Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Three years ago I blogged about #nuget serving outdated #curl packages.

Three years ago I blogged about #nuget serving outdated #curl packages.

Scheduled Pinned Locked Moved Uncategorized
nugetcurl
28 Posts 21 Posters 10 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • bagder@mastodon.socialB bagder@mastodon.social

    "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

    ๐Ÿ˜ 

    bagder@mastodon.socialB This user is from outside of this forum
    bagder@mastodon.socialB This user is from outside of this forum
    bagder@mastodon.social
    wrote last edited by
    #5

    but I took it to the big generic security portal and submitted a report there. Let's see what happens.

    bagder@mastodon.socialB 1 Reply Last reply
    0
    • bagder@mastodon.socialB bagder@mastodon.social

      "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

      ๐Ÿ˜ 

      sa7dse@chaos.socialS This user is from outside of this forum
      sa7dse@chaos.socialS This user is from outside of this forum
      sa7dse@chaos.social
      wrote last edited by
      #6

      @bagder Maybe they got too many slop reports via email.

      gmgall@ursal.zoneG 1 Reply Last reply
      0
      • sa7dse@chaos.socialS sa7dse@chaos.social

        @bagder Maybe they got too many slop reports via email.

        gmgall@ursal.zoneG This user is from outside of this forum
        gmgall@ursal.zoneG This user is from outside of this forum
        gmgall@ursal.zone
        wrote last edited by
        #7

        @sa7dse @bagder Time to get a lot of slop via the generic security form for a change.

        doomed_daniel@mastodon.gamedev.placeD 1 Reply Last reply
        0
        • bagder@mastodon.socialB bagder@mastodon.social

          Three years ago I blogged about #nuget serving outdated #curl packages.

          They then removed the packages I found.

          I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

          The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

          tenzer@s.waq.dkT This user is from outside of this forum
          tenzer@s.waq.dkT This user is from outside of this forum
          tenzer@s.waq.dk
          wrote last edited by
          #8

          @bagder Have you considered if there's a demand for vintage curl releases that you aren't serving? Give the people what they want!

          bagder@mastodon.socialB 1 Reply Last reply
          0
          • tenzer@s.waq.dkT tenzer@s.waq.dk

            @bagder Have you considered if there's a demand for vintage curl releases that you aren't serving? Give the people what they want!

            bagder@mastodon.socialB This user is from outside of this forum
            bagder@mastodon.socialB This user is from outside of this forum
            bagder@mastodon.social
            wrote last edited by
            #9

            @Tenzer I linked the security people to this relevant page: https://curl.se/docs/vuln-7.51.0.html

            1 Reply Last reply
            0
            • bagder@mastodon.socialB bagder@mastodon.social

              "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

              ๐Ÿ˜ 

              wookiesmasher@mastodon.socialW This user is from outside of this forum
              wookiesmasher@mastodon.socialW This user is from outside of this forum
              wookiesmasher@mastodon.social
              wrote last edited by
              #10

              @bagder AI Slop, this is why we can't have nice things.

              1 Reply Last reply
              0
              • R relay@relay.an.exchange shared this topic
              • gmgall@ursal.zoneG gmgall@ursal.zone

                @sa7dse @bagder Time to get a lot of slop via the generic security form for a change.

                doomed_daniel@mastodon.gamedev.placeD This user is from outside of this forum
                doomed_daniel@mastodon.gamedev.placeD This user is from outside of this forum
                doomed_daniel@mastodon.gamedev.place
                wrote last edited by
                #11

                @gmgall @sa7dse @bagder
                they should be more proactive and provide an MCP endpoint for slop reports

                1 Reply Last reply
                0
                • bagder@mastodon.socialB bagder@mastodon.social

                  Three years ago I blogged about #nuget serving outdated #curl packages.

                  They then removed the packages I found.

                  I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                  The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                  hisold@toot.ioH This user is from outside of this forum
                  hisold@toot.ioH This user is from outside of this forum
                  hisold@toot.io
                  wrote last edited by
                  #12

                  @bagder I've using dotnet for a few years and wanted to try using Curl but didn't find anything that wasn't poorly maintained or totally outdated.

                  1 Reply Last reply
                  0
                  • bagder@mastodon.socialB bagder@mastodon.social

                    Three years ago I blogged about #nuget serving outdated #curl packages.

                    They then removed the packages I found.

                    I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                    The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                    ssg@hachyderm.ioS This user is from outside of this forum
                    ssg@hachyderm.ioS This user is from outside of this forum
                    ssg@hachyderm.io
                    wrote last edited by
                    #13

                    @bagder @shanselman responded to the bluesky mirror of this post.

                    bagder@mastodon.socialB 1 Reply Last reply
                    0
                    • ssg@hachyderm.ioS ssg@hachyderm.io

                      @bagder @shanselman responded to the bluesky mirror of this post.

                      bagder@mastodon.socialB This user is from outside of this forum
                      bagder@mastodon.socialB This user is from outside of this forum
                      bagder@mastodon.social
                      wrote last edited by
                      #14

                      @ssg @shanselman thanks, I tend to miss the replies to the mirror-me over there...

                      1 Reply Last reply
                      0
                      • bagder@mastodon.socialB bagder@mastodon.social

                        Three years ago I blogged about #nuget serving outdated #curl packages.

                        They then removed the packages I found.

                        I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                        The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                        older@mstdn.socialO This user is from outside of this forum
                        older@mstdn.socialO This user is from outside of this forum
                        older@mstdn.social
                        wrote last edited by
                        #15

                        @bagder
                        Have you considered reserving "Curl" prefix on NuGet?
                        https://learn.microsoft.com/en-us/nuget/nuget-org/id-prefix-reservation
                        It is not much but it would prevent random people from uploading "officially looking" packages.

                        1 Reply Last reply
                        0
                        • bagder@mastodon.socialB bagder@mastodon.social

                          but I took it to the big generic security portal and submitted a report there. Let's see what happens.

                          bagder@mastodon.socialB This user is from outside of this forum
                          bagder@mastodon.socialB This user is from outside of this forum
                          bagder@mastodon.social
                          wrote last edited by
                          #16

                          My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                          tjbutt58@infosec.exchangeT totenlegionchris@metalhead.clubT bitpirate@mas.toB astraleureka@social.treehouse.systemsA moritzdietz@mastodon.socialM 7 Replies Last reply
                          0
                          • bagder@mastodon.socialB bagder@mastodon.social

                            My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                            tjbutt58@infosec.exchangeT This user is from outside of this forum
                            tjbutt58@infosec.exchangeT This user is from outside of this forum
                            tjbutt58@infosec.exchange
                            wrote last edited by
                            #17

                            @bagder our own IT team are running Office 2016 in a sensitive environment.
                            Why would MS be any better. ๐Ÿ™

                            agowa338@chaos.socialA 1 Reply Last reply
                            0
                            • bagder@mastodon.socialB bagder@mastodon.social

                              My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                              totenlegionchris@metalhead.clubT This user is from outside of this forum
                              totenlegionchris@metalhead.clubT This user is from outside of this forum
                              totenlegionchris@metalhead.club
                              wrote last edited by
                              #18

                              @bagder Subscription first, Quality second. Works as expected I suppose.

                              enfors@mastodon.socialE 1 Reply Last reply
                              0
                              • bagder@mastodon.socialB bagder@mastodon.social

                                My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                bitpirate@mas.toB This user is from outside of this forum
                                bitpirate@mas.toB This user is from outside of this forum
                                bitpirate@mas.to
                                wrote last edited by
                                #19

                                @bagder Microslop

                                1 Reply Last reply
                                0
                                • bagder@mastodon.socialB bagder@mastodon.social

                                  Three years ago I blogged about #nuget serving outdated #curl packages.

                                  They then removed the packages I found.

                                  I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                                  The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                                  gloriouscow@oldbytes.spaceG This user is from outside of this forum
                                  gloriouscow@oldbytes.spaceG This user is from outside of this forum
                                  gloriouscow@oldbytes.space
                                  wrote last edited by
                                  #20

                                  @bagder nuget? more like oldget amirite

                                  1 Reply Last reply
                                  0
                                  • bagder@mastodon.socialB bagder@mastodon.social

                                    My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                    astraleureka@social.treehouse.systemsA This user is from outside of this forum
                                    astraleureka@social.treehouse.systemsA This user is from outside of this forum
                                    astraleureka@social.treehouse.systems
                                    wrote last edited by
                                    #21

                                    @bagder amazed you even got a reply that fast; it took me 6 months for them to acknowledge and patch a local root privilege escalation in Defender for Linux (https://astr.al/notes/2024-11-28_mdatp-privesc/)

                                    1 Reply Last reply
                                    0
                                    • totenlegionchris@metalhead.clubT totenlegionchris@metalhead.club

                                      @bagder Subscription first, Quality second. Works as expected I suppose.

                                      enfors@mastodon.socialE This user is from outside of this forum
                                      enfors@mastodon.socialE This user is from outside of this forum
                                      enfors@mastodon.social
                                      wrote last edited by
                                      #22

                                      @totenlegionChris @bagder ... second? That's bold of you to assume.

                                      totenlegionchris@metalhead.clubT 1 Reply Last reply
                                      0
                                      • bagder@mastodon.socialB bagder@mastodon.social

                                        My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                        moritzdietz@mastodon.socialM This user is from outside of this forum
                                        moritzdietz@mastodon.socialM This user is from outside of this forum
                                        moritzdietz@mastodon.social
                                        wrote last edited by
                                        #23

                                        @bagder if you had stayed in the MVP program on the other handโ€ฆ ๐Ÿ˜‰

                                        1 Reply Last reply
                                        0
                                        • bagder@mastodon.socialB bagder@mastodon.social

                                          "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

                                          ๐Ÿ˜ 

                                          agowa338@chaos.socialA This user is from outside of this forum
                                          agowa338@chaos.socialA This user is from outside of this forum
                                          agowa338@chaos.social
                                          wrote last edited by
                                          #24

                                          @bagder

                                          Didn't they fire everyone in the team that was handling the submissions through that email address a few years ago?

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups