatich they singled out curl because the exploit proof of concept used curl. They stopped the example command line from working.

spmatich,
@spmatich@ioc.exchange avatar

@bagder so the exploit just needs an update to include setting the user agent header to something else right, and it could be one of many many many different strings.

bagder,
@bagder@mastodon.social avatar

@spmatich ... and that is exactly why the "fix" is so fun!

fnova,
@fnova@mastodon.social avatar

@bagder lol

Okanogen,
@Okanogen@mastodon.social avatar

@bagder
Bravo.
Elmer Fudd level.

iamwaseem,

@bagder 🥴

waynedixon,
@waynedixon@mastodon.social avatar

@bagder @briankrebs I’ve been selectively blocking all sorts of stuff on some servers like that.

alex,
@alex@gleasonator.com avatar

@bagder But you see, curl -A "anonymous" is now considered unauthorized access of a computer system and is illegal according to the Computer Fraud and Abuse Act.

mentallyalex,
@mentallyalex@beige.party avatar

@bagder :blobcatfearful:

psycodepath,
@psycodepath@mastodon.social avatar

@bagder unhackable

hnapel,
@hnapel@mastodon.social avatar

@bagder

I looked up the curl man page, especially the example for changing the user agent:

Example:
curl -A "Agent 007" https://example.com

😎

CodingThunder,
@CodingThunder@mastodon.social avatar

@bagder This is ofcourse going the obvious solution when your blog's "network engineer" tag is filled with PR BS:

CW: everything on this blog is bullshit, and unrelated to what the tag name is

https://blogs.cisco.com/tag/network-engineer

colin_mcmillen,
@colin_mcmillen@piaille.fr avatar

@bagder We need more context 😅

bagder,
@bagder@mastodon.social avatar

@colin_mcmillen it was their fix for this reported security problem: https://www.redteam-pentesting.de/en/advisories/rt-sa-2019-003/

colin_mcmillen,
@colin_mcmillen@piaille.fr avatar

@bagder 😂 thanks!

c0dec0dec0de,
@c0dec0dec0de@hachyderm.io avatar

@colin_mcmillen @bagder wait, you can dump the config without authentication of any kind, which includes the devices password hashes, and somehow you can just pass those hashes back to authenticate to the device?
No, that all tracks with the sophistication of this “fix”.

c0dec0dec0de,
@c0dec0dec0de@hachyderm.io avatar

@colin_mcmillen @bagder
✅ don’t store passwords in plaintext
❓ don’t transmit credentials in the clear
❌ prevent replay attacks

foosel,
@foosel@chaos.social avatar

@bagder OMG, did they really pull that off? That's... amazing 😂

bagder,
@bagder@mastodon.social avatar

@foosel that's the genuine "fix" for a reported security problem against some of their devices at the time, yes indeed

nullcolaship,

@foosel @bagder I can well believe it, from the company that once broke their website by somehow removing every lowercase "t" from their HTML... Though that was about a decade earlier!

image/jpeg

root42,
@root42@chaos.social avatar

@nullcolaship @foosel @bagder "Skip o Conen" sounds like an Irish talk show host.

cd_home,

@root42 @nullcolaship @foosel @bagder Interesting that it still renders as a website of sorts with all letters 't' removed. I wonder which letters are the most redundant ones in this metric.

mausmalone,
@mausmalone@mastodon.social avatar

@cd_home @root42 @nullcolaship @foosel @bagder It is pretty funny - it's just that most of the HTML tags for content (h1-6, a, p, div) don't have the letter t, while a lot of stuff in the head (title, script, style) do.

Surely any tables on the page are ruined, though.

root42,
@root42@chaos.social avatar

@mausmalone @cd_home @nullcolaship @foosel @bagder one more reason to use iframes!

kohelet,
@kohelet@mstdn.social avatar

@nullcolaship

@foosel @bagder
why would they wanna do that in the first place?

gilesdring,
@gilesdring@mastodon.me.uk avatar

@nullcolaship @foosel @bagder Just think of all those tabs they’d have been able to remove if they’d escaped their regex properly.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • cisco
  • DreamBathrooms
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • mdbf
  • GTA5RPClips
  • JUstTest
  • ethstaker
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • tacticalgear
  • anitta
  • provamag3
  • Leos
  • cisconetworking
  • megavids
  • lostlight
  • All magazines