Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Three years ago I blogged about #nuget serving outdated #curl packages.

Three years ago I blogged about #nuget serving outdated #curl packages.

Scheduled Pinned Locked Moved Uncategorized
nugetcurl
28 Posts 21 Posters 10 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • bagder@mastodon.socialB bagder@mastodon.social

    "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

    ๐Ÿ˜ 

    sa7dse@chaos.socialS This user is from outside of this forum
    sa7dse@chaos.socialS This user is from outside of this forum
    sa7dse@chaos.social
    wrote last edited by
    #6

    @bagder Maybe they got too many slop reports via email.

    gmgall@ursal.zoneG 1 Reply Last reply
    0
    • sa7dse@chaos.socialS sa7dse@chaos.social

      @bagder Maybe they got too many slop reports via email.

      gmgall@ursal.zoneG This user is from outside of this forum
      gmgall@ursal.zoneG This user is from outside of this forum
      gmgall@ursal.zone
      wrote last edited by
      #7

      @sa7dse @bagder Time to get a lot of slop via the generic security form for a change.

      doomed_daniel@mastodon.gamedev.placeD 1 Reply Last reply
      0
      • bagder@mastodon.socialB bagder@mastodon.social

        Three years ago I blogged about #nuget serving outdated #curl packages.

        They then removed the packages I found.

        I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

        The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

        tenzer@s.waq.dkT This user is from outside of this forum
        tenzer@s.waq.dkT This user is from outside of this forum
        tenzer@s.waq.dk
        wrote last edited by
        #8

        @bagder Have you considered if there's a demand for vintage curl releases that you aren't serving? Give the people what they want!

        bagder@mastodon.socialB 1 Reply Last reply
        0
        • tenzer@s.waq.dkT tenzer@s.waq.dk

          @bagder Have you considered if there's a demand for vintage curl releases that you aren't serving? Give the people what they want!

          bagder@mastodon.socialB This user is from outside of this forum
          bagder@mastodon.socialB This user is from outside of this forum
          bagder@mastodon.social
          wrote last edited by
          #9

          @Tenzer I linked the security people to this relevant page: https://curl.se/docs/vuln-7.51.0.html

          1 Reply Last reply
          0
          • bagder@mastodon.socialB bagder@mastodon.social

            "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

            ๐Ÿ˜ 

            wookiesmasher@mastodon.socialW This user is from outside of this forum
            wookiesmasher@mastodon.socialW This user is from outside of this forum
            wookiesmasher@mastodon.social
            wrote last edited by
            #10

            @bagder AI Slop, this is why we can't have nice things.

            1 Reply Last reply
            0
            • R relay@relay.an.exchange shared this topic
            • gmgall@ursal.zoneG gmgall@ursal.zone

              @sa7dse @bagder Time to get a lot of slop via the generic security form for a change.

              doomed_daniel@mastodon.gamedev.placeD This user is from outside of this forum
              doomed_daniel@mastodon.gamedev.placeD This user is from outside of this forum
              doomed_daniel@mastodon.gamedev.place
              wrote last edited by
              #11

              @gmgall @sa7dse @bagder
              they should be more proactive and provide an MCP endpoint for slop reports

              1 Reply Last reply
              0
              • bagder@mastodon.socialB bagder@mastodon.social

                Three years ago I blogged about #nuget serving outdated #curl packages.

                They then removed the packages I found.

                I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                hisold@toot.ioH This user is from outside of this forum
                hisold@toot.ioH This user is from outside of this forum
                hisold@toot.io
                wrote last edited by
                #12

                @bagder I've using dotnet for a few years and wanted to try using Curl but didn't find anything that wasn't poorly maintained or totally outdated.

                1 Reply Last reply
                0
                • bagder@mastodon.socialB bagder@mastodon.social

                  Three years ago I blogged about #nuget serving outdated #curl packages.

                  They then removed the packages I found.

                  I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                  The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                  ssg@hachyderm.ioS This user is from outside of this forum
                  ssg@hachyderm.ioS This user is from outside of this forum
                  ssg@hachyderm.io
                  wrote last edited by
                  #13

                  @bagder @shanselman responded to the bluesky mirror of this post.

                  bagder@mastodon.socialB 1 Reply Last reply
                  0
                  • ssg@hachyderm.ioS ssg@hachyderm.io

                    @bagder @shanselman responded to the bluesky mirror of this post.

                    bagder@mastodon.socialB This user is from outside of this forum
                    bagder@mastodon.socialB This user is from outside of this forum
                    bagder@mastodon.social
                    wrote last edited by
                    #14

                    @ssg @shanselman thanks, I tend to miss the replies to the mirror-me over there...

                    1 Reply Last reply
                    0
                    • bagder@mastodon.socialB bagder@mastodon.social

                      Three years ago I blogged about #nuget serving outdated #curl packages.

                      They then removed the packages I found.

                      I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                      The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                      older@mstdn.socialO This user is from outside of this forum
                      older@mstdn.socialO This user is from outside of this forum
                      older@mstdn.social
                      wrote last edited by
                      #15

                      @bagder
                      Have you considered reserving "Curl" prefix on NuGet?
                      https://learn.microsoft.com/en-us/nuget/nuget-org/id-prefix-reservation
                      It is not much but it would prevent random people from uploading "officially looking" packages.

                      1 Reply Last reply
                      0
                      • bagder@mastodon.socialB bagder@mastodon.social

                        but I took it to the big generic security portal and submitted a report there. Let's see what happens.

                        bagder@mastodon.socialB This user is from outside of this forum
                        bagder@mastodon.socialB This user is from outside of this forum
                        bagder@mastodon.social
                        wrote last edited by
                        #16

                        My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                        tjbutt58@infosec.exchangeT totenlegionchris@metalhead.clubT bitpirate@mas.toB astraleureka@social.treehouse.systemsA moritzdietz@mastodon.socialM 7 Replies Last reply
                        0
                        • bagder@mastodon.socialB bagder@mastodon.social

                          My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                          tjbutt58@infosec.exchangeT This user is from outside of this forum
                          tjbutt58@infosec.exchangeT This user is from outside of this forum
                          tjbutt58@infosec.exchange
                          wrote last edited by
                          #17

                          @bagder our own IT team are running Office 2016 in a sensitive environment.
                          Why would MS be any better. ๐Ÿ™

                          agowa338@chaos.socialA 1 Reply Last reply
                          0
                          • bagder@mastodon.socialB bagder@mastodon.social

                            My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                            totenlegionchris@metalhead.clubT This user is from outside of this forum
                            totenlegionchris@metalhead.clubT This user is from outside of this forum
                            totenlegionchris@metalhead.club
                            wrote last edited by
                            #18

                            @bagder Subscription first, Quality second. Works as expected I suppose.

                            enfors@mastodon.socialE 1 Reply Last reply
                            0
                            • bagder@mastodon.socialB bagder@mastodon.social

                              My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                              bitpirate@mas.toB This user is from outside of this forum
                              bitpirate@mas.toB This user is from outside of this forum
                              bitpirate@mas.to
                              wrote last edited by
                              #19

                              @bagder Microslop

                              1 Reply Last reply
                              0
                              • bagder@mastodon.socialB bagder@mastodon.social

                                Three years ago I blogged about #nuget serving outdated #curl packages.

                                They then removed the packages I found.

                                I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                                The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                                gloriouscow@oldbytes.spaceG This user is from outside of this forum
                                gloriouscow@oldbytes.spaceG This user is from outside of this forum
                                gloriouscow@oldbytes.space
                                wrote last edited by
                                #20

                                @bagder nuget? more like oldget amirite

                                1 Reply Last reply
                                0
                                • bagder@mastodon.socialB bagder@mastodon.social

                                  My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                  astraleureka@social.treehouse.systemsA This user is from outside of this forum
                                  astraleureka@social.treehouse.systemsA This user is from outside of this forum
                                  astraleureka@social.treehouse.systems
                                  wrote last edited by
                                  #21

                                  @bagder amazed you even got a reply that fast; it took me 6 months for them to acknowledge and patch a local root privilege escalation in Defender for Linux (https://astr.al/notes/2024-11-28_mdatp-privesc/)

                                  1 Reply Last reply
                                  0
                                  • totenlegionchris@metalhead.clubT totenlegionchris@metalhead.club

                                    @bagder Subscription first, Quality second. Works as expected I suppose.

                                    enfors@mastodon.socialE This user is from outside of this forum
                                    enfors@mastodon.socialE This user is from outside of this forum
                                    enfors@mastodon.social
                                    wrote last edited by
                                    #22

                                    @totenlegionChris @bagder ... second? That's bold of you to assume.

                                    totenlegionchris@metalhead.clubT 1 Reply Last reply
                                    0
                                    • bagder@mastodon.socialB bagder@mastodon.social

                                      My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                      moritzdietz@mastodon.socialM This user is from outside of this forum
                                      moritzdietz@mastodon.socialM This user is from outside of this forum
                                      moritzdietz@mastodon.social
                                      wrote last edited by
                                      #23

                                      @bagder if you had stayed in the MVP program on the other handโ€ฆ ๐Ÿ˜‰

                                      1 Reply Last reply
                                      0
                                      • bagder@mastodon.socialB bagder@mastodon.social

                                        "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

                                        ๐Ÿ˜ 

                                        agowa338@chaos.socialA This user is from outside of this forum
                                        agowa338@chaos.socialA This user is from outside of this forum
                                        agowa338@chaos.social
                                        wrote last edited by
                                        #24

                                        @bagder

                                        Didn't they fire everyone in the team that was handling the submissions through that email address a few years ago?

                                        1 Reply Last reply
                                        0
                                        • bagder@mastodon.socialB bagder@mastodon.social

                                          My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                          xenotrope@bsd.networkX This user is from outside of this forum
                                          xenotrope@bsd.networkX This user is from outside of this forum
                                          xenotrope@bsd.network
                                          wrote last edited by
                                          #25

                                          @bagder Without going into detail, I once worked for a company that sells a windowing operating system. My team managed e-mail, filtering and archiving, and we escalated a 0-day DNS vulnerability to the relevant dev team for immediate response. It wasn't even in-house DNS software. It was a "here's the BIND patch, go deploy it" situation.

                                          The dev lead told us that if it was important, we should have brought it up in that morning's shiproom meeting.

                                          The vulnerability wasn't announced until after the meeting had ended.

                                          I and a senior ops engineer spent most of that day trying to convey to the senior dev lead that a major security vulnerability was more important than his next two-week ship date.

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups