Elektrine lite

← Feed

"Mutant Rob" Robert Rothenberg

rrwo@infosec.exchange

<p>I was born on the Moon but kidnapped by astronauts and raised in the suburbs of Grumman. Eventually, I drifted along the Gulf Stream to Northern Europe.</p><p><a href="https://infosec.exchange/tags/Perl" class="mention hashtag" rel="tag">#<span>Perl</span></a> <a href="https://infosec.exchange/tags/InfoSec" class="mention hashtag" rel="tag">#<span>InfoSec</span></a></p>

Posts

  • Post #4176012

    I&#39;ve uploaded a new version of Plack-App-Prerender to #CPAN This is a #Plack #Perl application for a pre-rendering proxy using Chrome. This version fixes a potentially critical security issue, so if you use it, please upgrade ASAP. https://metacpan.org/release/RRWO/Plack-App-Prerender-v0.3.0

  • Post #4144529

    Catalyst::View::Wkhtnltopdf new version uploaded to #CPAN with documentation and bug fixes https://metacpan.org/release/RRWO/Catalyst-View-Wkhtmltopdf-v0.6.3 #Perl #Catalyst

  • Post #4068777

    I&#39;ve taken over maintenance of Catalyst::View::Wkhtmltopdf, and released a new version with a security fix, among other changes. This is a view that returns a PDF instead from a HTML template. https://metacpan.org/release/RRWO/Catalyst-View-Wkhtmltopdf-v0.6.0 Note that #wkhtmltopdf is no longer maintained. This module will soon be deprecated. #Perl #Catalyst #CPAN

  • Post #4007341

    Back in April the #Perl NOC turned off the #CPAN mail forwarding. https://log.perl.org/2026/04/cpanorg-email-forwarding-has-been-shut.html If you&#39;re like me, you&#39;ve been using that for 25+ years, and it&#39;s everywhere (and unfortunately that includes spammer lists). Here&#39;s what you can do in the meantime, via @timlegge@mas.to @cpansec@fosstodon.org https://security.metacpan.org/2026/06/14/cpan.org-email-forwarding-shutdown.html

  • Post #3830386

    I have a question about potential #Perl search modules to use. Search::Xapian is no longer being actively maintained. Lucy is retired. Are there good replacements?

  • Post #3070856

    The tech industry habit of asking&quot;Do you consent? Yes or Maybe Later&quot; started in the 1990s with web browsers complaining that they weren&#39;t the default app.

  • Post #3070855

    So Google decides to rebrand and change the app icons again... and I will be confused for a few days because marketing is more important than usability.

  • Post #3070854

    I received one of my favourite* kind of bug report emails today. The entire message was: &quot;The website doesn&#39;t work&quot; Why it&#39;s obvious. I&#39;ll fix that error right away. Not really but it&#39;s Thursday and I want to seem cheerful.

  • Post #3070853

    I&#39;ve uploaded a new #Perl module to #CPAN https://metacpan.org/release/RRWO/Dist-Zilla-Plugin-AutomationPolicy-v0.1.1

  • Post #3070852

    What&#39;s worse than an inconsistent API? How about one that doesn&#39;t behave as documented? What&#39;s worse than that? Getting AI slop response from support that ignores the question and refers to the incorrect documentation. Edit: I suspect the API and the docs have been written by &quot;AI&quot;.

  • Post #2020635

    &quot;575 Pull Requests in Three Weeks: What Happens When #AI Meets #CPAN Maintenance&quot; This is an interesting read, including the comments. https://blogs.perl.org/users/todd_rinaldo/2026/04/575-pull-requests-in-three-weeks-what-happens-when-ai-meets-cpan-maintenance.html #Perl #LLM #Claude

  • Post #1954140

    &quot;Musk&#39;s AI told me people were coming to kill me. I grabbed a hammer and prepared for war&quot; Adam is one of 14 people the BBC has spoken to who have experienced delusions after using AI. They are men and women from their 20s to 50s from six different countries, using a wide range of AI models. https://www.bbc.co.uk/news/articles/c242pzr1zp2o In case you know of someone caught up in LLM mania https://www.thehumanlineproject.org/

  • Post #1090230

    Are you still using the 2-argument open? (A short post on @cpansec by me.) https://security.metacpan.org/2025/06/06/two-arg-open.html #perl #security #infosec

  • Post #1090227

    Vulnerabilities in the #Perl JSON::XS, Cpanel::JSON::XS and JSON::SIMD modules via @cpansec If you have applications that handle JSON from untrusted sources (e.g. a web API), then you need to upgrade. CVE-2025-40928: JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact CVE-2025-40929: Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing...

  • Post #1090226

    The @cpansec CPAN Author&#39;s Guide to Random Data for Security has been updated. https://security.metacpan.org/docs/guides/random-data-for-security.html #perl #cpan #security

  • Post #1090225

    CVE-2025-40925: Starch versions 0.14 and earlier generate session ids insecurely via @cpansec https://lists.security.metacpan.org/cve-announce/msg/32910601/ #perl #cve #security

  • Post #978383

    It seems that the residential proxies have shifted to using Dominican IP addresses for the past few days. I guess when they&#39;ve destroyed the online reputation of one country, they need another to trash. #infosec

  • Post #978382

    MetaCPAN @metacpan now displays security advisories when you are viewing a module with advisories. #Perl #CPAN #security #infosec #CVE @cpansec

  • Post #978381

    A variation of the &quot;make money by not doing what we promised the customer and hope they give up on calling customer service after several tries&quot; business steategy is the &quot;pretend we never received the payment&quot; strategy. I&#39;ve wasted two hours fighting with one company about this. &quot;We bill for the previous month. You owe for January.&quot; &quot;Yes, I paid you in February.&quot; &quot;No, that was the previous month.&quot; &quot;No, December was paid. The bill f...

  • Post #978378

    #TIL that both My Neighbor Totoro and Grave of the Fireflies were released on the same bill in 1988. The dual billing was considered &quot;one of the most moving and remarkable double bills ever offered to a cinema audience&quot;. https://en.wikipedia.org/wiki/My_Neighbor_Totoro#Releaae I&#39;m not sure that I could have watched both films in the same sitting.

  • Post #978377

    It&#39;s 2026 and the solution to many software issues is still &quot;make backups, erase all of the data and reinstall&quot;.

  • Post #978376

    I came across a bug report that I filed 20+ years ago for some software... and I don&#39;t remember what that software even did. I don&#39;t use it anymore.

  • Post #978375

    There&#39;s nothing like starting service with a new company only to receive an email threatening to cancel service within 48 hours because if a payment problem. Bonus: the billing link is at a different website than the company, so it makes one wonder if it&#39;s a very good phishing attempt because your name, email and invoice number might be have been leaked. Extra Bonus: clicking on the link shows an error message that the payment is being processed. Double-Plus-Ungood Bonus: calling cust...

  • Post #332038

    I released a new #Perl #Apache::Session module to #CPAN. This module uses the system source of randomness to generate session ids. https://metacpan.org/dist/Apache-Session-Generate-Random

  • Post #332034

    Just received a spam message with the subject &quot;Your research is invisible to AI&quot;. That&#39;s exactly how I like it so though I suspect if they found my name and email then they are probably scrapping my content anyway.

  • Post #332028

    Rewriting the comments in the website security.txt file: Thank you for reading this. If you have found a bug while using our system, then we would love to hear from you. If you want to test our system for security issues, please contact us first. If you ran some scripts you downloaded from a security forum, and are hoping to get some money, then kindly bugger off. Bug reports that show you haven&#39;t bothered to read this will be ignored. Bug reports written using AI slop machines will be...