| 00:17:13 | | ssss joins |
| 00:18:12 | | ssss quits [Remote host closed the connection] |
| 00:26:00 | | AmAnd0A quits [Ping timeout: 265 seconds] |
| 00:53:05 | | etnguyen03 quits [Ping timeout: 252 seconds] |
| 01:07:32 | | etnguyen03 (etnguyen03) joins |
| 01:23:04 | | IDK quits [Quit: Connection closed for inactivity] |
| 01:44:14 | | etnguyen03 quits [Ping timeout: 252 seconds] |
| 02:12:06 | | sec^nd quits [Ping timeout: 245 seconds] |
| 02:14:58 | | etnguyen03 (etnguyen03) joins |
| 02:17:45 | | sec^nd (second) joins |
| 02:28:14 | | etnguyen03 quits [Ping timeout: 252 seconds] |
| 02:37:13 | | etnguyen03 (etnguyen03) joins |
| 02:44:41 | | icedice (icedice) joins |
| 03:37:16 | <fireonlive> | https://github.com/curl/curl/discussions/12026 |
| 03:37:25 | <fireonlive> | there’s a time now; 06:00Z |
| 03:40:08 | <fireonlive> | so in like 4 hours? |
| 03:40:15 | <fireonlive> | or 3 ig |
| 03:40:32 | <fireonlive> | wait, 2 |
| 03:40:38 | <fireonlive> | dont rely on my for time |
| 03:40:38 | | yzqzss quits [Quit: Reconnecting] |
| 03:40:44 | | yzqzss (yzqzss) joins |
| 03:52:22 | <nulldata> | https://www.youtube.com/watch?v=cRHOcWj--cs |
| 03:52:42 | <fireonlive> | uhh |
| 03:52:48 | <fireonlive> | leaked? |
| 03:52:50 | <fireonlive> | https://gitlab.com/redhat/centos-stream/rpms/curl/-/commit/0783247f07250043dceb74e426f16f9d46147163 |
| 03:53:25 | <fireonlive> | 11h ago too |
| 03:56:33 | <nukke> | Ofc it's fucking red hat leaking it |
| 03:57:39 | <fireonlive> | yuuuup. |
| 04:09:41 | <nulldata> | It's late and I'm tired - if this is the full patch for the CVE it looks like if you use curl with a SOCKS5 proxy there's potential for it to expose local network resources if a URL with a long hostname is passed? |
| 04:14:35 | <nulldata> | Not great, not terrible. With the hype I was expecting an RCE-level issue |
| 04:25:04 | <nukke> | I thought Daniel said the NIST classified it as critical |
| 04:25:10 | <nukke> | Yet he didn't think it was _that_ bad |
| 04:29:51 | <fireonlive> | yeah i was expecting a lot more, unless i'm misunderstanding it too |
| 04:30:06 | | HP_Archivist quits [Read error: Connection reset by peer] |
| 04:31:04 | <fireonlive> | bad for tor users maybe? |
| 04:34:45 | <project10> | seems pretty tame |
| 05:12:41 | | etnguyen03 quits [Client Quit] |
| 05:24:37 | <Barto> | nukke: daniel is not liking the NIST classification of vuln, so it was a reference to this |
| 05:25:11 | <Barto> | nukke: reference: https://daniel.haxx.se/blog/2023/06/12/nvd-damage-continued/ |
| 05:37:29 | <fireonlive> | he said 'HIGH' was 'his' classification and that NVD would probably call it 'CRITICAL' and 'meltdown' |
| 05:39:21 | <fireonlive> | https://twitter.com/bagder/status/1709126845516365886 https://twitter.com/bagder/status/1709171102100885728 |
| 05:39:22 | <eggdrop> | nitter: https://nitter.net/bagder/status/1709126845516365886 https://nitter.net/bagder/status/1709171102100885728 |
| 05:40:39 | <fireonlive> | also: https://twitter.com/bagder/status/1711707869416984788 lol |
| 05:40:39 | <eggdrop> | nitter: https://nitter.net/bagder/status/1711707869416984788 |
| 05:57:38 | <fireonlive> | literally just published now: https://curl.se/docs/CVE-2023-38545.html |
| 05:57:45 | <fireonlive> | "SOCKS5 heap buffer overflow" |
| 06:00:49 | | Mateon1 quits [Remote host closed the connection] |
| 06:02:37 | | Mateon1 joins |
| 06:03:24 | <fireonlive> | https://curl.se/docs/CVE-2023-38546.html libcurl (low) cookie injection with none file |
| 06:08:02 | | Arcorann (Arcorann) joins |
| 06:09:02 | | benjins quits [Read error: Connection reset by peer] |
| 06:14:25 | <fireonlive> | https://daniel.haxx.se/blog/2023/10/11/curl-8-4-0/ |
| 06:15:39 | <fireonlive> | PoC: https://infosec.exchange/@harrysintonen/111214844467791428 ack it leaked but he shut up about it: https://mastodon.social/@bagder/111214818507191934 |
| 06:19:58 | <fireonlive> | blog post: https://daniel.haxx.se/blog/2023/10/11/how-i-made-a-heap-overflow-in-curl/ |
| 06:59:08 | | themadpro quits [Client Quit] |
| 07:01:10 | <project10> | 🥱 |
| 07:01:37 | | Mateon1 quits [Remote host closed the connection] |
| 07:01:43 | <fireonlive> | yeah |
| 07:01:44 | <fireonlive> | lol |
| 07:01:52 | | BlueMaxima quits [Read error: Connection reset by peer] |
| 07:02:04 | | Mateon1 joins |
| 07:02:53 | | Mateon1 quits [Client Quit] |
| 07:03:20 | | Mateon1 joins |
| 07:25:44 | <pabs> | !a https://www.youtube.com/watch?v=Dr5rx1_0DQo -e Died |
| 07:25:58 | <pabs> | woops |
| 07:49:54 | | Mateon1 quits [Remote host closed the connection] |
| 07:53:10 | | Mateon1 joins |
| 08:24:11 | <pabs> | Progress on no-GIL CPython https://lwn.net/SubscriberLink/947138/9322fc57dae65f34/ |
| 08:28:16 | | IDK (IDK) joins |
| 08:36:42 | | lukash94 joins |
| 08:37:50 | | lukash9 quits [Ping timeout: 252 seconds] |
| 08:37:50 | | lukash94 is now known as lukash9 |
| 09:29:45 | | parfait quits [Ping timeout: 265 seconds] |
| 09:41:56 | | parfait (kdqep) joins |
| 10:25:01 | <@JAA> | Very underwhelming curl bug. |
| 10:25:10 | | parfait quits [Read error: Connection reset by peer] |
| 11:00:38 | | qwertyasdfuiopghjkl quits [Ping timeout: 265 seconds] |
| 11:02:08 | | qwertyasdfuiopghjkl (qwertyasdfuiopghjkl) joins |
| 11:04:00 | | qwertyasdfuiopghjkl quits [Remote host closed the connection] |
| 11:04:32 | | qwertyasdfuiopghjkl (qwertyasdfuiopghjkl) joins |
| 11:09:43 | | that_lurker quits [Read error: Connection reset by peer] |
| 11:10:01 | | that_lurker (that_lurker) joins |
| 11:22:50 | | benjins joins |
| 11:31:48 | <AK> | Agreed |
| 11:34:07 | | decky_e_ quits [Read error: Connection reset by peer] |
| 11:34:57 | | HP_Archivist (HP_Archivist) joins |
| 12:04:41 | | katocala joins |
| 12:04:56 | | katocala is now authenticated as katocala |
| 12:17:28 | | katocala quits [Ping timeout: 265 seconds] |
| 12:19:02 | | katocala joins |
| 12:27:38 | <nukke> | My disappointment is immeasurable and my day is ruined. |
| 12:28:09 | <katia> | hey at leat it's not that bad right |
| 12:28:12 | <katia> | :D! |
| 12:28:25 | | katocala is now authenticated as katocala |
| 12:29:28 | <nukke> | I was gonna take PTO at work today but had to cancel so I could patch our servers |
| 12:29:47 | <nukke> | I'm gonna have to write an angry email to Daniel |
| 12:29:54 | | icedice quits [Client Quit] |
| 12:35:46 | | katocala quits [Read error: Connection reset by peer] |
| 12:36:02 | | katocala joins |
| 12:40:40 | | katocala quits [Ping timeout: 265 seconds] |
| 12:40:56 | | katocala joins |
| 13:10:05 | | katocala quits [Ping timeout: 252 seconds] |
| 13:10:28 | | katocala joins |
| 13:30:01 | | katocala quits [Read error: Connection reset by peer] |
| 13:30:36 | | katocala joins |
| 13:54:25 | | etnguyen03 (etnguyen03) joins |
| 13:59:55 | <thuban> | thanks for the curl-bug links, everyone, informative |
| 14:03:03 | | vukky quits [Quit: Ping timeout (120 seconds)] |
| 14:10:35 | | katocala quits [Ping timeout: 252 seconds] |
| 14:10:47 | | katocala joins |
| 14:19:23 | | Arcorann quits [Ping timeout: 252 seconds] |
| 14:20:21 | | icedice (icedice) joins |
| 14:21:41 | | katocala quits [Ping timeout: 265 seconds] |
| 14:22:25 | | katocala joins |
| 14:27:00 | | katocala quits [Ping timeout: 265 seconds] |
| 14:27:18 | | katocala joins |
| 14:36:11 | | katocala quits [Ping timeout: 265 seconds] |
| 14:36:41 | | katocala joins |
| 14:41:23 | | katocala quits [Ping timeout: 252 seconds] |
| 14:42:09 | | katocala joins |
| 14:52:34 | | katocala is now authenticated as katocala |
| 15:03:42 | | vukky (vukky) joins |
| 15:08:52 | | Peroniko (Peroniko) joins |
| 15:13:24 | | Peroniko quits [Ping timeout: 265 seconds] |
| 15:14:17 | | Peroniko (Peroniko) joins |
| 15:14:17 | | Peroniko quits [Max SendQ exceeded] |
| 15:14:43 | | Peroniko (Peroniko) joins |
| 15:15:03 | | Peroniko quits [Remote host closed the connection] |
| 15:30:19 | | etnguyen03 quits [Ping timeout: 265 seconds] |
| 15:49:12 | | knecht4204 (knecht420) joins |
| 15:52:43 | | knecht4204 quits [Client Quit] |
| 15:53:07 | | knecht4204 (knecht420) joins |
| 15:53:48 | | knecht4204 quits [Client Quit] |
| 16:12:29 | | icedice quits [Client Quit] |
| 16:16:43 | | katocala quits [Ping timeout: 265 seconds] |
| 16:23:08 | | BearFortress quits [Ping timeout: 252 seconds] |
| 16:23:49 | | icedice (icedice) joins |
| 16:40:13 | | katocala joins |
| 16:45:04 | | katocala is now authenticated as katocala |
| 17:02:43 | | HP_Archivist_notsignedin joins |
| 17:03:27 | <HP_Archivist_notsignedin> | Not at PC, but I hope we're grabbing TT videos https://www.washingtonpost.com/technology/2023/10/10/tiktok-hamas-israel-war-videos/ |
| 17:14:14 | | HP_Archivist_notsignedin quits [Ping timeout: 265 seconds] |
| 17:14:38 | | etnguyen03 (etnguyen03) joins |
| 17:18:50 | | petrichor (petrichor) joins |
| 17:40:16 | | parfait (kdqep) joins |
| 17:41:18 | | katocala quits [Ping timeout: 265 seconds] |
| 17:42:05 | | katocala joins |
| 17:42:20 | | etnguyen03 quits [Ping timeout: 252 seconds] |
| 18:10:23 | | katocala quits [Ping timeout: 252 seconds] |
| 18:10:39 | | katocala joins |
| 18:32:32 | | katocala quits [Ping timeout: 265 seconds] |
| 18:33:29 | | katocala joins |
| 18:43:10 | | katocala quits [Ping timeout: 265 seconds] |
| 18:44:42 | | katocala joins |
| 18:47:13 | | BearFortress joins |
| 19:06:22 | | katocala quits [Ping timeout: 265 seconds] |
| 19:06:38 | | katocala joins |
| 19:06:49 | | katocala is now authenticated as katocala |
| 19:10:03 | <fireonlive> | https://shadow.tech employee was socially engineered into installing malware |
| 19:11:14 | <fireonlive> | getting a copy of the email from someone one sec |
| 19:12:38 | <katia> | taht's OVH now |
| 19:14:05 | <fireonlive> | email: https://bpa.st/A5SQVV3XXJY5C5RKTEAWNYUVWE |
| 19:14:20 | <fireonlive> | OVH bought shadow.tech? |
| 19:14:23 | <katia> | yeah |
| 19:14:26 | <fireonlive> | oh wow |
| 19:14:27 | <katia> | some tiem ago |
| 19:14:35 | <fireonlive> | missed that somehow |
| 19:15:02 | <fireonlive> | "At the end of September, we were the victim of a social engineering attack targeting one of our employees. This highly sophisticated attack began on the Discord platform with the downloading of malware under cover of a game on the Steam platform, proposed by an acquaintance of our employee, himself a victim of the same attack." |
| 19:15:02 | <fireonlive> | > highly sophisticated attack |
| 19:15:08 | <katia> | >This highly sophisticated attack began on the Discord platform |
| 19:15:10 | <katia> | lol |
| 19:15:12 | <fireonlive> | ikr |
| 19:15:13 | <fireonlive> | lol |
| 19:15:34 | <fireonlive> | may I propose you don't use the same system you use for personal things as your gaming things |
| 19:15:47 | <fireonlive> | to go above that too, your work machine should be separate as well |
| 19:16:03 | <fireonlive> | but at the very least, isolate your gaming |
| 19:16:27 | <katia> | hey yo download this game |
| 19:16:34 | <katia> | free_cupholder.exe |
| 19:16:50 | <fireonlive> | here's it as plain text because that blue on gray looks like butt: https://bpa.st/CVM33MJFOLWFZ4YVHPSGCWT4NE |
| 19:17:11 | <fireonlive> | oooh free cupholder! |
| 19:17:16 | <fireonlive> | *runs as admin* |
| 19:17:29 | | katocala quits [Ping timeout: 265 seconds] |
| 19:17:46 | | katocala joins |
| 19:18:58 | | katocala is now authenticated as katocala |
| 19:23:06 | <HP_Archivist> | RE: From my post earlier. Is there a dedicated channel for Tiktok material? |
| 19:23:32 | | katocala quits [Ping timeout: 252 seconds] |
| 19:24:09 | <fireonlive> | HP_Archivist: #TikOff |
| 19:24:19 | <fireonlive> | no bot/etc that i know of though |
| 19:24:32 | <fireonlive> | HP_Archivist: #TikOff |
| 19:25:00 | <HP_Archivist> | Ahh okay. Thanks ^ |
| 19:27:50 | <Barto> | i was expecting it to be underwhelming, just like that critical openssl bug |
| 19:29:20 | | katocala joins |
| 19:30:36 | | pabs quits [Read error: Connection reset by peer] |
| 19:31:24 | | pabs (pabs) joins |
| 19:37:09 | <nukke> | https://megamansec.github.io/Squid-Security-Audit/ |
| 19:37:22 | <nukke> | 35 0days in squid proxy ouch |
| 19:37:47 | | CandidSparrow quits [Quit: Ping timeout (120 seconds)] |
| 19:38:06 | | CandidSparrow joins |
| 19:40:35 | | katocala quits [Ping timeout: 252 seconds] |
| 19:42:12 | | katocala joins |
| 19:42:21 | | katocala is now authenticated as katocala |
| 19:48:17 | | Irenes quits [Ping timeout: 252 seconds] |
| 19:52:08 | | katocala quits [Ping timeout: 252 seconds] |
| 19:52:55 | | katocala joins |
| 19:53:41 | | katocala is now authenticated as katocala |
| 19:55:03 | <fireonlive> | oh yay i can access my client back |
| 19:55:04 | <fireonlive> | again* |
| 19:55:14 | <fireonlive> | nukke: ooof. glad i don't use that at the moment |
| 19:56:00 | <katia> | tinyproxy seems nice |
| 20:15:14 | | Irenes (ireneista) joins |
| 20:21:08 | | Naruyoko quits [Client Quit] |
| 20:30:08 | | etnguyen03 (etnguyen03) joins |
| 20:31:41 | | Naruyoko joins |
| 20:34:55 | <nukke> | caching is useless anyway. most people have asymmetric 1Gbps fiber nowadays |
| 20:36:21 | <@HCross> | nukke: not in all parts of the world |
| 20:38:44 | | thuban flashes back to https://danluu.com/web-bloat/ |
| 20:41:13 | <flashfire42> | 1Gbps??? |
| 20:42:01 | <fireonlive> | i fuckin' wish |
| 20:42:16 | <fireonlive> | but yeah; i don't want to want to run a tls mitm proxy |
| 20:42:25 | <flashfire42> | https://server8.kiska.pw/uploads/bec4672e9a825705/image.png |
| 20:42:45 | <flashfire42> | if most people have 1Gbps I am getting fucked over |
| 20:50:26 | | etnguyen03 quits [Ping timeout: 252 seconds] |
| 20:52:41 | <katia> | lol |
| 20:54:30 | <audrooku|m> | 50/10 i cri |
| 20:55:14 | <flashfire42> | Which is why I want to configure my warrior to download 1 item at a time but be able to upload up to 10 items at a time but I can't figure out how to make it do that |
| 20:55:27 | <flashfire42> | because my download speed is alright but my upload speed |
| 20:55:29 | <flashfire42> | is yeah that |
| 21:01:35 | | ymgve_ joins |
| 21:01:36 | | benjinsm joins |
| 21:01:51 | | parfait_ joins |
| 21:01:53 | | Naruyoko5 joins |
| 21:01:56 | | AlsoHP_Archivist joins |
| 21:02:48 | | benjins2_ joins |
| 21:05:16 | | Naruyoko quits [Ping timeout: 265 seconds] |
| 21:05:16 | | parfait quits [Ping timeout: 265 seconds] |
| 21:05:16 | | HP_Archivist quits [Ping timeout: 265 seconds] |
| 21:05:16 | | benjins2 quits [Ping timeout: 265 seconds] |
| 21:06:14 | | benjins quits [Ping timeout: 265 seconds] |
| 21:06:14 | | ymgve quits [Ping timeout: 265 seconds] |
| 21:08:20 | | BlueMaxima joins |
| 21:20:01 | | BigBrain quits [Ping timeout: 245 seconds] |
| 21:22:21 | | BigBrain (bigbrain) joins |
| 21:26:03 | | katocala quits [Ping timeout: 265 seconds] |
| 21:26:07 | | etnguyen03 (etnguyen03) joins |
| 21:26:26 | | katocala joins |
| 21:27:25 | | parfait_ quits [Client Quit] |
| 21:34:30 | | BlueMaxima quits [Read error: Connection reset by peer] |
| 21:34:35 | | BlueMaxima joins |
| 21:42:36 | | DogsRNice joins |
| 21:47:06 | <nukke> | you guys don't get fiber?! |
| 22:19:24 | | DogsRNice_ joins |
| 22:21:11 | | DogsRNice quits [Ping timeout: 252 seconds] |
| 22:21:57 | <DogsRNice_> | i sure love when my internet speed drops so low even irc times me out |
| 22:22:17 | <DogsRNice_> | at&t is so cool |
| 22:30:21 | | katocala is now authenticated as katocala |
| 22:48:41 | | etnguyen03 quits [Ping timeout: 252 seconds] |
| 23:56:53 | | katocala quits [Ping timeout: 252 seconds] |
| 23:57:44 | | katocala joins |