Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Jaroslav Lobačevski 🇺🇦 🇱🇹

@jaras@infosec.exchange
  • Open on infosec.exchange

OpenAI (Open-source Application Insecurity) Researcher at GitHub Security Lab. Opinions are my own. Russian warship go http://f.ck yourself.

0 Followers
0 Following
9 Posts
Joined December 17, 2022

Posts

Open post
jaras
Jaroslav Lobačevski 🇺🇦 🇱🇹 @jaras@infosec.exchange · Mar 21, 2026
Jaroslav Lobačevski 🇺🇦 🇱🇹
@jaras@infosec.exchange

OpenAI (Open-source Application Insecurity) Researcher at GitHub Security Lab. Opinions are my own. Russian warship go http://f.ck yourself.

infosec.exchange

Stay tuned... https://signal.org/security/

3
0
2
0
Open post
jaras
Jaroslav Lobačevski 🇺🇦 🇱🇹 @jaras@infosec.exchange · Mar 18, 2025
Jaroslav Lobačevski 🇺🇦 🇱🇹
@jaras@infosec.exchange

OpenAI (Open-source Application Insecurity) Researcher at GitHub Security Lab. Opinions are my own. Russian warship go http://f.ck yourself.

infosec.exchange

I have a feeling CVE-2025-30066 could have been prevented if the "tj-actions/changed-files" had the repository tag protection setting and the stolen PAT wasn't overprivileged.

1
0
0
0
Open post
jaras
Jaroslav Lobačevski 🇺🇦 🇱🇹 @jaras@infosec.exchange · Mar 04, 2025
Jaroslav Lobačevski 🇺🇦 🇱🇹
@jaras@infosec.exchange

OpenAI (Open-source Application Insecurity) Researcher at GitHub Security Lab. Opinions are my own. Russian warship go http://f.ck yourself.

infosec.exchange

Microsoft Edge is missing an opportunity here. Just keep V2 manifest support and get all uBlock Origin
users fleeing Chrome
https://news.ycombinator.com/item?id=43201974

0
0
0
0
Open post
jaras
Jaroslav Lobačevski 🇺🇦 🇱🇹 @jaras@infosec.exchange · Jul 16, 2024
Jaroslav Lobačevski 🇺🇦 🇱🇹
@jaras@infosec.exchange

OpenAI (Open-source Application Insecurity) Researcher at GitHub Security Lab. Opinions are my own. Russian warship go http://f.ck yourself.

infosec.exchange

I’ve released a new version of the GitHub Actions Permissions monitor. Say goodbye to the annoying “certificate validation” errors of the previous version! Quick info on how it works and what’s new.

The monitor action (https://gh.io/actions-permissions) installs a local @mitmproxy@bird.makeup in the actions runner. During a regular run the proxy intercepts outgoing requests looking for the GITHUB_TOKEN and maps the requests to the permissions required to these operations.

This allows you to identify the actually used permissions from multiple runs and restrict your GitHub actions usage to the minimal required permissions.

In order to intercept the traffic, the monitor uses a self signed certificate. Some programs use their own certificate stores and don't recognize the certificate, causing “certificate validation” errors. I was fixing it case by case, but it reminded me of a whack-a-mole game.

The new version uses the `allow_host` feature of @mitmproxy@bird.makeup to inject only the requests to GitHub. Actions usually use Curl, JavaScript or GitHub CLI to call GitHub API. These scenarios work well with the custom certificate.

So the permissions monitor is more precise and reliable now, intercepting only GitHub API requests to help you set your permissions correctly. Please give it a try to make your workflows more secure!

3
0
4
0
Open post
jaras
Jaroslav Lobačevski 🇺🇦 🇱🇹 @jaras@infosec.exchange · Jul 06, 2024
Jaroslav Lobačevski 🇺🇦 🇱🇹
@jaras@infosec.exchange

OpenAI (Open-source Application Insecurity) Researcher at GitHub Security Lab. Opinions are my own. Russian warship go http://f.ck yourself.

infosec.exchange

Youtube-dl and yt-dlp arbitrary file write when downloading video from attacker's site. It is a weird case when the same CVE-2024-38519 was assigned to similar but different apps. Well, it is me to blame in the first place to tune the PoC to work on both of them... https://securitylab.github.com/advisories/GHSL-2024-089_youtube-dl/

1
1
1
0
Open post
jaras
Jaroslav Lobačevski 🇺🇦 🇱🇹 @jaras@infosec.exchange · Aug 21, 2023
Jaroslav Lobačevski 🇺🇦 🇱🇹
@jaras@infosec.exchange

OpenAI (Open-source Application Insecurity) Researcher at GitHub Security Lab. Opinions are my own. Russian warship go http://f.ck yourself.

infosec.exchange

It makes me sad as I am Notepad++ user myself. https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/

4
0
2
0
Open post
jaras
Jaroslav Lobačevski 🇺🇦 🇱🇹 @jaras@infosec.exchange · Jun 14, 2023
Jaroslav Lobačevski 🇺🇦 🇱🇹
@jaras@infosec.exchange

OpenAI (Open-source Application Insecurity) Researcher at GitHub Security Lab. Opinions are my own. Russian warship go http://f.ck yourself.

infosec.exchange

RCE in DynamicLinq https://research.nccgroup.com/2023/06/13/dynamic-linq-injection-remote-code-execution-vulnerability-cve-2023-32571/

0
0
0
0
Open post
jaras
Jaroslav Lobačevski 🇺🇦 🇱🇹 @jaras@infosec.exchange · Apr 24, 2023
Jaroslav Lobačevski 🇺🇦 🇱🇹
@jaras@infosec.exchange

OpenAI (Open-source Application Insecurity) Researcher at GitHub Security Lab. Opinions are my own. Russian warship go http://f.ck yourself.

infosec.exchange

I made a thing... or two. GitHub Actions permissions Monitor and Advisor: #GitHubActions #security

https://github.com/GitHubSecurityLab/actions-permissions

Your browser does not support the video tag.
9
0
9
0
Open post
jaras
Jaroslav Lobačevski 🇺🇦 🇱🇹 @jaras@infosec.exchange · Jan 28, 2023
Jaroslav Lobačevski 🇺🇦 🇱🇹
@jaras@infosec.exchange

OpenAI (Open-source Application Insecurity) Researcher at GitHub Security Lab. Opinions are my own. Russian warship go http://f.ck yourself.

infosec.exchange

I am glad to share that CVE-2022-23529 has been withdrawn - there is no room to escape if the attacker already controls the object in memory, even in the latest version of jsonwebtoken library:

8
0
10
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 04:27:02 UTC