Advertisement · 728 × 90

Posts by RyotaK

Preview
Clone2Leak: Your Git Credentials Belong To Us Introduction Hello, I’m RyotaK ( @ryotkak ), a security engineer at GMO Flatt Security Inc. In October 2024, I was hunting bugs for the GitHub Bug Bounty program. After investigating GitHub Enterprise...

I published a blog post about six vulnerabilities in Git/GitHub-related projects. They all result in credential leakage when cloning a malicious repository, so be sure to update the Git installation!

flatt.tech/research/pos...

1 year ago 8 1 0 0

Thank you so much for reading it!

1 year ago 0 0 0 0

Thank you for reading it ;)

1 year ago 0 0 0 0
Preview
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at Flatt Security Inc. A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt on my router.1 After ac...

If you're interested in the technical details, I wrote the blog post here: flatt.tech/research/pos...

For the further details, please check out the announcement from the OpenWrt team: lists.openwrt.org/pipermail/op... (2/2)

1 year ago 17 8 0 1

[PSA]
If you're using OpenWrt router and have used the Attended sysupgrade, firmware-selector.openwrt[.]org or CLI upgrade previously, I recommend you to re-flash your firmware.

Due to a security issue, it was possible to pollute the firmware images delivered to these tools. (1/2)

1 year ago 9 2 1 0
Preview
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at Flatt Security Inc. A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt on my router.1 After ac...

OpenWrtのビルド用サーバーに脆弱性を報告しました。

Attended sysupgrade、firmware-selector.openwrt[.]orgあるいはCLIからのアップグレードを過去に実施した場合、改ざんされたファームウェアが配信された可能性が完全には否定できないため、ファームウェアの再更新を推奨します。

技術的解説についてはこちらの記事をご確認ください。 flatt.tech/research/pos...

公式からの発表はこちらをご覧ください。 lists.openwrt.org/pipermail/op...

1 year ago 9 2 0 0

そのうちやる: BlueskyとTwitterの自動ポスト

1 year ago 0 0 0 0

ねむ

2 years ago 1 0 0 0
[びじゅチューン!] 何にでも牛乳を注ぐ女 | NHK
[びじゅチューン!] 何にでも牛乳を注ぐ女 | NHK 「びじゅチューン!」は放送後1週間見逃し配信をしています!https://www.nhk.jp/p/bijutune/ts/MPPMVRL98N/plus/?cid=dchk-yt-1912-126-st発想の源はフェルメール「牛乳を注ぐ女」。絵の中の女が注いでいる牛乳が、やけに細く描かれている。これは料理の仕上...

www.youtube.com/watch?v=pia0...

2 years ago 2 2 0 1
Advertisement

ねこぱっぱ

2 years ago 2 2 0 0

Bluesky、まだフェデレーションできないのか

2 years ago 0 0 0 0

Dynamicな波

2 years ago 5 2 0 0

UnstableなTableはかなり嫌だな

2 years ago 2 0 0 0

StableなTable

2 years ago 8 2 0 0

オヤジギャグ系エンジニアであるところの @ryotak.net

2 years ago 1 1 0 0

@ryotak.net 「だいぶTwitterだなぁ」
@ryotak.net 「『だいぶTwitter』の『ダイブツ』の部分」

2 years ago 1 2 0 0

だいぶTwitterの大仏の部分 by RyotaK

2 years ago 1 2 0 0

じゃああねてあさんは邪悪の悪で

2 years ago 2 0 0 1
Advertisement

独自ドメインヨシ!

2 years ago 2 0 0 1