Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @bagder
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @bagder
-
Pinned Tweet
Whenever you or your team get stuck on a curl problem, help is just a support deal away: https://curl.se/support.html - I could literally be helping you with your issue within 24 hours.pic.twitter.com/mMYGVxYgHV
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Daniel’s weekly report May 13, 2022 https://bagder.github.io/log/ release, trailing dots, curl up, hosting, past vulnspic.twitter.com/zYfDLdHXIT
Thanks. Twitter will use this to make your timeline better. UndoUndo -
curl is 24 years old, runs in some 10 billions installations world and now has a fair amount of sponsors. I'm proposing I no longer have to pay with my own money for the server and instead spend some of our fund on it: https://curl.se/mail/lib-2022-05/0017.html …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Bug bounty payouts in the curl project. Over time and per CVE. In total almost 35,000 USD. Recent average over 2,000 USD per issue.pic.twitter.com/LAGogneZ9Q
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
The
@Hacker0x01 Internet Bug Bounty has now paid more than 17,000 USD in reward money on the curl project's behalf. Thank you IBB sponsors!https://www.hackerone.com/internet-bug-bounty …Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
If you too want to write yourself a new minivan: 5 of the recent curl CVEs get 2,400 USD each in bounty rewards. Thank you awesome people! https://hackerone.com/ibb/hacktivity?type=team …
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Happy to say we have a few official curl up 2022 sponsors now. And we're working on more content. June 6, in San Francisco: https://github.com/curl/curl-up/wiki/2022 … Also looking for more speakers so don't be shy!pic.twitter.com/zimWzUXLgn
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Daniel Stenberg Retweeted
Serious Security: Learning from curl’s latest bug updatehttps://nakedsecurity.sophos.com/2022/05/12/serious-security-learning-from-curls-latest-bug-update/ …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Answer: Why does curl send a Proxy-Connection header, even though the RFC seems to discourage it?https://stackoverflow.com/a/62722840/93747?stw=2 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Daniel Stenberg Retweeted
I could add that we don't pre-notify the commercial operating systems. Because: Apple mostly yell at me for not giving them eons of time when I do and Microsoft doesn't provide a method for me to do so.
Thanks. Twitter will use this to make your timeline better. UndoUndo -
The
@Hacker0x01 reports behind these issues are now trickling out and are made public one by one: https://hackerone.com/curl/hacktivity - for some insights on how we worked on the issues before the release.Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
A tale of a trailing dot https://daniel.haxx.se/blog/2022/05/12/a-tale-of-a-trailing-dot/ … - how allowing a dot lead to two curl security vulnerabilities - and more. Did I tell you trailing dots are evil?pic.twitter.com/9qHEqXY2u8
Thanks. Twitter will use this to make your timeline better. UndoUndo -
in simple English: non-C mistake vulnerabilities in curl, remain in the code 24% longer until found than the vulnerabilities caused by C mistakes. On average.
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
that's 6.8 years vs 8.5 years
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
All vulnerabilities live a very long time until fixed in curl. On average, the non-C mistakes seem to live around ~600 days longer than the C mistakes, but the C mistake average age is still >2,500 days (vs 3178 for non-C mistakes). The graph is a little rough.pic.twitter.com/r4V9iQDz01
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
I'll make a separate run and see if there's a difference in time: how long mistakes remain in the code, C mistakes vs non-C mistakes until detected. One theory says that C mistakes are easier to find with tools.
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
At no point time was the share of security flaws existing in curl caused by "C mistakes" larger than the amount of vulnerabilities caused by other mistakes. (per date of when the flaw was first shipped in a release). One project. 121 flaws. Not much to draw conclusions from.pic.twitter.com/u8qTTka7fU
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Daniel Stenberg Retweeted
curl official container image curlimages/curl:7.83.1 has been released ... give it a spin> docker run -it curlimages/curl:7.83.1 https://httpbin.org/get
Thanks. Twitter will use this to make your timeline better. UndoUndo -
The curl 7.83.1 release presentation video https://youtu.be/mnsCTd4cwyI pic.twitter.com/HqQik54tNP
Thanks. Twitter will use this to make your timeline better. UndoUndo -
The curl 7.83.1 release presentation live-stream starts now at https://www.twitch.tv/curlhacker pic.twitter.com/25wfaPd535
Thanks. Twitter will use this to make your timeline better. UndoUndo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.