Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Alexander Bochmann

@galaxis@mastodon.infra.de
hometown 4.6.8+hometown-1.3.0
  • Open on mastodon.infra.de

generic computer and internetworking geek

network and systems administration, infosec, retrocomputing

#nobot #noindex #nobridge #noai

956 Followers
959 Following
50 Posts
Joined May 07, 2017
languages:
EN, DE, (FR)
home page:
https://web.gxis.de/tiki/
home town:
Freiburg, Germany
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 3mo ago
Ah, so it's that day then after the latest Vivaldi update...
16
4
19
1
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 3mo ago
Considering all of the GPL house of cards is built on the notion that copyright (copyleft) has legal value, I'm really astonished about all these "free software" organizations bending over so they don't appear hostile to code produced with AI contributions (which, according to current assumptions, is not copyrightable as such).
23
3
12
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 1mo ago

WTF? Why has the ssh host key on the VM for my secondary DNS server changed?

1
1
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 1mo ago

Yikes. The RPi I use as an (overly complicated) mobile router still runs Raspbian 11/bullseye

(Hasn't been powered on in a year or so...)

Also I don't have the Wifi password documented anywhere?

1
1
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 2mo ago
Replying to
@masek@infosec.exchange Depends on your hobbies? But yeah, unless you want to run or salvage old stuff, most of these are useless by now. No one's going to come up with new Firewire hardware or such, and VGA is increasingly omitted on both new PCs and new monitors.
2
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 2mo ago
Wonder if this affects Mastodon, via oss-security earlier today: https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm "In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process environment." "An application is affected if it meets all of these requirements: Uses libvips for Active Storage image processing. This is config.active_storage.variant_processor = :vips, which load_defaults 7.0 set and no later default has changed. Allows image uploads from untrusted users." #mastoadmin
GitHub

Possible arbitrary file read and remote code execution in Active Storage variant processing

### Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process envi...

2
5
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 3mo ago
Replying to
@3rz@freiburg.social @aeble@mastodon.eble.name @masek@infosec.exchange I'm using mastodon-archive.py, which also has a regex search function over archived toots: https://jort.link/src.alexschroeder.ch/mastodon-archive.git/
jort.link
3
1
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 3mo ago
Replying to
@masek@infosec.exchange Bei einigen USV-Herstellern gibt's Hinweise, dass ihre Geräte eine echte Sinuswelle auf der Netzseite erwarten, und keine PWM-modulierte von einem Wechselrichter akzeptieren. Kann also davon abhängen, was da aus dem PV-Akku erzeugt wird. (z.B. APC, "If you are using a UPS that outputs a step-approximated sine wave when on battery, as soon as the fist UPS goes on battery, the second UPS will also go on battery because it will see the step-approximated sine wave as distorted or bad power.", https://www.se.com/us/en/faqs/FA157424/#:~:text=If%20you%20are%20using%20a%20UPS%20that%20outputs%20a%20step%2Dapproximated%20sine%20wave%20when%20on%20battery) @EinsTux@chaos.social
se.com
3
7
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 3mo ago
Replying to
@Mastodon@mastodon.social For some reason, the number of scrapers hitting the /explore feed on our instance has dropped significantly after switching the start page to /about (even though the former is still linked from there with the current template). I still wish it was possible to disable /explore and /tags for unauthenticated users (or at least only show local posts) - the effects of these being available still make up for a significant chunk of traffic and media storage. Might not make a difference to mastodon.social, but when you run an instance for a couple hundred users, it's quite tedious to fend off that crap and keep resource usage in check.
2
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 2mo ago
Replying to
@alex@feed.yopp.me Tbh I only read the "The vulnerability in one paragraph" section, everything beyond looks like complete slop for slop processors. Seems like you need to be able to provide a specific version of a matlab file to be routed into a vulnerable decoder for those. I have not immediately seen how to actually triger that, but it reads like the bug is in imagemagick code (not sure if copied over into libvips or by using that as a library).
1
1
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 2mo ago
Replying to
@alex@feed.yopp.me More details on this attack now: https://discuss.rubyonrails.org/t/cve-2026-66066-attack-details-and-tools-to-perform-a-forensic-investigation/91441
[CVE-2026-66066] Attack details, and tools to perform a forensic investigation
Ruby on Rails Discussions

[CVE-2026-66066] Attack details, and tools to perform a forensic investigation

Hello there, I’m writing as a member of the Rails security team about CVE-2026-66066. As mentioned in the advisory, GHSA-xr9x-r78c-5hrm, we held back details about the attack vector to allow applications to be upgraded before malicious attackers could take advantage of the vulnerability. We originally intended to publish these details no later than 2026-08-28, but several researchers quickly reverse-engineered the attack and have already published proofs-of-concept. As a result, we are disclos

1
3
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 5mo ago
Replying to
@cyclopentane @niklaskorz Repeating myself on this, but I have seen two sources of exploding media storage this year: 1) Crawlers hitting public views of timelines, behaving like a web browser, and "viewing" individual posts in thread context. They cause the instance to load remote posts and their attachments, greatly increasing media cache usage. Disabling public access to remote timelines and tags searches in the instance admin Discovery settings helps. 2) Crawlers descending into old posts from Trends, which unfortunately can not be disabled just for unauthenticated users. This causes Mastodon to temporarily re-fetch remote media into the media proxy. Since the crawlers use huge ranges of source IPs, the proxy rate limits are rarely triggered. I'm using this patch for the rate limiter: https://github.com/mastodon/mastodon/issues/37987#issuecomment-3969147018 - though with an additional change that curbs unauthenticated access to 1 per 10 minutes with 'throttle_media_proxy_unauthenticated', limit: 1 instead of 100
GitHub

Bot defense: Disable unauthenticated access to media proxy · Issue #37987 · mastodon/mastodon

Pitch Mastodon should have an admin option to disable unauthenticated access to the media proxy. To my understanding, unauthenticated requests that get punted to the media proxy currently only have...

4
1
4
1
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 5mo ago

Sigh, next round of blocking kernel modules...

https://dirtyfrag.io
https://www.openwall.com/lists/oss-security/2026/05/07/8

#linux

dirtyfrag.io
3
2
12
1
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 2mo ago
Trying to look up web comics from one of my old bookmarks collections... Most of them are offline. Wayback Machine coverage is extremely sketchy, often it's just the splash page, or empty navigation with no images... :flan_sad:
1
1
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 3mo ago
Replying to
@ifin@infosec.exchange The second link in that post currently points to some HP printer thing instead of Tenda on opencve...
1
1
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 3mo ago
Replying to
@waffles@masto.yttrx.com Yeah, when I did that, our scrapers suddenly turned up from sources geolocated to Africa and South America, plus a spatter of western hosting providers and residential IPs...
1
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 3mo ago
Replying to
@gumnos@mastodon.bsd.cafe @homegrown@social.growyourown.services I'd add: Avoid any plans with usage-based billing (like for storage, bandwidth, database transactions) and autoscaling, or at least check you have appropriate limits on everything. It's better to run into availability problems than to run out of money.
1
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 3mo ago
Replying to
@masek@infosec.exchange Ich habe dazu auch keine nützlichen Stichworte gefunden. Weiss nicht ob's sinnvoll ist, mal noch eine Online-USV zu probieren, Deine jetzige scheint Line-interactive zu sein? Vielleicht sind die weniger wählerisch was den Eingangsstrom angeht, weil sie den Output grundsätzlich neu generieren. @EinsTux@chaos.social
1
5
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 5mo ago
Replying to
@drwho @penguin42 @fedops @alexanderkjall The kernel CVE assignment team has their own CNA, but their policy is to tag a CVE to everything that could potentially be a security problem, and they don't usually do scores, so kernel CVEs are nigh useless to track the criticality of security bugs, see https://lore.kernel.org/linux-cve-announce/ (In this particular case, the CVE had a score, which might have served as a signal for something unusual.) The process around disclosure of kernel security problems has been completely dysfunctional for years, and every time something out of the ordinary happens, the same people turn up with the same conflicting viewpoints 🤷‍♂️ Greg KH has written about how the kernel security team handles things earlier this year: https://h.jort.link/www.kroah.com/log/blog/2026/01/02/linux-kernel-security-work/
lore.kernel.org
2
0
1
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 5mo ago
Replying to
@DerMolly Apparently the patch was published a week ago on linux-cve-announce: https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/T/#u I don't think there is still any coordinated disclosure going on for vulnerabilities reported directly to the kernel security team?
lore.kernel.org
2
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 5mo ago

The Atom mini-ITX board in my toolbox PC doesn't have USB3, and only two SATA ports, so that's not enough connectors to copy a TB between two disks and also have a boot device...

So I ended up connecting the boot disk to an IDE-to-SATA adapter (the board does have an additional IDE port for CDROMs), and use the two SATA connectors to move the data...

2
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 4mo ago
Replying to
@aphyr@woof.group Disable public access to Fediverse timeline and hashtag searches as a first step, also see https://mastodon.infra.de/@galaxis/116518564405290149
mastodon.infra.de

Alexander Bochmann: "@cyclopentane@rheinneckar.social @niklaskorz@rhei…" - INFRa Mastodon

1
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 4mo ago
Replying to
@jrenken@mastodon.sandwich.net @tyler@typing.ink @cadey@pony.social There's also an update by the Gentoo dev in https://www.openwall.com/lists/oss-security/2026/05/15/11 saying "What I got mixed up with was that in Gentoo, for some reasons I won't bore readers with, =2 and =3 aren't an option yet [..]", so that's currently a Gentoo-specific limitation.
openwall.com

oss-security - Re: Logic bug in the Linux kernel's __ptrace_may_access() function

1
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 4mo ago
Replying to
@jrenken@mastodon.sandwich.net @tyler@typing.ink A different post in that oss-security thread backs the claim that setting yama.ptrace_scope=[23] is sufficient (for now): https://www.openwall.com/lists/oss-security/2026/05/15/10 @cadey@pony.social
openwall.com

oss-security - Re: Logic bug in the Linux kernel's __ptrace_may_access() function

1
1
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 4mo ago

Finally managed to cancel the VM that had been running my Mastodon instance for a couple of years (everything was migrated off last year, but somehow I wasn't sure if there was some dependency on whatever that I might have forgotten about)...

Oh well, it's powered off now, and will disappear in a month, so I guess I can still grab a couple of files in case anything turns up.

1
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 4mo ago

Random idea to make followers-only posts on the Fediverse less terrible: Always turn replies from followers into DMs to the original sender.

Immediately prevents all the problems with disparate followership and threads that are only partially visible to participants with very little effort.

1
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 4mo ago
Replying to
@thomasbeagle@mastodon.nz It's the wrong nerds, thanks to many of the 1990s nerds being too naive and myopic outside of their own objectives.
1
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 4mo ago
Replying to
...first pass has about halved my active address book. Seems I synced the current incarnation into SOGo in 2017 - I think it got copied around mostly as a bunch of icard files before, but this collection probably started on a Psion S3 after I typed in everything relevant from the paper address notebook? For about a quarter of the people that I moved into the archive I don't even know who they were, right now.
1
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 4mo ago

There's Freeplane as a Flatpak, but I still wanted to use good old FreeMind instead, again...

It doesn't run with Java 21 that Debian (LMDE) brings, and also doesn't do fractional scaling that's best on this display (I use 125% for everything else)...

But I dropped in a download of the Amazon Coretto Java 11 LTS jre (pointing to its directory by setting JAVA_HOME accordingly in .freemind/freemindrc), and created a .desktop file that runs env GDK_SCALE=2 freemind.sh, which makes it almost usable, except everything is slightly too large... Oh well, in a couple of years I'll probably need things at that size as a default...

(I guess there is a way to set environment variables in .desktop files? Didn't check.)

1
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 5mo ago
Replying to
@wdormann@infosec.exchange As I read it, that was an upstream mishap in 6.1, see quote in this previous post (last paragraph in the original linked from there): https://mastodon.infra.de/@galaxis/116506313441423652
mastodon.infra.de

Alexander Bochmann: "Funny, the Copy Fail exploit fails on 6.1 LTS ker…" - INFRa Mastodon

1
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 5mo ago
Replying to
@atarifrosch@mastodon.de mastodon-archive kann einerseits ein Backup der Account-Daten erzeugen und dann andererseits daraus einen Satz HTML-Dateien (mit Bildern, wenn man die mit archiviert hat): https://github.com/kensanata/mastodon-archive#generating-a-html-file Braucht wahrscheinlich noch ein bisschen Arbeit außenrum, um schön auszusehen. Für G+ hatte ich auch mal was, muss aber suchen. Twitter und Diaspora weiss ich nicht.
GitHub

GitHub - kensanata/mastodon-archive: Archive your statuses, favorites and media using the Mastodon API (i.e. login required)

Archive your statuses, favorites and media using the Mastodon API (i.e. login required) - kensanata/mastodon-archive

1
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 5mo ago

Last time I powered on the OpenPandora (maybe a year ago), it had a bright spot in the center of the screen, and I thought the LCD was maybe failing?

Today, it looks just fine (though the battery was completely flat, and charging statistics are confused)...

1
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 5mo ago

The first thing I think when I see the news that "Firefox has integrated Brave's Adblock Engine" is - ah, so they want to get rid of Manifest V2 extensions after all?

(The second is - WTF, why Brave? I mean, we know who's behind that?)

Not that I'm surprised about any bad decision happening over at Mozilla.

1
3
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 5mo ago
Replying to
...an a different note, why do I have xscreensaver on a server?
1
2
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 5mo ago
Replying to
Hrm, the default for zonefiles-write is 3600 seconds, so it should have updated those at some point? A "nsd-control write" issued manually created the missing files, so IDK what's up with all this. Guess I'll check tomorrow if the new files are still unchanged.
1
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 1mo ago

Somehow the Document Scanner application in Linux Mint / LMDE has regressed?

It used to be able to work with my document scanner just fine, but now it only scans the front side of a paper, even when told to scan both...

0
1
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 5mo ago

#np: Roxy Music - for your pleasure

https://www.youtube.com/watch?v=XUhYAcgmTtU

For your pleasure in our present state
Part false, part true, like anything
We present ourselves

[..]

The instrumental part reeks of desolation to me (fittingly, following "through every step, a change / you watch me walk away")...

mastodon.infra.de

INFRa Mastodon

0
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 5mo ago

Underground parking, empty.

0
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 5mo ago
Replying to
I could probably create a dedicated bridge for this container (connected to the uplink network interface) and just use the floating IP directly, with not NAT? Don't think that's how it's supposed to be done though.
0
4
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 3mo ago
I added a throttle for unauthenticated accesses to /tags on our public Mastodon instance. The rate limit of 50 in 10 minutes triggers quickly, and for the first time this year, our media cache usage has been slightly decreasing since. A toggle to completely disable unauthenticated access to hashtag search would curb the current wave of scrapers quite effectively. #mastoadmin
0
2
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 4mo ago

#np: Georgia Knight - not bad at all

https://georgiaknight.bandcamp.com/track/not-bad-at-all

mastodon.infra.de

INFRa Mastodon

0
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 5mo ago
Replying to
@sbeyer@ioc.exchange @alfonsosiciliano@mastodon.bsd.cafe ...and every couple of years, someone somewhere rewrites an OS installer, making everything much easier without all these weird edge cases, and surely there can't be any good reason against sorting timezone options alphabetically and make the one appearing first the default selection...? Yeah, sigh.
0
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 4mo ago

Wat, Stripe unterstützt Wero als Bezahloption? Und hier quängeln alle weil noch ein Bezahlding ja ach so kompliziert ist?

0
0
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 5mo ago
Replying to
@yala@degrowth.social I wouldn't label that as a conclusion, more of a gut feeling? I fully expect the Firefox people to push out alternative solutions as soon as they are satisfied with an own adblock engine. At the same time, the kind of access that extensions have under V2 is a real problem as the general environment gets more hostile (like supply chain attacks on extension developers, or buyouts by untrustworthy 3rd parties), so I think Mozilla is going to be pressured to lock down their extension ecosystem.
0
2
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 5mo ago
Replying to
@yala@degrowth.social This is on a Netcup VM, and when you order additional IPv4 from them, you just get a random address from one of their allocations, usually outside of the network your main address is in. Should still work as a pointopoint interface when assigned directly to a container on a bridged network, but I don't particularly like that kind of setup either. IPv6 would be less of a problem (but I primarily need IPv4 connectivity in this case). Anyway, I thought there maybe would be some configuration like floating public IPs in Openstack, where you just map one to a VM, and Openstack does all the NAT magic for traffic towards the Internet.
0
2
0
0
Open post
Alexander Bochmann @galaxis@mastodon.infra.de
· 2mo ago
Replying to
@misty@digipres.club Thanks!
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 04:53:35 UTC