Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Three years ago I blogged about #nuget serving outdated #curl packages.

Three years ago I blogged about #nuget serving outdated #curl packages.

Scheduled Pinned Locked Moved Uncategorized
nugetcurl
28 Posts 21 Posters 10 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • bagder@mastodon.socialB bagder@mastodon.social

    Three years ago I blogged about #nuget serving outdated #curl packages.

    They then removed the packages I found.

    I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

    The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

    aerique@genart.socialA This user is from outside of this forum
    aerique@genart.socialA This user is from outside of this forum
    aerique@genart.social
    wrote last edited by
    #2

    @bagder That's quite the nugget you found there.

    1 Reply Last reply
    0
    • bagder@mastodon.socialB bagder@mastodon.social

      Three years ago I blogged about #nuget serving outdated #curl packages.

      They then removed the packages I found.

      I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

      The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

      photo55@mastodon.socialP This user is from outside of this forum
      photo55@mastodon.socialP This user is from outside of this forum
      photo55@mastodon.social
      wrote last edited by
      #3

      Microsoft, and Windows.
      Ah well.

      1 Reply Last reply
      0
      • R relay@relay.infosec.exchange shared this topic
      • bagder@mastodon.socialB bagder@mastodon.social

        Three years ago I blogged about #nuget serving outdated #curl packages.

        They then removed the packages I found.

        I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

        The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

        bagder@mastodon.socialB This user is from outside of this forum
        bagder@mastodon.socialB This user is from outside of this forum
        bagder@mastodon.social
        wrote last edited by
        #4

        "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

        ๐Ÿ˜ 

        bagder@mastodon.socialB sa7dse@chaos.socialS wookiesmasher@mastodon.socialW agowa338@chaos.socialA 4 Replies Last reply
        0
        • limebar@mastodon.socialL limebar@mastodon.social shared this topic
        • bagder@mastodon.socialB bagder@mastodon.social

          "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

          ๐Ÿ˜ 

          bagder@mastodon.socialB This user is from outside of this forum
          bagder@mastodon.socialB This user is from outside of this forum
          bagder@mastodon.social
          wrote last edited by
          #5

          but I took it to the big generic security portal and submitted a report there. Let's see what happens.

          bagder@mastodon.socialB 1 Reply Last reply
          0
          • bagder@mastodon.socialB bagder@mastodon.social

            "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

            ๐Ÿ˜ 

            sa7dse@chaos.socialS This user is from outside of this forum
            sa7dse@chaos.socialS This user is from outside of this forum
            sa7dse@chaos.social
            wrote last edited by
            #6

            @bagder Maybe they got too many slop reports via email.

            gmgall@ursal.zoneG 1 Reply Last reply
            0
            • sa7dse@chaos.socialS sa7dse@chaos.social

              @bagder Maybe they got too many slop reports via email.

              gmgall@ursal.zoneG This user is from outside of this forum
              gmgall@ursal.zoneG This user is from outside of this forum
              gmgall@ursal.zone
              wrote last edited by
              #7

              @sa7dse @bagder Time to get a lot of slop via the generic security form for a change.

              doomed_daniel@mastodon.gamedev.placeD 1 Reply Last reply
              0
              • bagder@mastodon.socialB bagder@mastodon.social

                Three years ago I blogged about #nuget serving outdated #curl packages.

                They then removed the packages I found.

                I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                tenzer@s.waq.dkT This user is from outside of this forum
                tenzer@s.waq.dkT This user is from outside of this forum
                tenzer@s.waq.dk
                wrote last edited by
                #8

                @bagder Have you considered if there's a demand for vintage curl releases that you aren't serving? Give the people what they want!

                bagder@mastodon.socialB 1 Reply Last reply
                0
                • tenzer@s.waq.dkT tenzer@s.waq.dk

                  @bagder Have you considered if there's a demand for vintage curl releases that you aren't serving? Give the people what they want!

                  bagder@mastodon.socialB This user is from outside of this forum
                  bagder@mastodon.socialB This user is from outside of this forum
                  bagder@mastodon.social
                  wrote last edited by
                  #9

                  @Tenzer I linked the security people to this relevant page: https://curl.se/docs/vuln-7.51.0.html

                  1 Reply Last reply
                  0
                  • bagder@mastodon.socialB bagder@mastodon.social

                    "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

                    ๐Ÿ˜ 

                    wookiesmasher@mastodon.socialW This user is from outside of this forum
                    wookiesmasher@mastodon.socialW This user is from outside of this forum
                    wookiesmasher@mastodon.social
                    wrote last edited by
                    #10

                    @bagder AI Slop, this is why we can't have nice things.

                    1 Reply Last reply
                    0
                    • R relay@relay.an.exchange shared this topic
                    • gmgall@ursal.zoneG gmgall@ursal.zone

                      @sa7dse @bagder Time to get a lot of slop via the generic security form for a change.

                      doomed_daniel@mastodon.gamedev.placeD This user is from outside of this forum
                      doomed_daniel@mastodon.gamedev.placeD This user is from outside of this forum
                      doomed_daniel@mastodon.gamedev.place
                      wrote last edited by
                      #11

                      @gmgall @sa7dse @bagder
                      they should be more proactive and provide an MCP endpoint for slop reports

                      1 Reply Last reply
                      0
                      • bagder@mastodon.socialB bagder@mastodon.social

                        Three years ago I blogged about #nuget serving outdated #curl packages.

                        They then removed the packages I found.

                        I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                        The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                        hisold@toot.ioH This user is from outside of this forum
                        hisold@toot.ioH This user is from outside of this forum
                        hisold@toot.io
                        wrote last edited by
                        #12

                        @bagder I've using dotnet for a few years and wanted to try using Curl but didn't find anything that wasn't poorly maintained or totally outdated.

                        1 Reply Last reply
                        0
                        • bagder@mastodon.socialB bagder@mastodon.social

                          Three years ago I blogged about #nuget serving outdated #curl packages.

                          They then removed the packages I found.

                          I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                          The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                          ssg@hachyderm.ioS This user is from outside of this forum
                          ssg@hachyderm.ioS This user is from outside of this forum
                          ssg@hachyderm.io
                          wrote last edited by
                          #13

                          @bagder @shanselman responded to the bluesky mirror of this post.

                          bagder@mastodon.socialB 1 Reply Last reply
                          0
                          • ssg@hachyderm.ioS ssg@hachyderm.io

                            @bagder @shanselman responded to the bluesky mirror of this post.

                            bagder@mastodon.socialB This user is from outside of this forum
                            bagder@mastodon.socialB This user is from outside of this forum
                            bagder@mastodon.social
                            wrote last edited by
                            #14

                            @ssg @shanselman thanks, I tend to miss the replies to the mirror-me over there...

                            1 Reply Last reply
                            0
                            • bagder@mastodon.socialB bagder@mastodon.social

                              Three years ago I blogged about #nuget serving outdated #curl packages.

                              They then removed the packages I found.

                              I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                              The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                              older@mstdn.socialO This user is from outside of this forum
                              older@mstdn.socialO This user is from outside of this forum
                              older@mstdn.social
                              wrote last edited by
                              #15

                              @bagder
                              Have you considered reserving "Curl" prefix on NuGet?
                              https://learn.microsoft.com/en-us/nuget/nuget-org/id-prefix-reservation
                              It is not much but it would prevent random people from uploading "officially looking" packages.

                              1 Reply Last reply
                              0
                              • bagder@mastodon.socialB bagder@mastodon.social

                                but I took it to the big generic security portal and submitted a report there. Let's see what happens.

                                bagder@mastodon.socialB This user is from outside of this forum
                                bagder@mastodon.socialB This user is from outside of this forum
                                bagder@mastodon.social
                                wrote last edited by
                                #16

                                My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                tjbutt58@infosec.exchangeT totenlegionchris@metalhead.clubT bitpirate@mas.toB astraleureka@social.treehouse.systemsA moritzdietz@mastodon.socialM 7 Replies Last reply
                                0
                                • bagder@mastodon.socialB bagder@mastodon.social

                                  My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                  tjbutt58@infosec.exchangeT This user is from outside of this forum
                                  tjbutt58@infosec.exchangeT This user is from outside of this forum
                                  tjbutt58@infosec.exchange
                                  wrote last edited by
                                  #17

                                  @bagder our own IT team are running Office 2016 in a sensitive environment.
                                  Why would MS be any better. ๐Ÿ™

                                  agowa338@chaos.socialA 1 Reply Last reply
                                  0
                                  • bagder@mastodon.socialB bagder@mastodon.social

                                    My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                    totenlegionchris@metalhead.clubT This user is from outside of this forum
                                    totenlegionchris@metalhead.clubT This user is from outside of this forum
                                    totenlegionchris@metalhead.club
                                    wrote last edited by
                                    #18

                                    @bagder Subscription first, Quality second. Works as expected I suppose.

                                    enfors@mastodon.socialE 1 Reply Last reply
                                    0
                                    • bagder@mastodon.socialB bagder@mastodon.social

                                      My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                      bitpirate@mas.toB This user is from outside of this forum
                                      bitpirate@mas.toB This user is from outside of this forum
                                      bitpirate@mas.to
                                      wrote last edited by
                                      #19

                                      @bagder Microslop

                                      1 Reply Last reply
                                      0
                                      • bagder@mastodon.socialB bagder@mastodon.social

                                        Three years ago I blogged about #nuget serving outdated #curl packages.

                                        They then removed the packages I found.

                                        I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                                        The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                                        gloriouscow@oldbytes.spaceG This user is from outside of this forum
                                        gloriouscow@oldbytes.spaceG This user is from outside of this forum
                                        gloriouscow@oldbytes.space
                                        wrote last edited by
                                        #20

                                        @bagder nuget? more like oldget amirite

                                        1 Reply Last reply
                                        0
                                        • bagder@mastodon.socialB bagder@mastodon.social

                                          My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                          astraleureka@social.treehouse.systemsA This user is from outside of this forum
                                          astraleureka@social.treehouse.systemsA This user is from outside of this forum
                                          astraleureka@social.treehouse.systems
                                          wrote last edited by
                                          #21

                                          @bagder amazed you even got a reply that fast; it took me 6 months for them to acknowledge and patch a local root privilege escalation in Defender for Linux (https://astr.al/notes/2024-11-28_mdatp-privesc/)

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups