Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Harry Sintonen

@harrysintonen@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Infosec consultant at REVƎЯSEC https://reversec.com - Coding, Research + various other interests

0 Followers
0 Following
50 Posts
Joined November 18, 2022
PGP:
https://sintonen.fi/pgpkey.txt
Research:
https://sintonen.fi/advisories/
Github:
https://github.com/piru
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 1w ago
We Finns do love our salty liquorice... https://www.saarioinen.fi/tuotteet/salmiakkimaksalaatikko-350g/?lang=en
Salmiakkimaksalaatikko 350 g - Saarioinen
Saarioinen

Salmiakkimaksalaatikko 350 g - Saarioinen

10
1
4
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 3mo ago
I have consistently refused to engage AI in any tasks that require mental effort. Intuitively, I felt that it leads to laziness and eventual deterioration of problem-solving skills. I still consistently challenge myself by solving already solved problems - not because they haven't been solved well already - but in order to maintain my skills. I can only recommend this approach. https://www.nature.com/articles/d41586-026-01947-1
nature.com
127
8
130
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 3mo ago
I, for one, hail our EU overlords for staying their ground and not bending over to Apple. This EU regulation did not come as a surprise to anyone, and definitely not to Apple. Yet they decided to go all knee-jerky about it. Food for thought: If you cannot implement an AI feature in an interoperable and safe manner, it likely should not be implemented at all.
113
10
53
2
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 2mo ago
Last night I "discovered" a vulnerability in a very widely used open-source tool. The tool is nearly 40 years old, and the vulnerability is at least 28 years old. Interestingly, Apple has a fix included that dates it back to 2008, but it appears for whatever reason the fix never made it to upstream. Result? Everyone else is vulnerable today. I am not pointing fingers here, but clearly something went wrong. I've now reported the issue upstream, which will hopefully eventually lead to a fix being distributed to every affected platform. I am not going to disclose the details of the vulnerability right now, even though the fix has been public for a very, very long time now. As far as I can tell, most Linux and BSD systems are vulnerable right now, so letting coordinated disclosure happen only makes sense. #infosec #cybersecurity #vulnerabilityresearch
36
4
18
1
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 3mo ago

No, the libssh2 vulnerability CVE-2026-55200 isn't end of the world.

  1. You need to defeat ASLR to successfully exploit it. The PoC works only when you disable ASLR. In most realistic use cases you need additional off-band infoleak from the app using libssh2.
  2. You also must somehow convince the victim to connect to your malicious server, OR compromise some existing server to perform the attack.

Calling this a "CRITICAL VULNERABILITY" is dumb.

68
0
45
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 4mo ago

Vulnerabilities found from #curl:

#Mythos: 1
Me: 30

- https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/
- https://sintonen.fi/advisories/

infosec.exchange
137
8
94
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 2mo ago
Back when the "internet" involved expensive phone calls and modems, someone figured out that a video backup system (VBS) could be used to distribute hundreds of megabytes of "backups" between friends by shipping a VHS cassette in a padded envelope. You just needed a VCR (everyone had one), and a small harness that could sample the video signal from the VCR for the software to decode. Interestingly, the Video Backup System website is still up: http://www.hugolyppens.com/VBS.html I'm sure someone used this thing for actual backup purposes as well...
hugolyppens.com

Video Backup System Amiga

38
10
35
1
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 3mo ago
Heads up to anyone using #AMD CPUs in a setting where Transparent Secure Memory Encryption (TSME) is critical: AMD has disabled this feature for consumer AMD products as of the latest AGESA updates. The feature is now only available for "PRO" CPU variants. https://arstechnica.com/security/2026/06/users-cry-foul-after-amd-stripped-memory-crypto-from-its-consumer-cpus/ #enshittification
arstechnica.com
52
1
56
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 3mo ago
Significant number of vulnerabilities fixed in #OpenSSL - https://openssl-library.org/news/secadv/20260609.txt The most serious one is CVE-2026-45447: Use-After-Free in the PKCS7_verify() Function that could lead to remote code execution in some conditions. #CVE_2026_45447
openssl-library.org
44
0
47
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 3w ago
Replying to
@dirkdierickx@mastodon-belgium.be Remarkably the basic theory of operation hasn't changed significantly in about 70 years. Vertically locating head was replaced with multiple heads, the head was put on a pivot arm, but other than that the developments have mostly been just making things smaller and faster.
2
1
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 3mo ago
Risto Mikael Riihimäki, owner of Rent ja Kalusto Oy, has been sentenced to three years and 8 months in prison for a aggravated regulatory offence. The company delivered 135 trucks and 29 trailers to Russia, circumventing the EU sanctions. In court, the company claimed that the items were destined for Kazakhstan or Turkey, but Finnish officials were able to recover the communications between Riihimäki and his Russian contacts, making it clear where the items were really destined. The company was sentenced to lose the 608275€ profits from these dealings, fined 10000€, and equipment worth 6 million € confiscated.
24
1
23
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 2mo ago
Yet another linux LPE to root. "CVE-2026-64564: Linux SCTP ASCONF transport UAF leading to local privilege escalation and container escape" https://www.openwall.com/lists/oss-security/2026/08/06/3 #CVE_2026_64564 #infosec #cybersecurity
openwall.com
9
4
6
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 2mo ago
Replying to
Here's my older mitm-to-SYSTEM vulnerability writeup for anyone interested: https://sintonen.fi/advisories/n-able-ecosystem-agent-improper-certificate-validation.txt N-able dismissed this as low level finding.
sintonen.fi
5
0
3
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 3mo ago
Replying to
https://fightchatcontrol.eu/#contact-tool #fightchatcontrol #chatcontrol
fightchatcontrol.eu
4
1
6
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 3mo ago
3
1
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 5mo ago

Several vulnerabilities in #Apache HTTP Server 2.4 have been fixed in release 2.4.67. The most severe of these are:

- CVE-2026-23918: Apache HTTP Server: http2: double free and possible RCE on early reset

- CVE-2026-24072: Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr

- CVE-2026-33006: Apache HTTP Server: mod_auth_digest timing attack

https://httpd.apache.org/security/vulnerabilities_24.html

#CVE_2026_23918 #CVE_2026_24072 #CVE_2026_33006 #infosec #cybersecurity

infosec.exchange
6
0
8
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 5mo ago
Replying to
@rebane2001 This reminds me of a certain provider who used to have a pre-created user on the default Linux image with a password the same as the username. The user was in sudoers. This user account wasn't documented anywhere. So even if you changed the root password, all systems set up with that image remained trivially exploitable over ssh.
5
0
1
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 5mo ago
Replying to
You can use the following the check if the mitigation has been applied correctly: python3 -c 'import socket; s=socket.socket(38,5,0); try: s.bind(("aead","authencesn(hmac(sha256),cbc(aes))")) print("AEAD interface present") except OSError: print("AEAD interface disabled")'
5
0
6
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 4mo ago
Replying to
@gnirre@mastodon.social None.
3
1
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 5mo ago
Replying to
Certainly, it was a different time back then, but the huge spying incidents related to the US nuclear program had already happened. It boggles my mind that Los Alamos National Laboratory would just hand out any hardware to third parties, rather than just destroying it.
1
2
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 5mo ago

Reminder to anyone using #ApacheCamel SCP/SFTP connections: Apache Camel does not perform host identity validation unless you explicitly configure "StrictHostKeyChecking" as "yes". The default value for "StrictHostKeyChecking" is "no". If you do not explicitly configure this option as "yes", the connections are susceptible to meddler in the middle attacks.

What is the impact of such insecure configuration?

If you are using SSH password authentication, the attacker in a privileged network position can perform full MiTM, grab the username and password, and thus gain authenticated access to the target server.

If you use a key-based authentication, the attacker cannot perform full MitM. However, they can still present a fake server and, in case of upload, steal the uploaded files. In case of download, the malicious server can present fake or malicious files for download.

So, any configuration that could get intercepted MUST always specify the host identity and use "StrictHostKeyChecking" "yes". Even configurations in secured networks should use "yes" for additional security.

Unfortunately, the Apache Camel documentation isn't clear on this topic, and the OpenSSH's similar option and its default value working in a different manner can easily lead to confusion and insecure configurations.

#insecuredefaults

infosec.exchange
1
0
6
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 5mo ago
Replying to
In other news: UK Biobank health data listed for sale in China, government confirms https://www.bbc.com/news/articles/cpvxgl3n138o
bbc.com
1
0
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 1mo ago
I've been quite happy with #Strongbox password manager. I migrated years ago from 1Password when they dropped functionality I needed and revoked the lifetime subscription.
0
1
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 2mo ago

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

  • CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
  • CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
  • CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
  • CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
  • CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
  • CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/

#infosec #cybersecurity

bouncycastle.org
0
0
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 4mo ago
Replying to
@lordkhan@social.cologne In terms of energy and resource consumption, very likely so.
0
0
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 2mo ago
#Amazon #CloudFront seems to having global issues. https://health.aws.amazon.com/health/status
health.aws.amazon.com

View the overall status and health of AWS services using the AWS Health Dashboard.

0
0
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 1mo ago
Replying to
@andrew@this.wplr.rocks It should be noted though that the container format it uses is the Keepass one, so it can be accessed with regular Keepass client - I use #KeepassXC on Linux to access it. Of course on macOS and iOS I use the native Strongbox client.
0
0
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 2mo ago
#Engadget, yes we do have a reason not to watch #Babylon5 from YouTube.
0
0
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 2mo ago
13 2026-07-24 16:23:31 +0000 error: Corrected error, no action required., CPU 2, bank Unified Memory Controller (bank=17), mcg mcgstatus=0, mci CECC, mca DRAM ECC error. Ext Err Code: 0 Memory Error 'mem-tx: generic read, tx: generic, level: L3/generic', memory_channel=0,csrow=0, mcgcap=0x0000011c, status=0x9c2041000000011b, addr=0x72fb55480, misc=0xd01a000101000000, walltime=0x6a639183, cpuid=0x00a20f10, bank=0x00000011, microcode=0x0a201030 #ECCMemory saving the day.
0
0
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 1mo ago
Replying to
I should also add that I added the very bug myself years before. That kind of dampened by joy of root cause discovery. 😆
0
0
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 2mo ago
#openai #huggingface
0
0
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 2mo ago
Replying to
@icing@chaos.social "We must also get on the doom marketing bandwagon, or get left behind!"
0
0
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 2mo ago
Replying to
@VictoriaFerryRetroGeek@piaille.fr Negative bit number isn't necessarily incorrect. The CPU internally modulo the bit number by 32, even if negative. Thus, for example: btst #-32,d0 btst #-64,d0 btst #-96,d0 All those btst are entirely valid, and the same as btst #0,d0. The question is if the value is actually correct (even if negative). If it is not correct then this is a problem indeed.
0
0
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 2mo ago
40 years of #Byterapers: 1986: https://www.youtube.com/watch?v=txaIWaT6zik 2026: https://www.youtube.com/watch?v=TmwjZ33ID5k (Assembly 2026 #democompetition winner) Congratulations on continuing to be awesome! #demoscene
0
0
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 2mo ago
"Embargo klo 01:00" ja juttu julkaistu 00:01 - nyt ei kai ihan mennyt niin kuin suunniteltiin. #yleisradio
0
0
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 1w ago
#Debian [DSA 6528-1] linux kernel #security update has fixes to 1313 CVEs. https://lists.debian.org/debian-security-announce/2026/msg00441.html
lists.debian.org

[SECURITY] [DSA 6528-1] linux security update

0
0
6
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 2mo ago
VESA Monitor Control Command Set (MCCS) standard "Asset Tag" function has a gaping flaw. The key is 16-bit and there is no rate limiting. 🤦‍♂️
0
0
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 2mo ago
"As was standard in our cyber testing, we had intentionally permitted internet access, and model-provider cyber classifiers were deliberately disabled" 🤦‍♂️ What exactly did they expect would happen when following such policy? ref: https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing
AI Security Institute

Incident Report: unsanctioned agent behaviour during cyber testing | AISI Work

0
0
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 2mo ago
Replying to
@gabrielesvelto@mas.to Indeed, "RAID is not a backup". This is why in my own setup I have important zfs datasets backed up to second onsite pool with syncoid and really important data also to a remote server.
0
0
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 1mo ago
Replying to
Since they feel so strongly about helping the #curl project I told them to look into https://curl.se/sponsors.html
curl.se

curl - Project Sponsors

0
0
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 3mo ago
I've started to outright block accounts posting AI slop or parroting AI company PR statements. Life is too short.
0
1
0
0
Open post
Harry Sintonen @harrysintonen@infosec.exchange
· 3mo ago
Replying to
@GossiTheDog@cyberplace.social I was a LPB using uni network. 😄
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 17:24:55 UTC