I started working on tlslookieloo after failing to find a utility that I can use to basically MITM a client-server application I was testing at work. I looked at sslsniff and Cisco Talos' Mutiny Fuzzing Framework and Decept Proxy to see if it provides what I need, or modify it for my own needs. In … Continue reading Mocking C APIs in testing
This tutorial is intended for git beginners who need to sync up their working repo with changes made to the upstream repo. Cloning repos within collaboration platforms such as gitlab will not be part of this tutorial. Setup For the purposes of this project, we will use https://github.com/w3c-social/activipy as the upstream repository. Create a clone of the project, and … Continue reading Keeping Upstream and Working git Repos In Sync
I stumbled into this issue since one of my kid's teacher uses Remind. The issue is any pictures posted on Remind is publicly accessible from Cloudflare CDN. I have notified Remind's Security Team of the issue. Here is an example of a picture that my son's teacher posted to Remind that can be accessed by … Continue reading Remind Platform CDN misconfiguration
One of my favorite Christmas songs is the little drummer boy. Although there was no drummer boy recorded in the Bible I feel the story of the Little Drummer Boy summarizes what God expects of us all: to come to Him--warts and all--and be willing to be used by Him. The first two lines of … Continue reading Be the Little Drummer Boy
CVE-2018-144665 refers to "An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges." Here's the link to Matthew Hickey's tweet that shows the exploit. I'm not … Continue reading A Broader Issue Exposed by CVE-2018-14665
I found out that someone created an account on twitter using my email address. So, I decided to take over the account. For the longest time, I never saw the point of having a twitter account. I had one during twitter's early days. I'm talking back when you twitted by sending a text message, and … Continue reading Someone Used My Email for a Twitter Account
As I was boiling some macaroni the picture of the glowing heat coil after I've turned the knob to the off position, and slid the pot over got me thinking: have we as an industrialized society become overly cautious? Are we too concerned about the "one time that <insert fearful event here> might happen"? From … Continue reading Overly Cautious Much?