Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Three years ago I blogged about #nuget serving outdated #curl packages.

Three years ago I blogged about #nuget serving outdated #curl packages.

Scheduled Pinned Locked Moved Uncategorized
nugetcurl
28 Posts 21 Posters 10 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • bagder@mastodon.socialB bagder@mastodon.social

    My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

    bitpirate@mas.toB This user is from outside of this forum
    bitpirate@mas.toB This user is from outside of this forum
    bitpirate@mas.to
    wrote last edited by
    #19

    @bagder Microslop

    1 Reply Last reply
    0
    • bagder@mastodon.socialB bagder@mastodon.social

      Three years ago I blogged about #nuget serving outdated #curl packages.

      They then removed the packages I found.

      I checked nuget again *today* and immediately found a nine year old curl package that is downloaded at the rate of 1,000 times/week from there... with **64** known vulnerabilities.

      The blog post from back then: https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/

      gloriouscow@oldbytes.spaceG This user is from outside of this forum
      gloriouscow@oldbytes.spaceG This user is from outside of this forum
      gloriouscow@oldbytes.space
      wrote last edited by
      #20

      @bagder nuget? more like oldget amirite

      1 Reply Last reply
      0
      • bagder@mastodon.socialB bagder@mastodon.social

        My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

        astraleureka@social.treehouse.systemsA This user is from outside of this forum
        astraleureka@social.treehouse.systemsA This user is from outside of this forum
        astraleureka@social.treehouse.systems
        wrote last edited by
        #21

        @bagder amazed you even got a reply that fast; it took me 6 months for them to acknowledge and patch a local root privilege escalation in Defender for Linux (https://astr.al/notes/2024-11-28_mdatp-privesc/)

        1 Reply Last reply
        0
        • totenlegionchris@metalhead.clubT totenlegionchris@metalhead.club

          @bagder Subscription first, Quality second. Works as expected I suppose.

          enfors@mastodon.socialE This user is from outside of this forum
          enfors@mastodon.socialE This user is from outside of this forum
          enfors@mastodon.social
          wrote last edited by
          #22

          @totenlegionChris @bagder ... second? That's bold of you to assume.

          totenlegionchris@metalhead.clubT 1 Reply Last reply
          0
          • bagder@mastodon.socialB bagder@mastodon.social

            My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

            moritzdietz@mastodon.socialM This user is from outside of this forum
            moritzdietz@mastodon.socialM This user is from outside of this forum
            moritzdietz@mastodon.social
            wrote last edited by
            #23

            @bagder if you had stayed in the MVP program on the other handโ€ฆ ๐Ÿ˜‰

            1 Reply Last reply
            0
            • bagder@mastodon.socialB bagder@mastodon.social

              "Microsoft is no longer accepting new submissions through secure@microsoft.com. Please use the Microsoft Researcher Portal "...

              ๐Ÿ˜ 

              agowa338@chaos.socialA This user is from outside of this forum
              agowa338@chaos.socialA This user is from outside of this forum
              agowa338@chaos.social
              wrote last edited by
              #24

              @bagder

              Didn't they fire everyone in the team that was handling the submissions through that email address a few years ago?

              1 Reply Last reply
              0
              • bagder@mastodon.socialB bagder@mastodon.social

                My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                xenotrope@bsd.networkX This user is from outside of this forum
                xenotrope@bsd.networkX This user is from outside of this forum
                xenotrope@bsd.network
                wrote last edited by
                #25

                @bagder Without going into detail, I once worked for a company that sells a windowing operating system. My team managed e-mail, filtering and archiving, and we escalated a 0-day DNS vulnerability to the relevant dev team for immediate response. It wasn't even in-house DNS software. It was a "here's the BIND patch, go deploy it" situation.

                The dev lead told us that if it was important, we should have brought it up in that morning's shiproom meeting.

                The vulnerability wasn't announced until after the meeting had ended.

                I and a senior ops engineer spent most of that day trying to convey to the senior dev lead that a major security vulnerability was more important than his next two-week ship date.

                1 Reply Last reply
                0
                • tjbutt58@infosec.exchangeT tjbutt58@infosec.exchange

                  @bagder our own IT team are running Office 2016 in a sensitive environment.
                  Why would MS be any better. ๐Ÿ™

                  agowa338@chaos.socialA This user is from outside of this forum
                  agowa338@chaos.socialA This user is from outside of this forum
                  agowa338@chaos.social
                  wrote last edited by
                  #26

                  @tjbutt58 @bagder

                  I once had office 2003 and I'm almost certain that they're still running it to this day. On a Win 2000 server...

                  1 Reply Last reply
                  0
                  • bagder@mastodon.socialB bagder@mastodon.social

                    My not at all surprised face: "After careful investigation, this case has been assessed as not a vulnerability and does not meet Microsoft's bar for immediate servicing."

                    devlead@mastodon.socialD This user is from outside of this forum
                    devlead@mastodon.socialD This user is from outside of this forum
                    devlead@mastodon.social
                    wrote last edited by
                    #27

                    @bagder For NuGet packages, there's beyond "contact owners" also the Report package option, which goes to NuGet support. But found mileage to vary there, too. If you got a package id, I could try to back-channel it. NuGet gallery have option to bot unlist, mark as deprecated, and security advisory.

                    1 Reply Last reply
                    0
                    • enfors@mastodon.socialE enfors@mastodon.social

                      @totenlegionChris @bagder ... second? That's bold of you to assume.

                      totenlegionchris@metalhead.clubT This user is from outside of this forum
                      totenlegionchris@metalhead.clubT This user is from outside of this forum
                      totenlegionchris@metalhead.club
                      wrote last edited by
                      #28

                      @Enfors @bagder I am an thick headed optimist, so I will not bow to reality ๐Ÿ˜‰

                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups