Post #1777561
2026-04-29 08:54 UTC
Replies (9)
-
@sash@hachyderm.io 2026-04-29 08:56
My disclosure process with RIPE NCC took 14 months, 26 messages, and included two incorrect fixes for the same vulnerability. I wrote about the process, with thoughts on what better would look like for RIPE NCC and others: https://mxsasha.eu/posts/ripe-ncc-disclosure-retrospective/
-
@wall_e@ioc.exchange 2026-04-29 09:11
@sash amazing work!
-
@nyanbinary@infosec.exchange 2026-04-29 09:37
@sash this is very cool & absolutely gets me thinking about the need for separating standard sessions/identities from administrative sessions again :neobot_giggle:
-
@jeroen@secluded.ch 2026-04-29 09:46
@sash Great work Sasha (as many other things you have done! :), and thank you for responsibly disclosing it and patiently working with them to properly resolve it.
-
@photovince@mastodon.social 2026-04-29 09:50
@sash 🙏 And we live another day
-
@nicksilkey@hachyderm.io 2026-04-29 10:07
@sash thank you for your service - and a great write up for all on your discovery! ✌️💙
-
@rmd1023@infosec.exchange 2026-04-29 16:47
@sash Interesting!
-
@fanf@mendeddrum.org 2026-04-29 13:39
@sash « I stumbled into the first vulnerability while debugging the reverse DNS zone for my IPv6 range in RIPEstat, RIPE NCC’s network information tool. A blue marquee started scrolling across the page, from an XSS payload I had put in my DNS server months earlier. » actual irl lol, excellent work
-
@theorangetheme@en.osm.town 2026-04-29 18:25
@sash This is phenomenal! I'm reading this on my lunch break.