Advertisement · 728 × 90

Posts by David Leadbeater

(Also renamed this account as then it’s clearer in clients what’s happening, I think.)

4 months ago 0 0 0 0

Yeah, shame, would be nice to do it transparently. Mostly I kept forgetting to check Bluesky so figured if I could have everything in one place it would be nicer and aside from this bit it seems this should be possible.

4 months ago 0 0 0 0

I apparently don’t understand how Bluesky works, this account was @dgl.cx but I switched it to use @ap.brid.gy by changing the DNS records. However there doesn’t seem to be a Mastodon like way to migrate followers. So you might need to refollow this same handle @dgl.cx to get future updates.

4 months ago 0 0 2 0
Bash a newline: Exploiting SSH via ProxyCommand, again (CVE-2025-61984)

You have a bash command line of "exec program ..." and you control "..." can you make it do something different? What if it is somewhat sanitised for shell metacharacters? If you can inject $[+] it will make bash error on that line and run the next. This is how dgl.cx/2025/10/bash... works.

6 months ago 1 0 0 0
Preview
Developers, the weakest link in the supply chain? BSides Canberra 2025 Supply chain security is a topic which has been raised in profile in recent years through events such as the xz backdoor. In the open source world trust matters a lot. While trust is mostly gained thr...

I'll be speaking at BSides Canberra: cfp.bsidescbr.com.au/bsides-canbe... -- this will cover my recent find of an RCE in Git (dgl.cx/2025/07/git-...) and how that and some other vulnerabilities could be used against developers.

8 months ago 2 0 0 0
Déjà vu: Ghostly CVEs in my terminal title

New blog post: Ghostty 1.0.0 terminal security; dgl.cx/2024/12/ghos... (CVE-2024-56803)

1 year ago 11 3 1 0

That's some twisted spire.

1 year ago 0 0 0 0
Advertisement

Since Apple discontinued the iPhone mini. Because Apple define market segments…

1 year ago 0 0 0 0
terminal smooth scrolling

Would be fun combined with the old style VT smooth scrolling… flak.tedunangst.com/post/termina...

1 year ago 0 0 0 0