Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 7 days ago

over the weekend we did:

hackerone_count += 2;

Now at 142 submissions this year so far for #curl. Out of which 8 were confirmed actual vulnerabilities.

https://curl.se/dashboard1.html#hackerone

curl - Project status dashboard

  • Copy link
  • Flag this post
  • Block
Neal Walfield
@nwalfield@mastodon.social replied  ·  activity timestamp 7 days ago

@bagder Interesting! Thanks for sharing. Sequoia received 74 reports this year on yeswehack and we've confirmed 6 vulnerabilities. Of those, none were serious. Two had to do with wasting resources on specially crafted input. Two were out of bounds array accesses that result in a panic (we're using rust). One was a terminal injection, because we forgot to escape attacker controlled data that we print. And the last one was forgetting to check that the value returned from malloc is not NULL.

  • Copy link
  • Flag this comment
  • Block
Wolf480pl
@wolf480pl@mstdn.io replied  ·  activity timestamp 7 days ago

@bagder
how many of the not-actually-vulns were good-faith or otherwise helpful?

  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
@bagder@mastodon.social replied  ·  activity timestamp 7 days ago

@wolf480pl 32 of them were marked "informative", means typically means they identified a bug - just not a vulnerability or security problem

  • Copy link
  • Flag this comment
  • Block
Karl
@karl@infosec.exchange replied  ·  activity timestamp 7 days ago

@bagder Interesting. Even when removing the AI slop count from the tallies, this year has the worst ratio of actual vulns to reports.

Do you have insights as to why that is?

  • Copy link
  • Flag this comment
  • Block
Stefan Eissing
@icing@chaos.social replied  ·  activity timestamp 7 days ago

@bagder Sloppy work by the submitters. (In the traditional, but maybe also in the modern sense)

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.8 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login