Martin Seeger

3.6K Followers
286 Following
18.4K Posts

Working at front lines of the IT and having fun there. Been around the Internet since 1992 and still in awe what has become of that little baby. Currently wanted for repeated "Nerd Sniping" on all continents.

Personal interests:

- IT Security
- Computer Games & TTRPGs
- Cycling
- Cooking & Baking
- Books, Movies, TV-Series (mostly F&SF)
- 3D printing (new!)
- Everything that blinks, has buttons to press and looks remotely gadgetoid

Everything i write, post, tweet, blog or blurp is just my personal opinion and is not the opinion or policy of my employer, my cat or my goldfish.

I post in English and German. Will try to mark each post correctly, but errors happen. Sorry for that.

I apologize if I am not following you back. This happens as my stream is already getting more posts than I can read.

Signalhttps://signal.me/#eu/UCIZRNn72tPSdaqYa4KBK3UBwwJD0jYCP0A5FCTw8NO2nRujm6JJsKWa0hAIlM2Q
Threemahttps://threema.id/RR6MJMU5
BLOGhttps://blog.literarily-starved.com/
LC_LANGen_EN, de_DE
LocationEurope, Germany, Schleswig-Holstein, Kiel/Kronshagen

Das ist echt faszinierend:

  • Drei mal 50cm Styroporplatten mit Einwuchssperre
  • Dann einen diicke Betonplatte
  • Dann eine dicke Schicht Kies
  • Dann eine dicke Schicht Schotter
  • Dann noch einmal 30cm Asphalt

Die Straße geht da so ca. 2.50m tief in den Boden....

B76 bei Plön: Erste Sanierung einer Bundesstraße mit Styropor | NDR Info

YouTube

Is there, by any chance, a union for “people trying to save the world without a mandate” or something along those lines?

I may have a few comments regarding the working conditions 😄

Gibt es irgendwo eine Gewerkschaft für "Menschen die ohne Mandat die Welt retten" oder so?

Ich hätte da ein paar Anmerkungen zu den Arbeitsbedingungen 😄.

I promise this is not AI.

This is the sitting US president trying to convince the press, that he is doing important work, because he is renovating the pool in the local park, and that pool is longer than some skyscrapers.

This is what the US president is doing for his people, while the US economy is in tatters, Putin is waging war against Europe and and the Hormuz Strait is blocked.

A pool length measuring contest.

Insane.

A friend of a friend is missing - please boost 💔

#twitch #twitchcon #Netherlands

Happy Pride Month!

Rainbow Railroad is an organization which helps LGBTQ+ people flee dangerous regimes.

They’ve had a surge in requests from Americans looking to escape Trump.

No one is “safe” under fascism.

The tyrants start with the most marginalized.

They don’t stop there.

I found that crafted #MeshCore node names could compromise #HomeAssistant instances running meshcore-card, with an XSS leading to remote root access on the HA host. An attacker could then access anything controlled or visible through Home Assistant. The attacker doesn't need to be near the target, as MeshCore advertisements are repeated over the mesh, which is dense in NL.

This also affects around 20 public MeshCore analyzer websites. Some of those run CoreScope, where it looks like a vibecoding bot broke the XSS filter while hallucinating a bugfix. The analyzers are mostly public data though. In addition, the less popular MeshCore-Home-Assistant-Panel-v2 is likely also affected, but I was unable to make contact with the maintainer.

MeshCore node names are only 32 bytes, and each rendered in a different place in the page, so I had to be creative to run a more substantial payload. I found a way with three node names using an iframe feature I never heard of before.

https://mxsasha.eu/posts/meshcore-xss-home-assistant/

Rooting Home Assistant through MeshCore: XSS attacks with a LoRa node name

A crafted MeshCore node name could compromise any Home Assistant instance running meshcore-card as soon as someone viewed a dashboard with that card. MeshCore …

Forschung: Trump-Regierung lässt System zur Ozeanüberwachung abbauen - Golem.de

Das 900 Tiefseeinstrumente umfassende Sensorensystem soll nach weniger als der Hälfte der geplanten Laufzeit zurückgebaut werden.

Golem.de