Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Three years ago I blogged about #nuget serving outdated #curl packages.

Three years ago I blogged about #nuget serving outdated #curl packages.

Scheduled Pinned Locked Moved Uncategorized
nugetcurl
28 Posts 21 Posters 10 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • bagder@mastodon.socialB bagder@mastodon.social

    Three years ago I blogged about #nuget serving outdated #curl packages.

    They then removed the packages I found.

    I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

    The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

    photo55@mastodon.socialP This user is from outside of this forum
    photo55@mastodon.socialP This user is from outside of this forum
    photo55@mastodon.social
    wrote last edited by
    #3

    Microsoft, and Windows.
    Ah well.

    1 Reply Last reply
    0
    • R relay@relay.infosec.exchange shared this topic
    • bagder@mastodon.socialB bagder@mastodon.social

      Three years ago I blogged about #nuget serving outdated #curl packages.

      They then removed the packages I found.

      I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

      The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

      bagder@mastodon.socialB This user is from outside of this forum
      bagder@mastodon.socialB This user is from outside of this forum
      bagder@mastodon.social
      wrote last edited by
      #4

      "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

      ๐Ÿ˜ 

      bagder@mastodon.socialB sa7dse@chaos.socialS wookiesmasher@mastodon.socialW agowa338@chaos.socialA 4 Replies Last reply
      0
      • limebar@mastodon.socialL limebar@mastodon.social shared this topic
      • bagder@mastodon.socialB bagder@mastodon.social

        "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

        ๐Ÿ˜ 

        bagder@mastodon.socialB This user is from outside of this forum
        bagder@mastodon.socialB This user is from outside of this forum
        bagder@mastodon.social
        wrote last edited by
        #5

        but I took it to the big generic security portal and submitted a report there. Let's see what happens.

        bagder@mastodon.socialB 1 Reply Last reply
        0
        • bagder@mastodon.socialB bagder@mastodon.social

          "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

          ๐Ÿ˜ 

          sa7dse@chaos.socialS This user is from outside of this forum
          sa7dse@chaos.socialS This user is from outside of this forum
          sa7dse@chaos.social
          wrote last edited by
          #6

          @bagder Maybe they got too many slop reports via email.

          gmgall@ursal.zoneG 1 Reply Last reply
          0
          • sa7dse@chaos.socialS sa7dse@chaos.social

            @bagder Maybe they got too many slop reports via email.

            gmgall@ursal.zoneG This user is from outside of this forum
            gmgall@ursal.zoneG This user is from outside of this forum
            gmgall@ursal.zone
            wrote last edited by
            #7

            @sa7dse @bagder Time to get a lot of slop via the generic security form for a change.

            doomed_daniel@mastodon.gamedev.placeD 1 Reply Last reply
            0
            • bagder@mastodon.socialB bagder@mastodon.social

              Three years ago I blogged about #nuget serving outdated #curl packages.

              They then removed the packages I found.

              I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

              The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

              tenzer@s.waq.dkT This user is from outside of this forum
              tenzer@s.waq.dkT This user is from outside of this forum
              tenzer@s.waq.dk
              wrote last edited by
              #8

              @bagder Have you considered if there's a demand for vintage curl releases that you aren't serving? Give the people what they want!

              bagder@mastodon.socialB 1 Reply Last reply
              0
              • tenzer@s.waq.dkT tenzer@s.waq.dk

                @bagder Have you considered if there's a demand for vintage curl releases that you aren't serving? Give the people what they want!

                bagder@mastodon.socialB This user is from outside of this forum
                bagder@mastodon.socialB This user is from outside of this forum
                bagder@mastodon.social
                wrote last edited by
                #9

                @Tenzer I linked the security people to this relevant page: https://curl.se/docs/vuln-7.51.0.html

                1 Reply Last reply
                0
                • bagder@mastodon.socialB bagder@mastodon.social

                  "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

                  ๐Ÿ˜ 

                  wookiesmasher@mastodon.socialW This user is from outside of this forum
                  wookiesmasher@mastodon.socialW This user is from outside of this forum
                  wookiesmasher@mastodon.social
                  wrote last edited by
                  #10

                  @bagder AI Slop, this is why we can't have nice things.

                  1 Reply Last reply
                  0
                  • R relay@relay.an.exchange shared this topic
                  • gmgall@ursal.zoneG gmgall@ursal.zone

                    @sa7dse @bagder Time to get a lot of slop via the generic security form for a change.

                    doomed_daniel@mastodon.gamedev.placeD This user is from outside of this forum
                    doomed_daniel@mastodon.gamedev.placeD This user is from outside of this forum
                    doomed_daniel@mastodon.gamedev.place
                    wrote last edited by
                    #11

                    @gmgall @sa7dse @bagder
                    they should be more proactive and provide an MCP endpoint for slop reports

                    1 Reply Last reply
                    0
                    • bagder@mastodon.socialB bagder@mastodon.social

                      Three years ago I blogged about #nuget serving outdated #curl packages.

                      They then removed the packages I found.

                      I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                      The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                      hisold@toot.ioH This user is from outside of this forum
                      hisold@toot.ioH This user is from outside of this forum
                      hisold@toot.io
                      wrote last edited by
                      #12

                      @bagder I've using dotnet for a few years and wanted to try using Curl but didn't find anything that wasn't poorly maintained or totally outdated.

                      1 Reply Last reply
                      0
                      • bagder@mastodon.socialB bagder@mastodon.social

                        Three years ago I blogged about #nuget serving outdated #curl packages.

                        They then removed the packages I found.

                        I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                        The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                        ssg@hachyderm.ioS This user is from outside of this forum
                        ssg@hachyderm.ioS This user is from outside of this forum
                        ssg@hachyderm.io
                        wrote last edited by
                        #13

                        @bagder @shanselman responded to the bluesky mirror of this post.

                        bagder@mastodon.socialB 1 Reply Last reply
                        0
                        • ssg@hachyderm.ioS ssg@hachyderm.io

                          @bagder @shanselman responded to the bluesky mirror of this post.

                          bagder@mastodon.socialB This user is from outside of this forum
                          bagder@mastodon.socialB This user is from outside of this forum
                          bagder@mastodon.social
                          wrote last edited by
                          #14

                          @ssg @shanselman thanks, I tend to miss the replies to the mirror-me over there...

                          1 Reply Last reply
                          0
                          • bagder@mastodon.socialB bagder@mastodon.social

                            Three years ago I blogged about #nuget serving outdated #curl packages.

                            They then removed the packages I found.

                            I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                            The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                            older@mstdn.socialO This user is from outside of this forum
                            older@mstdn.socialO This user is from outside of this forum
                            older@mstdn.social
                            wrote last edited by
                            #15

                            @bagder
                            Have you considered reserving "Curl" prefix on NuGet?
                            https://learn.microsoft.com/en-us/nuget/nuget-org/id-prefix-reservation
                            It is not much but it would prevent random people from uploading "officially looking" packages.

                            1 Reply Last reply
                            0
                            • bagder@mastodon.socialB bagder@mastodon.social

                              but I took it to the big generic security portal and submitted a report there. Let's see what happens.

                              bagder@mastodon.socialB This user is from outside of this forum
                              bagder@mastodon.socialB This user is from outside of this forum
                              bagder@mastodon.social
                              wrote last edited by
                              #16

                              My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                              tjbutt58@infosec.exchangeT totenlegionchris@metalhead.clubT bitpirate@mas.toB astraleureka@social.treehouse.systemsA moritzdietz@mastodon.socialM 7 Replies Last reply
                              0
                              • bagder@mastodon.socialB bagder@mastodon.social

                                My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                tjbutt58@infosec.exchangeT This user is from outside of this forum
                                tjbutt58@infosec.exchangeT This user is from outside of this forum
                                tjbutt58@infosec.exchange
                                wrote last edited by
                                #17

                                @bagder our own IT team are running Office 2016 in a sensitive environment.
                                Why would MS be any better. ๐Ÿ™

                                agowa338@chaos.socialA 1 Reply Last reply
                                0
                                • bagder@mastodon.socialB bagder@mastodon.social

                                  My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                  totenlegionchris@metalhead.clubT This user is from outside of this forum
                                  totenlegionchris@metalhead.clubT This user is from outside of this forum
                                  totenlegionchris@metalhead.club
                                  wrote last edited by
                                  #18

                                  @bagder Subscription first, Quality second. Works as expected I suppose.

                                  enfors@mastodon.socialE 1 Reply Last reply
                                  0
                                  • bagder@mastodon.socialB bagder@mastodon.social

                                    My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                    bitpirate@mas.toB This user is from outside of this forum
                                    bitpirate@mas.toB This user is from outside of this forum
                                    bitpirate@mas.to
                                    wrote last edited by
                                    #19

                                    @bagder Microslop

                                    1 Reply Last reply
                                    0
                                    • bagder@mastodon.socialB bagder@mastodon.social

                                      Three years ago I blogged about #nuget serving outdated #curl packages.

                                      They then removed the packages I found.

                                      I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                                      The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                                      gloriouscow@oldbytes.spaceG This user is from outside of this forum
                                      gloriouscow@oldbytes.spaceG This user is from outside of this forum
                                      gloriouscow@oldbytes.space
                                      wrote last edited by
                                      #20

                                      @bagder nuget? more like oldget amirite

                                      1 Reply Last reply
                                      0
                                      • bagder@mastodon.socialB bagder@mastodon.social

                                        My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                        astraleureka@social.treehouse.systemsA This user is from outside of this forum
                                        astraleureka@social.treehouse.systemsA This user is from outside of this forum
                                        astraleureka@social.treehouse.systems
                                        wrote last edited by
                                        #21

                                        @bagder amazed you even got a reply that fast; it took me 6 months for them to acknowledge and patch a local root privilege escalation in Defender for Linux (https://astr.al/notes/2024-11-28_mdatp-privesc/)

                                        1 Reply Last reply
                                        0
                                        • totenlegionchris@metalhead.clubT totenlegionchris@metalhead.club

                                          @bagder Subscription first, Quality second. Works as expected I suppose.

                                          enfors@mastodon.socialE This user is from outside of this forum
                                          enfors@mastodon.socialE This user is from outside of this forum
                                          enfors@mastodon.social
                                          wrote last edited by
                                          #22

                                          @totenlegionChris @bagder ... second? That's bold of you to assume.

                                          totenlegionchris@metalhead.clubT 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups