Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

wdormann@infosec.exchangeW

wdormann@infosec.exchange

@wdormann@infosec.exchange
About
Posts
123
Topics
28
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • Somebody released a PoC for Firefox CVE-2026-8389, and it works.
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    Somebody released a PoC for Firefox CVE-2026-8389, and it works.

    The PoC doesn't include a sandbox escape, and claims that poc-win-sbx.html includes the escape. This file was not shared in the repo.

    The python server on localhost seems unnecessary, as the exploit web server can surely serve up primer.js the first time that payload.js is requested, and the actual payload.js the second time. πŸ€”

    Uncategorized

  • https://access.redhat.com/security/cve/cve-2026-10840
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    @FritzAdalis @cR0w

    Uncategorized

  • https://access.redhat.com/security/cve/cve-2026-10840
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    @cR0w
    "Don't have YouTube"...
    YouTube is a website?

    Uncategorized

  • https://access.redhat.com/security/cve/cve-2026-10840
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    @cR0w
    https://www.youtube.com/watch?v=aW2LvQUcwqc

    Uncategorized

  • An 8TB hard drive that was $129.99 a year ago is now $299.99.
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    An 8TB hard drive that was $129.99 a year ago is now $299.99.

    Thanks, AI. You're really making the world a better place.

    Uncategorized

  • In preparation for an upcoming blog post, I wondered about the various ways that Windows can refer to a remote WebDAV resource.
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    @GossiTheDog
    At least in my case, that's covered by the \\example.com\pwned.exe case.

    Uncategorized

  • In preparation for an upcoming blog post, I wondered about the various ways that Windows can refer to a remote WebDAV resource.
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    In preparation for an upcoming blog post, I wondered about the various ways that Windows can refer to a remote WebDAV resource.

    These all work:

    \\example.com\pwned.exe
    \/example.com\pwned.exe
    file://example.com\pwned.exe
    file:/\example.com\pwned.exe
    file:\/example.com\pwned.exe
    file:\\example.com\pwned.exe
    file:////example.com\pwned.exe
    file:///\example.com\pwned.exe
    file://\/example.com\pwned.exe
    file://\\example.com\pwned.exe
    file:/\//example.com\pwned.exe
    file:/\/\example.com\pwned.exe
    file:/\\/example.com\pwned.exe
    file:/\\\example.com\pwned.exe
    file:\///example.com\pwned.exe
    file:\//\example.com\pwned.exe
    file:\/\/example.com\pwned.exe
    file:\/\\example.com\pwned.exe
    file:\\//example.com\pwned.exe
    file:\\/\example.com\pwned.exe
    file:\\\/example.com\pwned.exe
    file:\\\\example.com\pwned.exe

    These don't, presumably because windows treats the leading / as meaning it comes from the local filesystem:

    //example.com\pwned.exe
    /\example.com\pwned.exe
    Uncategorized

  • Once in a blue moon, I see something on Temu that I might consider buying.
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    Once in a blue moon, I see something on Temu that I might consider buying.

    And then I'm bombarded by spinning wheels that land on "one more spin", and then "(up to) 100% off", explosions, confetti, yelling in ALL CAPS, required app install with notifications. At which point I power off my phone and go outside.

    I'm afraid to ask if there is a customer base out there that enjoys this sort of stuff, or if it's merely willing to put up with to maybe get a good deal. Surely it's the former, as otherwise why would the company subject potential customers to it? πŸ€¦β€β™‚οΈ

    Uncategorized

  • Tired of Linux LPEs?Good.
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    CIFSwitch has been assigned CVE-2026-46243.

    Uncategorized

  • GenAI is going great (this is real)
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    @GossiTheDog
    They're on to you.

    Uncategorized

  • GenAI is going great (this is real)
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    @GossiTheDog
    It's weird that something can be on the internet and also be incorrect. πŸ€”

    Uncategorized

  • LOL.
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    @sysop408
    You mean Outlook (classic) or Outlook (new)? πŸ˜‚

    Uncategorized

  • LOL.
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    @autinerd
    How can one have an HTML email without mso-element support? πŸ˜‚

    Uncategorized

  • LOL.
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    @Taco_lad @scottwilson
    I think that wwlib.dll (Microsoft Word) was indpendently developed from IE or any of the other web engines that may be present on Windows.

    Uncategorized

  • LOL.
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    I'm no expert, but I get the impression that Microsoft Word is perhaps not the best choice for rendering HTML content.

    But what else is Outlook supposed to use to render HTML emails? πŸ˜‚

    Uncategorized

  • LOL.
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    LOL. From over at the bad site:

    An html email will crash Outlook.

    Granted, it's "harmless" (stack overflow (exhaustion)), but I dunno... I sort of expect the act of rendering an HTML email that uses CSS to not crash my mail client?

    Uncategorized

  • Android user who is done using the flashlight presses what button?
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    Bonus points:
    Tapping anywhere else on the screen does the exact same thing as the Done button (the flashlight stays on but you see the rest of Android.

    Wonders:
    1) Did they have anyone other than the developer use this dialog before deploying it to the masses?
    2) Why does the Done button even exist?

    Uncategorized

  • Android user who is done using the flashlight presses what button?
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    Android user who is done using the flashlight presses what button?

    Link Preview Image
    Uncategorized

  • Tired of Linux LPEs?Good.
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    Tired of Linux LPEs?
    Good.

    CIFSwitch is for you. It's not quite as universal as recent ones (distro compatibility table), but it works.

    No CVE, as it seems that we don't do CVEs so much these days.

    It's patched in the kernel on May 19, but who knows who is protected. (See comment about no CVE)

    Uncategorized

  • The openSUSE peeps have figured out some crazy compression, it seems.
    wdormann@infosec.exchangeW wdormann@infosec.exchange

    The openSUSE peeps have figured out some crazy compression, it seems. 107.0 B for everything!

    Uncategorized
  • Login

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups