ok this project now has protection against directory traversal attacks (more because I'm bound to fuck something up than because of actual attackers tbh)
ok this project now has protection against directory traversal attacks (more because I'm bound to fuck something up than because of actual attackers tbh)
New bot just dropped!
This bot checks CVE descriptions for the string `../`[1] & posts any new here.
Posts contain one CVE as well as the description & some (sometimes vendor-themed) #directorytraversalmemes . Posts are at most hourly & unlisted, working through the backlog as required. Expect about 1-2 posts per day on average.
@nyanbinary will gladly accept new memes (generic or vendor specific).
[1]: "But nyan, why don't you use CWE-22 and children": Because thats >800 this year so far & this is a shitpost bot, not actual threat intel, you want to go to #GAYINT for that. The bot repo contains a "library" including a function to filter for these if you actually care.
Edit: This bot now uses a set of CWEs + string search for ../ because SOME CNAs (*cough* Linux) couldn't behave themselves & added ../ in description strings to describe paths.

ER: plz add #fuckCloudflare and #directoryTraversalMemes to the algo
return of the slash
you know that i’ll be ../

And a really quick and dirty ../ edit since this is what and who it originally reminded me of. @cR0w