Posts
1311
Following
Hidden
Followers
Hidden
She/Her or It/It's, trans to the people who know me. I'm less active here, oh well...
repeated

A sassy chee to brighten your timeline for a moment. 💜🧡

Arts by Reina (https://vipercrown.com/)

0
4
1
repeated
Low effort Fursuit-Photo posting here.

#Furry #Fursuit #FilmPhotography
0
3
0
repeated

Stefan wants to be your friend! Little character idea i came up with in a recent stream. He is a stray and looking for friends and maybe a home. Be nice to him!

1
4
1
stupid joke
Show content
other companies: we truly are ahead of our time, we have 7-point autofocus and matrix metering and 1/8000s of a shutter speed

pentax: haha 67
0
0
0
repeated

download more ram dot com

0
3
1
repeated
repeated

OMG. -froot bug resurfaced. https://seclists.org/oss-sec/2026/q1/89

I see the headlines, "10 years old bug".

My friends, this bug is older. Much older. Not this particular instance, but it is a classical mistake to make. It's a command line injection when calling the login executable.

Some people point to CVE-2007-0882. Solaris had that, almost 20 years ago.

But it's even older than that. It's so old it predates the CVE system. I don't remember exact dates, but we popped Linux and AIX boxes with that, mid 90s.

But it is *even older* than that. Have a look at System V R4, ©1990, getty calling login with unsanitized input:

https://github.com/calmsacibis995/svr4-src/blob/7dabeda6fc10bd1bbd1a84d502f05642b1bf0c9e/cmd/getty/getty.c#L526

But how deep does the rabbit hole go? When was this bug introduced?

Getty called login with user input since the dawn of time (UNIX V2, 1972):

https://www.tuhs.org/cgi-bin/utree.pl?file=V2/cmd/getty.s

But this predates command line arguments in login:

https://www.tuhs.org/cgi-bin/utree.pl?file=V2/cmd/login.s

So, when did this particular command line feature of login appear?

In the BSD universe, -f was introduced with POSIX compatibilitiy in 4.3BSD-Reno:

https://www.tuhs.org/cgi-bin/utree.pl?file=4.3BSD-Reno/src/usr.bin/login/login.c

But someone paid attention and filtered out user names starting with - in getty:

https://www.tuhs.org/cgi-bin/utree.pl?file=4.3BSD-Reno/src/libexec/getty/main.c

RCS timestamp says 6/29/1990, so same age as SysV R4.

The original 4.3BSD (1986) doesn't filter the user name:

https://www.tuhs.org/cgi-bin/utree.pl?file=4.3BSD/usr/src/etc/getty/main.c

And it does have a -r option in login:

https://www.tuhs.org/cgi-bin/utree.pl?file=4.3BSD/usr/src/bin/login.c

Exploitable? No idea, argv processing might be a problem. I'll find out another day.

In conclusion: bug existed since 1990, it's so easy to make when implementing POSIX that it keeps resurfacing, and at least one person in Berkeley knew since day 0.

0
4
0
repeated

Do not store your Bitlocker encryption keys on Microsoft's servers if your threat model includes governments or law enforcement. As this article points out, this is the result of a design choice Microsoft made. It didn't have to be this way.

https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/

1
4
0
repeated
repeated
as a fedi user, you either only post once every 3 months or you make a post every time you exhale just to let everyone know
2
10
5
repeated

Clep-Karb @ Home 🏠

"Noodle Dragon in front of noodle shop? Now all I need is my noodle bowl to get comfy. Do you want to join?"

📍 Suitwalk Offenburg January
📸 @Setsu

1
7
1
For #fursuitFriday have a mii fox being a bit silly on a plushlife wolf

Photo by @botchFrivarg on my #gl690 #analogPhotography
it's a girl fox falling over on…
it's a girl fox riding the plus…
0
0
1
repeated

Charlotte lotteheartplural/Cinny cinny_heart_plural thetadelta ursaminor treblesand

Edited 1 month ago

dutch trains are digital. either you arrive approximately on time or you do not arrive at all
german trains are satanic. you will eventually arrive but the price in terms of time or sanity may be greater than you intended

5
63
130
repeated
Low effort Fursuit-Photo posting here.

#Furry #Fursuit #FilmPhotography
0
3
1
repeated

Coffeehound RetroSharka 🏳️‍⚧️

"Scanned on the Almighty A1200"

A fine bit of Eric W Schwartz's Amy the Squirrel from a Productions archive CD.

Fierce love for the burning bright in '94, much as it did then for me and still today. 💜

0
2
0
repeated

Posessed 🐾 Speedling for Jeuno

0
4
1
repeated
repeated

what's better than a fox and a german shepherd? well, a fox-shep of course 🍂

0
5
2
mmm could it be i simply don't have a native language?

listening back to my own voice i sure do sound like a foreigner in any language
0
0
0
Show older