@_xhr_@cybervillains.com
@_xhr_@cybervillains.com avatar

_xhr_

@_xhr_@cybervillains.com

OpenBSD user ● DragonFly BSD committer (retired) ● InfoSec and CCC for > 25y ● Pronouns: he/him

finger m@f.xosc.org for more information

My presence in gemini: gemini://xosc.org

Posts are deleted after 2 years!

This profile is from a federated server and may be incomplete. Browse more on the original instance.

_xhr_, to random
@_xhr_@cybervillains.com avatar

Migrated one of my #OpenBSD VMs to @OpenBSDAms . Super fast setup process, well documented and works like a charm. 100% in line with OpenBSD's sane defaults.

Kudos to @mischa and team!

_xhr_, to linux
@_xhr_@cybervillains.com avatar

TIL that you can redirect clear(1)'s standard output to a file and the use cat on the file to clear the screen.

$ clear > foo
$ cat foo

#unix #bsd #linux #openbsd

_xhr_,
@_xhr_@cybervillains.com avatar

@apodoxus hehe, i used hexdump and did exactly the same :)

_xhr_, to infosec
@_xhr_@cybervillains.com avatar

Another vulnerability with a name and a logo: TerraPin. This time on #SSH.

While this sounds scary, the "Terrapin attack requires an active Man-in-the-Middle attacker, that means some way for an attacker to intercept and modify the data sent from the client or server to the remote peer."

#OpenSSH on #OpenBSD already received a syspatch.

https://terrapin-attack.com/ #infosec

_xhr_, to random
@_xhr_@cybervillains.com avatar

In December, I usually share an #OpenBSD screenshot showing #xsnow

This year, I am showing a screenshot (made with grim) of #Wayland on OpenBSD. It shows #sway, foot as terminal, mpv and Firefox (although no idea if native of with XWayland). Setup on -current was simple and runs stable so far. Kudos to @matthieu and all other devs involved!

I'll stick with X for now since the WL tools miss the usual security mitigations like pledge and unveil.

_xhr_, to infosec
@_xhr_@cybervillains.com avatar

This pull request clearly shows what's currently wrong in the #infosec community.

Another misaligned CVE with a CVSS score of 9.8 for code in a contrib/ dir that is not even build by default shows up in commercial vulnerability scanners and suddenly random people press the maintainer to release an updated version.

https://github.com/madler/zlib/pull/843

_xhr_, to privacy
@_xhr_@cybervillains.com avatar

Awesome. Just detected the following #privacy preserving gems in #Firefox's 120 release notes. Use Firefox, use an ad blocker, stay safe online.

fitheach, to movies
@fitheach@mstdn.io avatar

We all know that the US is stuck using US customary units. Except, in the movies, major criminals always use "kilos" or "Ks" when discussing large quantities of cocaine or heroin. It's good to know that the drug dealers are helping to bring the US towards using the metric system.

#movies #metric

_xhr_,
@_xhr_@cybervillains.com avatar

@fitheach Now that you mention it. I heard it a thousands time but never really realized. TIL!

_xhr_, to random
@_xhr_@cybervillains.com avatar

I couldn't resist

_xhr_, to random
@_xhr_@cybervillains.com avatar

Sad to say this, but no #37c3 for me this year.

_xhr_,
@_xhr_@cybervillains.com avatar

@mcfly I will move to a new place shortly after congress and I don't want to risk getting the Congressseuche or something worse.

jcs, to random
@jcs@jcs.org avatar

The water wheel is now turning. [2]

_xhr_,
@_xhr_@cybervillains.com avatar

@jcs Very nice shot. Is that an unmodified shot or did you use any filters?

thomas, to random
@thomas@metalhead.club avatar

Time for a Bavarian dinner!

It's not healthy or climate friendly but sooo tasty 😍

_xhr_,
@_xhr_@cybervillains.com avatar

@thomas Enjoy!

globalc, to retrocomputing
@globalc@chaos.social avatar

I did a tour through 3 hard off stores today, turns out they also have 8086 systems from NEC around!
Also DOS-games on disks: Ultima underworld, Syndicate. But these are quite expensive. Empty 3.5" floppy are no longer around.

I got an ATAPI cd/dvd reader/writer home with me for 330円, will try to use it in the Sun Ultra 5 to install Solaris.

Will make a wiki page to store which hardoff features old hardware (they have a bit of that on their site, but not much).
#retrocomputing

_xhr_,
@_xhr_@cybervillains.com avatar

@globalc Oh, Syndicate on floppies. That brings back memories and tells me that I am an old fart by now :)

_xhr_, to random
@_xhr_@cybervillains.com avatar

PSA: if you haven't fetched your pre-ordered #cccamp23 merch yet, please come to the merch tent. There is a dedicated counter on the left side of the tent. No need to wait in line! Please boost

_xhr_, to random
@_xhr_@cybervillains.com avatar

PSA: official #cccamp23 merch sale starts today at 15:00. Pre-sale only! Bring your QR code! Please boost

Semi, to random German

Das #cccamp23 wird ja mein erstes Camp. Was sagen denn die Campveteranen, was man unbedingt gemacht haben muss? Engeln, klar. Bahnfahren, offensichtlich. Was noch?

_xhr_,
@_xhr_@cybervillains.com avatar

@scy @Semi Genau das!

Zudem noch Nachts auf den kleinen Berg auf den Turm, runterschauen und die Lichter geniessen.

_xhr_, to Amd
@_xhr_@cybervillains.com avatar

a use-after-free vulnerability in Zen2 processors discovered by Tavis Ormandy.

Seems AMD also got their speculative execution share

https://lock.cmpxchg8b.com/zenbleed.html

_xhr_,
@_xhr_@cybervillains.com avatar

Looking at the timeline of 's Github repo, it seems the disclosure process was accidentally speed up since released patches to early.

https://github.com/google/security-research/tree/master/pocs/cpus/zenbleed

djm, to random
@djm@cybervillains.com avatar

We've just made an OpenSSH release to fix a remotely exploitable RCE vulnerability in ssh-agent's PKCS#11 support (CVE-2023-38408). Details at https://openssh.com/releasenotes.html#9.3p2

Thanks to the Qualys Security Advisory Team for finding and reporting this bug.

_xhr_,
@_xhr_@cybervillains.com avatar

@djm Can you say which versions of OpenSSH are affected? Only 9.3 or also earlier versions?

fitheach, to random
@fitheach@mstdn.io avatar

Been away for the weekend. Had a wonderful time. Came home to find the house had been burgled. Not yet sure what is missing. Place is in a mess.

The feeling of elation has quickly taken a downturn.

_xhr_,
@_xhr_@cybervillains.com avatar

@fitheach I can assure you the thief is not Swabian. The Schwaben don't use a press for making Spätzle, they only use a knife and a cutting board ("Spätzle schaben").

Only immigrants (basically everyone outside of Swabian) uses a press :D

_xhr_,
@_xhr_@cybervillains.com avatar

@fitheach We usually use the same dough for cut or pressed Spätzle. Mostly flour, eggs and butter. My wife likes to add curd sometimes, this creates a more airy (is that the right word?) dough.

Pub quiz fact: If you cut the dough into the water, you make Spätzle. If you use a press you make Knöpfle (small buttons).

_xhr_,
@_xhr_@cybervillains.com avatar

@fitheach Is there another editor? Blasphemy!

_xhr_,
@_xhr_@cybervillains.com avatar

@fitheach Yeah, that's what the hipsters with so called monitors use. Real admins use line printers

_xhr_,
@_xhr_@cybervillains.com avatar

@fitheach Thanks, will give it a try!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • provamag3
  • kavyap
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • ngwrru68w68
  • Youngstown
  • everett
  • slotface
  • rosin
  • ethstaker
  • Durango
  • GTA5RPClips
  • megavids
  • cubers
  • modclub
  • mdbf
  • khanakhh
  • vwfavf
  • osvaldo12
  • cisconetworking
  • tester
  • Leos
  • tacticalgear
  • anitta
  • normalnudes
  • JUstTest
  • All magazines