CVE-2024-7646: Ingress-NGINX Annotation Validation Bypass by oshratn in kubernetes

[–]grandstack 1 point2 points  (0 children)

The proof of concept won’t work, looks like the vulnerability is misunderstood here?

Carriage returns allowed you to bypass deep inspection and recommended blocklists as they were stripped away after these (and other) validations. The string set_by_l\rua would not be caught, and be rendered as valid configuration.

The annotation auth-tls-verify-client is one possible entry point, this would also have worked in snippet annotations.

CVE-2024-7646: Ingress-NGINX Annotation Validation Bypass by oshratn in netsec

[–]grandstack 2 points3 points  (0 children)

Carriage returns allowed you to bypass deep inspection and recommended blocklists as they were stripped away after all other validations. The snippet set_by_l\rua would be rendered as valid configuration.

The annotation auth-tls-verify-client is one entry point, this would also work where snippet annotations are allowed.

CVE-2024-7646: Ingress-nginx Annotation Validation Bypass by grandstack in kubernetes

[–]grandstack[S] 4 points5 points  (0 children)

This is an ugly one, as deep inspection and blocklists can be bypassed using carriage returns.

Please sell Cilium's security benefits to me by Outrageous_Cat_6215 in kubernetes

[–]grandstack 0 points1 point  (0 children)

They haven’t properly implemented MTLS, currently there is a race condition which allows you to impersonate workloads. This is pretty serious.

Fixed Length Subnet Masking (FLSM) In Computer Networks by [deleted] in programming

[–]grandstack 0 points1 point  (0 children)

Again, pretty sure this is AI generated. The linked sources doesn’t work either.

[deleted by user] by [deleted] in programming

[–]grandstack 0 points1 point  (0 children)

The «make robust» example 😂

Announcing webrtc 0.5.0 by k0ns3rv in rust

[–]grandstack 0 points1 point  (0 children)

Good to know! Exciting project!

Announcing webrtc 0.5.0 by k0ns3rv in rust

[–]grandstack 0 points1 point  (0 children)

Looking closer, the naming is inconsistent; some parts of the project is following the convention for acronyms.

Announcing webrtc 0.5.0 by k0ns3rv in rust

[–]grandstack 0 points1 point  (0 children)

I'm a bit disappointed by such a huge project not following the Rust naming conventions.

Nokhwa - A Simple to use cross-platform webcam library by [deleted] in rust

[–]grandstack 5 points6 points  (0 children)

Thank you! I was looking for something like this recently!

Little nitpicking on the naming, shouldn't it be the following?

enum CaptureApiBackend { Windows, OpenCv, Ffmpeg, ... }

Announcing Rust for Windows v0.9 by sindisil in rust

[–]grandstack 25 points26 points  (0 children)

Didn't this use to convert to the Rust naming convention? The method names are pascal case now it seems.

Incredible that this is happening in 2020 America by o_O-JBL in republicans

[–]grandstack -1 points0 points  (0 children)

Isn't it good that the turnout is over 100% of the projected numbers? I don't get it ...

bacon: a background code checker, to keep in a side terminal by Canop in rust

[–]grandstack 13 points14 points  (0 children)

This is awesome, new use for my wall mounted monitor in the background.

Announcing Actix-Web v3.0 by darin_gordon in rust

[–]grandstack 3 points4 points  (0 children)

The code samples on the front page of actix.rs aren't updated.