Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Three years ago I blogged about #nuget serving outdated #curl packages.

Three years ago I blogged about #nuget serving outdated #curl packages.

Scheduled Pinned Locked Moved Uncategorized
nugetcurl
28 Posts 21 Posters 10 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • bagder@mastodon.socialB This user is from outside of this forum
    bagder@mastodon.socialB This user is from outside of this forum
    bagder@mastodon.social
    wrote last edited by
    #1

    Three years ago I blogged about #nuget serving outdated #curl packages.

    They then removed the packages I found.

    I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

    The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

    aerique@genart.socialA photo55@mastodon.socialP bagder@mastodon.socialB tenzer@s.waq.dkT hisold@toot.ioH 8 Replies Last reply
    2
    0
    • bagder@mastodon.socialB bagder@mastodon.social

      Three years ago I blogged about #nuget serving outdated #curl packages.

      They then removed the packages I found.

      I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

      The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

      aerique@genart.socialA This user is from outside of this forum
      aerique@genart.socialA This user is from outside of this forum
      aerique@genart.social
      wrote last edited by
      #2

      @bagder That's quite the nugget you found there.

      1 Reply Last reply
      0
      • bagder@mastodon.socialB bagder@mastodon.social

        Three years ago I blogged about #nuget serving outdated #curl packages.

        They then removed the packages I found.

        I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

        The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

        photo55@mastodon.socialP This user is from outside of this forum
        photo55@mastodon.socialP This user is from outside of this forum
        photo55@mastodon.social
        wrote last edited by
        #3

        Microsoft, and Windows.
        Ah well.

        1 Reply Last reply
        0
        • R relay@relay.infosec.exchange shared this topic
        • bagder@mastodon.socialB bagder@mastodon.social

          Three years ago I blogged about #nuget serving outdated #curl packages.

          They then removed the packages I found.

          I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

          The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

          bagder@mastodon.socialB This user is from outside of this forum
          bagder@mastodon.socialB This user is from outside of this forum
          bagder@mastodon.social
          wrote last edited by
          #4

          "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

          ๐Ÿ˜ 

          bagder@mastodon.socialB sa7dse@chaos.socialS wookiesmasher@mastodon.socialW agowa338@chaos.socialA 4 Replies Last reply
          0
          • limebar@mastodon.socialL limebar@mastodon.social shared this topic
          • bagder@mastodon.socialB bagder@mastodon.social

            "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

            ๐Ÿ˜ 

            bagder@mastodon.socialB This user is from outside of this forum
            bagder@mastodon.socialB This user is from outside of this forum
            bagder@mastodon.social
            wrote last edited by
            #5

            but I took it to the big generic security portal and submitted a report there. Let's see what happens.

            bagder@mastodon.socialB 1 Reply Last reply
            0
            • bagder@mastodon.socialB bagder@mastodon.social

              "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

              ๐Ÿ˜ 

              sa7dse@chaos.socialS This user is from outside of this forum
              sa7dse@chaos.socialS This user is from outside of this forum
              sa7dse@chaos.social
              wrote last edited by
              #6

              @bagder Maybe they got too many slop reports via email.

              gmgall@ursal.zoneG 1 Reply Last reply
              0
              • sa7dse@chaos.socialS sa7dse@chaos.social

                @bagder Maybe they got too many slop reports via email.

                gmgall@ursal.zoneG This user is from outside of this forum
                gmgall@ursal.zoneG This user is from outside of this forum
                gmgall@ursal.zone
                wrote last edited by
                #7

                @sa7dse @bagder Time to get a lot of slop via the generic security form for a change.

                doomed_daniel@mastodon.gamedev.placeD 1 Reply Last reply
                0
                • bagder@mastodon.socialB bagder@mastodon.social

                  Three years ago I blogged about #nuget serving outdated #curl packages.

                  They then removed the packages I found.

                  I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                  The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                  tenzer@s.waq.dkT This user is from outside of this forum
                  tenzer@s.waq.dkT This user is from outside of this forum
                  tenzer@s.waq.dk
                  wrote last edited by
                  #8

                  @bagder Have you considered if there's a demand for vintage curl releases that you aren't serving? Give the people what they want!

                  bagder@mastodon.socialB 1 Reply Last reply
                  0
                  • tenzer@s.waq.dkT tenzer@s.waq.dk

                    @bagder Have you considered if there's a demand for vintage curl releases that you aren't serving? Give the people what they want!

                    bagder@mastodon.socialB This user is from outside of this forum
                    bagder@mastodon.socialB This user is from outside of this forum
                    bagder@mastodon.social
                    wrote last edited by
                    #9

                    @Tenzer I linked the security people to this relevant page: https://curl.se/docs/vuln-7.51.0.html

                    1 Reply Last reply
                    0
                    • bagder@mastodon.socialB bagder@mastodon.social

                      "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

                      ๐Ÿ˜ 

                      wookiesmasher@mastodon.socialW This user is from outside of this forum
                      wookiesmasher@mastodon.socialW This user is from outside of this forum
                      wookiesmasher@mastodon.social
                      wrote last edited by
                      #10

                      @bagder AI Slop, this is why we can't have nice things.

                      1 Reply Last reply
                      0
                      • R relay@relay.an.exchange shared this topic
                      • gmgall@ursal.zoneG gmgall@ursal.zone

                        @sa7dse @bagder Time to get a lot of slop via the generic security form for a change.

                        doomed_daniel@mastodon.gamedev.placeD This user is from outside of this forum
                        doomed_daniel@mastodon.gamedev.placeD This user is from outside of this forum
                        doomed_daniel@mastodon.gamedev.place
                        wrote last edited by
                        #11

                        @gmgall @sa7dse @bagder
                        they should be more proactive and provide an MCP endpoint for slop reports

                        1 Reply Last reply
                        0
                        • bagder@mastodon.socialB bagder@mastodon.social

                          Three years ago I blogged about #nuget serving outdated #curl packages.

                          They then removed the packages I found.

                          I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                          The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                          hisold@toot.ioH This user is from outside of this forum
                          hisold@toot.ioH This user is from outside of this forum
                          hisold@toot.io
                          wrote last edited by
                          #12

                          @bagder I've using dotnet for a few years and wanted to try using Curl but didn't find anything that wasn't poorly maintained or totally outdated.

                          1 Reply Last reply
                          0
                          • bagder@mastodon.socialB bagder@mastodon.social

                            Three years ago I blogged about #nuget serving outdated #curl packages.

                            They then removed the packages I found.

                            I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                            The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                            ssg@hachyderm.ioS This user is from outside of this forum
                            ssg@hachyderm.ioS This user is from outside of this forum
                            ssg@hachyderm.io
                            wrote last edited by
                            #13

                            @bagder @shanselman responded to the bluesky mirror of this post.

                            bagder@mastodon.socialB 1 Reply Last reply
                            0
                            • ssg@hachyderm.ioS ssg@hachyderm.io

                              @bagder @shanselman responded to the bluesky mirror of this post.

                              bagder@mastodon.socialB This user is from outside of this forum
                              bagder@mastodon.socialB This user is from outside of this forum
                              bagder@mastodon.social
                              wrote last edited by
                              #14

                              @ssg @shanselman thanks, I tend to miss the replies to the mirror-me over there...

                              1 Reply Last reply
                              0
                              • bagder@mastodon.socialB bagder@mastodon.social

                                Three years ago I blogged about #nuget serving outdated #curl packages.

                                They then removed the packages I found.

                                I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                                The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                                older@mstdn.socialO This user is from outside of this forum
                                older@mstdn.socialO This user is from outside of this forum
                                older@mstdn.social
                                wrote last edited by
                                #15

                                @bagder
                                Have you considered reserving "Curl" prefix on NuGet?
                                https://learn.microsoft.com/en-us/nuget/nuget-org/id-prefix-reservation
                                It is not much but it would prevent random people from uploading "officially looking" packages.

                                1 Reply Last reply
                                0
                                • bagder@mastodon.socialB bagder@mastodon.social

                                  but I took it to the big generic security portal and submitted a report there. Let's see what happens.

                                  bagder@mastodon.socialB This user is from outside of this forum
                                  bagder@mastodon.socialB This user is from outside of this forum
                                  bagder@mastodon.social
                                  wrote last edited by
                                  #16

                                  My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                  tjbutt58@infosec.exchangeT totenlegionchris@metalhead.clubT bitpirate@mas.toB astraleureka@social.treehouse.systemsA moritzdietz@mastodon.socialM 7 Replies Last reply
                                  0
                                  • bagder@mastodon.socialB bagder@mastodon.social

                                    My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                    tjbutt58@infosec.exchangeT This user is from outside of this forum
                                    tjbutt58@infosec.exchangeT This user is from outside of this forum
                                    tjbutt58@infosec.exchange
                                    wrote last edited by
                                    #17

                                    @bagder our own IT team are running Office 2016 in a sensitive environment.
                                    Why would MS be any better. ๐Ÿ™

                                    agowa338@chaos.socialA 1 Reply Last reply
                                    0
                                    • bagder@mastodon.socialB bagder@mastodon.social

                                      My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                      totenlegionchris@metalhead.clubT This user is from outside of this forum
                                      totenlegionchris@metalhead.clubT This user is from outside of this forum
                                      totenlegionchris@metalhead.club
                                      wrote last edited by
                                      #18

                                      @bagder Subscription first, Quality second. Works as expected I suppose.

                                      enfors@mastodon.socialE 1 Reply Last reply
                                      0
                                      • bagder@mastodon.socialB bagder@mastodon.social

                                        My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                        bitpirate@mas.toB This user is from outside of this forum
                                        bitpirate@mas.toB This user is from outside of this forum
                                        bitpirate@mas.to
                                        wrote last edited by
                                        #19

                                        @bagder Microslop

                                        1 Reply Last reply
                                        0
                                        • bagder@mastodon.socialB bagder@mastodon.social

                                          Three years ago I blogged about #nuget serving outdated #curl packages.

                                          They then removed the packages I found.

                                          I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                                          The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                                          gloriouscow@oldbytes.spaceG This user is from outside of this forum
                                          gloriouscow@oldbytes.spaceG This user is from outside of this forum
                                          gloriouscow@oldbytes.space
                                          wrote last edited by
                                          #20

                                          @bagder nuget? more like oldget amirite

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups