{"version": "https://jsonfeed.org/version/1", "title": "/dev/posts/ - Archive for 2019", "home_page_url": "https://www.gabriel.urdhr.fr", "feed_url": "/2019/feed.json", "items": [{"id": "http://www.gabriel.urdhr.fr/2019/11/18/flamegraph-disk-usage/", "title": "Disk usage with FlameGraph", "url": "https://www.gabriel.urdhr.fr/2019/11/18/flamegraph-disk-usage/", "date_published": "2019-11-18T00:00:00+01:00", "date_modified": "2019-11-18T00:00:00+01:00", "tags": ["computer", "flamegraph"], "content_html": "<p>Using <a href=\"https://github.com/brendangregg/FlameGraph\">FlameGraph</a>\nfor displaying disk usage.</p>\n"}, {"id": "http://www.gabriel.urdhr.fr/2019/04/02/llmnr-mdns-cli-lookup/", "title": "Using dig as a LLMNR or mDNS CLI lookup utility", "url": "https://www.gabriel.urdhr.fr/2019/04/02/llmnr-mdns-cli-lookup/", "date_published": "2019-04-02T00:00:00+02:00", "date_modified": "2023-09-22T14:20:00+02:00", "tags": ["computer", "network", "dns", "llmnr", "mdns"], "content_html": "<p>I was looking for a LLMNR commandline lookup utility.\nActually, <code>dig</code> can do the job quite fine.</p>\n"}, {"id": "http://www.gabriel.urdhr.fr/2019/03/29/surprising-shell-pathname-expansion/", "title": "Surprising shell pathname expansion", "url": "https://www.gabriel.urdhr.fr/2019/03/29/surprising-shell-pathname-expansion/", "date_published": "2019-03-29T00:00:00+01:00", "date_modified": "2019-03-29T00:00:00+01:00", "tags": ["computer", "unix", "shell"], "content_html": "<p>I thought I was understanding pretty well how bash argument processing and\nvarious expansions is supposed to behave. Apparently, there are still\nsubtleties which tricks me, sometimes.</p>\n"}, {"id": "http://www.gabriel.urdhr.fr/2019/02/12/yunohost-rce-csrf/", "title": "Remote code execution via cross site request forgery in InternetCube and YunoHost", "url": "https://www.gabriel.urdhr.fr/2019/02/12/yunohost-rce-csrf/", "date_published": "2019-02-12T00:00:00+01:00", "date_modified": "2019-02-12T00:00:00+01:00", "tags": ["computer", "web", "security", "yunohost", "csrf", "vulnerability"], "content_html": "<p>How I found remote code execution vulnerabilities\nvia <a href=\"https://marc.info/?l=bugtraq&amp;m=99263135911884&amp;w=2\">Cross Site Request Forgery</a> (CSRF)\non the administration interfaces\nof <a href=\"https://labriqueinter.net/\">InternetCube</a> applications\nand of the <a href=\"https://yunohost.org/\">YunoHost</a> administration interface\nwhich could have been used to execute arbitrary code as root.\nThese vulnerabilities were fixed in YunoHost 3.3, OpenVPN Client app 1.3.0.\nand YunoHost 3.4.</p>\n"}]}