Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

chaos

@chaos@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange
0 Followers
0 Following
4 Posts
Joined November 05, 2022
blog:
https://scumjr.github.io
Open post
chaos @chaos@infosec.exchange
· 35mo ago

And here we go for the 2nd blog post about a vulnerability in Mastodon. It details how HTTP signatures can be bypassed because of an innocuous bug, and how it can lead to the spoofing of Mastodon instances depending on their domain name. Don't worry, infosec.exchange wasn't vulnerable ;)

https://scumjr.github.io/2023/11/07/usurping-mastodon-instances-cve-2023-42451/

scumjr.github.io
28
2
20
0
Open post
chaos @chaos@infosec.exchange
· 36mo ago
Replying to
The first blog post details a SSRF vuln in Mastodon, which leads to arbitrary code execution. No need to freak out, the vulnerability doesn't exist in prod in default configuration, and affected versions are limited to pre-releases. https://scumjr.github.io/2023/10/12/from-ssrf-to-rce-on-mastodon-cve-2023-42450/
scumjr.github.io
0
0
2
0
Open post
chaos @chaos@infosec.exchange
· 5mo ago

@tanavit@toot.aquilenet.fr @MonniauxD@social.sciences.re "Command & Control": ce sont le ou les serveurs utilisés par les attaquants pour communiquer avec les systèmes compromis.

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:59:59 UTC