Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Three years ago I blogged about #nuget serving outdated #curl packages.

Three years ago I blogged about #nuget serving outdated #curl packages.

Scheduled Pinned Locked Moved Uncategorized
nugetcurl
28 Posts 21 Posters 10 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • bagder@mastodon.socialB bagder@mastodon.social

    Three years ago I blogged about #nuget serving outdated #curl packages.

    They then removed the packages I found.

    I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

    The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

    bagder@mastodon.socialB This user is from outside of this forum
    bagder@mastodon.socialB This user is from outside of this forum
    bagder@mastodon.social
    wrote last edited by
    #4

    "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

    ๐Ÿ˜ 

    bagder@mastodon.socialB sa7dse@chaos.socialS wookiesmasher@mastodon.socialW agowa338@chaos.socialA 4 Replies Last reply
    0
    • limebar@mastodon.socialL limebar@mastodon.social shared this topic
    • bagder@mastodon.socialB bagder@mastodon.social

      "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

      ๐Ÿ˜ 

      bagder@mastodon.socialB This user is from outside of this forum
      bagder@mastodon.socialB This user is from outside of this forum
      bagder@mastodon.social
      wrote last edited by
      #5

      but I took it to the big generic security portal and submitted a report there. Let's see what happens.

      bagder@mastodon.socialB 1 Reply Last reply
      0
      • bagder@mastodon.socialB bagder@mastodon.social

        "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

        ๐Ÿ˜ 

        sa7dse@chaos.socialS This user is from outside of this forum
        sa7dse@chaos.socialS This user is from outside of this forum
        sa7dse@chaos.social
        wrote last edited by
        #6

        @bagder Maybe they got too many slop reports via email.

        gmgall@ursal.zoneG 1 Reply Last reply
        0
        • sa7dse@chaos.socialS sa7dse@chaos.social

          @bagder Maybe they got too many slop reports via email.

          gmgall@ursal.zoneG This user is from outside of this forum
          gmgall@ursal.zoneG This user is from outside of this forum
          gmgall@ursal.zone
          wrote last edited by
          #7

          @sa7dse @bagder Time to get a lot of slop via the generic security form for a change.

          doomed_daniel@mastodon.gamedev.placeD 1 Reply Last reply
          0
          • bagder@mastodon.socialB bagder@mastodon.social

            Three years ago I blogged about #nuget serving outdated #curl packages.

            They then removed the packages I found.

            I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

            The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

            tenzer@s.waq.dkT This user is from outside of this forum
            tenzer@s.waq.dkT This user is from outside of this forum
            tenzer@s.waq.dk
            wrote last edited by
            #8

            @bagder Have you considered if there's a demand for vintage curl releases that you aren't serving? Give the people what they want!

            bagder@mastodon.socialB 1 Reply Last reply
            0
            • tenzer@s.waq.dkT tenzer@s.waq.dk

              @bagder Have you considered if there's a demand for vintage curl releases that you aren't serving? Give the people what they want!

              bagder@mastodon.socialB This user is from outside of this forum
              bagder@mastodon.socialB This user is from outside of this forum
              bagder@mastodon.social
              wrote last edited by
              #9

              @Tenzer I linked the security people to this relevant page: https://curl.se/docs/vuln-7.51.0.html

              1 Reply Last reply
              0
              • bagder@mastodon.socialB bagder@mastodon.social

                "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

                ๐Ÿ˜ 

                wookiesmasher@mastodon.socialW This user is from outside of this forum
                wookiesmasher@mastodon.socialW This user is from outside of this forum
                wookiesmasher@mastodon.social
                wrote last edited by
                #10

                @bagder AI Slop, this is why we can't have nice things.

                1 Reply Last reply
                0
                • R relay@relay.an.exchange shared this topic
                • gmgall@ursal.zoneG gmgall@ursal.zone

                  @sa7dse @bagder Time to get a lot of slop via the generic security form for a change.

                  doomed_daniel@mastodon.gamedev.placeD This user is from outside of this forum
                  doomed_daniel@mastodon.gamedev.placeD This user is from outside of this forum
                  doomed_daniel@mastodon.gamedev.place
                  wrote last edited by
                  #11

                  @gmgall @sa7dse @bagder
                  they should be more proactive and provide an MCP endpoint for slop reports

                  1 Reply Last reply
                  0
                  • bagder@mastodon.socialB bagder@mastodon.social

                    Three years ago I blogged about #nuget serving outdated #curl packages.

                    They then removed the packages I found.

                    I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                    The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                    hisold@toot.ioH This user is from outside of this forum
                    hisold@toot.ioH This user is from outside of this forum
                    hisold@toot.io
                    wrote last edited by
                    #12

                    @bagder I've using dotnet for a few years and wanted to try using Curl but didn't find anything that wasn't poorly maintained or totally outdated.

                    1 Reply Last reply
                    0
                    • bagder@mastodon.socialB bagder@mastodon.social

                      Three years ago I blogged about #nuget serving outdated #curl packages.

                      They then removed the packages I found.

                      I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                      The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                      ssg@hachyderm.ioS This user is from outside of this forum
                      ssg@hachyderm.ioS This user is from outside of this forum
                      ssg@hachyderm.io
                      wrote last edited by
                      #13

                      @bagder @shanselman responded to the bluesky mirror of this post.

                      bagder@mastodon.socialB 1 Reply Last reply
                      0
                      • ssg@hachyderm.ioS ssg@hachyderm.io

                        @bagder @shanselman responded to the bluesky mirror of this post.

                        bagder@mastodon.socialB This user is from outside of this forum
                        bagder@mastodon.socialB This user is from outside of this forum
                        bagder@mastodon.social
                        wrote last edited by
                        #14

                        @ssg @shanselman thanks, I tend to miss the replies to the mirror-me over there...

                        1 Reply Last reply
                        0
                        • bagder@mastodon.socialB bagder@mastodon.social

                          Three years ago I blogged about #nuget serving outdated #curl packages.

                          They then removed the packages I found.

                          I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                          The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                          older@mstdn.socialO This user is from outside of this forum
                          older@mstdn.socialO This user is from outside of this forum
                          older@mstdn.social
                          wrote last edited by
                          #15

                          @bagder
                          Have you considered reserving "Curl" prefix on NuGet?
                          https://learn.microsoft.com/en-us/nuget/nuget-org/id-prefix-reservation
                          It is not much but it would prevent random people from uploading "officially looking" packages.

                          1 Reply Last reply
                          0
                          • bagder@mastodon.socialB bagder@mastodon.social

                            but I took it to the big generic security portal and submitted a report there. Let's see what happens.

                            bagder@mastodon.socialB This user is from outside of this forum
                            bagder@mastodon.socialB This user is from outside of this forum
                            bagder@mastodon.social
                            wrote last edited by
                            #16

                            My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                            tjbutt58@infosec.exchangeT totenlegionchris@metalhead.clubT bitpirate@mas.toB astraleureka@social.treehouse.systemsA moritzdietz@mastodon.socialM 7 Replies Last reply
                            0
                            • bagder@mastodon.socialB bagder@mastodon.social

                              My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                              tjbutt58@infosec.exchangeT This user is from outside of this forum
                              tjbutt58@infosec.exchangeT This user is from outside of this forum
                              tjbutt58@infosec.exchange
                              wrote last edited by
                              #17

                              @bagder our own IT team are running Office 2016 in a sensitive environment.
                              Why would MS be any better. ๐Ÿ™

                              agowa338@chaos.socialA 1 Reply Last reply
                              0
                              • bagder@mastodon.socialB bagder@mastodon.social

                                My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                totenlegionchris@metalhead.clubT This user is from outside of this forum
                                totenlegionchris@metalhead.clubT This user is from outside of this forum
                                totenlegionchris@metalhead.club
                                wrote last edited by
                                #18

                                @bagder Subscription first, Quality second. Works as expected I suppose.

                                enfors@mastodon.socialE 1 Reply Last reply
                                0
                                • bagder@mastodon.socialB bagder@mastodon.social

                                  My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                  bitpirate@mas.toB This user is from outside of this forum
                                  bitpirate@mas.toB This user is from outside of this forum
                                  bitpirate@mas.to
                                  wrote last edited by
                                  #19

                                  @bagder Microslop

                                  1 Reply Last reply
                                  0
                                  • bagder@mastodon.socialB bagder@mastodon.social

                                    Three years ago I blogged about #nuget serving outdated #curl packages.

                                    They then removed the packages I found.

                                    I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

                                    The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

                                    gloriouscow@oldbytes.spaceG This user is from outside of this forum
                                    gloriouscow@oldbytes.spaceG This user is from outside of this forum
                                    gloriouscow@oldbytes.space
                                    wrote last edited by
                                    #20

                                    @bagder nuget? more like oldget amirite

                                    1 Reply Last reply
                                    0
                                    • bagder@mastodon.socialB bagder@mastodon.social

                                      My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                      astraleureka@social.treehouse.systemsA This user is from outside of this forum
                                      astraleureka@social.treehouse.systemsA This user is from outside of this forum
                                      astraleureka@social.treehouse.systems
                                      wrote last edited by
                                      #21

                                      @bagder amazed you even got a reply that fast; it took me 6 months for them to acknowledge and patch a local root privilege escalation in Defender for Linux (https://astr.al/notes/2024-11-28_mdatp-privesc/)

                                      1 Reply Last reply
                                      0
                                      • totenlegionchris@metalhead.clubT totenlegionchris@metalhead.club

                                        @bagder Subscription first, Quality second. Works as expected I suppose.

                                        enfors@mastodon.socialE This user is from outside of this forum
                                        enfors@mastodon.socialE This user is from outside of this forum
                                        enfors@mastodon.social
                                        wrote last edited by
                                        #22

                                        @totenlegionChris @bagder ... second? That's bold of you to assume.

                                        totenlegionchris@metalhead.clubT 1 Reply Last reply
                                        0
                                        • bagder@mastodon.socialB bagder@mastodon.social

                                          My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                                          moritzdietz@mastodon.socialM This user is from outside of this forum
                                          moritzdietz@mastodon.socialM This user is from outside of this forum
                                          moritzdietz@mastodon.social
                                          wrote last edited by
                                          #23

                                          @bagder if you had stayed in the MVP program on the other handโ€ฆ ๐Ÿ˜‰

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups