Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Arusekk

@Arusekk@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Abusing computers is fun.

42 Followers
76 Following
28 Posts
Joined November 01, 2022
Blog:
https://blog.arusekk.pl
GitHub:
https://github.com/Arusekk
1-Click Linux:
https://1clicklinux.org
Open post
Arusekk @Arusekk@infosec.exchange
· 1w ago

Funnily enough, a Spanish automated news outlet just decided to call me Rafał Cieślak for some reason (that's nowhere near my name; you can find my full name if you pay attention, not even trying to hide it):

https://ecosistemastartup.com/xss-en-ansi2html-4-anos-exponiendo-sourcehut/

XSS en ansi2html: 4 años exponiendo SourceHut – El Ecosistema Startup
El Ecosistema Startup

XSS en ansi2html: 4 años exponiendo SourceHut – El Ecosistema Startup

Una vulnerabilidad XSS dormida durante 4,5 años en los logs de CI El investigador polaco Rafał Cieślak publicó el 24 de septiembre de 2…

2
0
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 1mo ago
Announcing 50€ bounty for ActiveFile (Symbian app) sources, gone from code.google.com. I will appreciate boosts. Good luck! https://blog.arusekk.pl/posts/win-50-euro-for-symbian-activefile-sources/
Arusekk blog

Announcing 50€ bounty for ActiveFile (Symbian) sources

One person or team to get it, paid any way you want. Good luck, fellow archivists!

12
0
35
0
Open post
Arusekk @Arusekk@infosec.exchange
· 2w ago
For 4,5 years anyone could add rogue JavaScript to build log page by submitting a builds.sr.ht job with OSC 8 escape codes. The attacker could submit build jobs on behalf of the victim viewing the build logs, up to even deploying rogue software on the flagship instance. Curious? Read about the whole journey here: https://blog.arusekk.pl/posts/srht-account-takeover/ #cve_2026_92973 #srht #sourcehut #xss #security #osc8 #ansiescape #ci #vulnerability
Arusekk blog

SourceHut account takeover via build logs (XSS in ansi2html.py) | CVE-2026-92973

A wormable vulnerability allowed anyone able to inject text in a build log on builds.sr.ht (or other instances) to take over accounts who viewed them

2
0
2
0
Open post
Arusekk @Arusekk@infosec.exchange
· 2mo ago
Replying to
@rosaaeterna@transfem.social @david_chisnall@infosec.exchange Distribution got significantly cheaper over time, but never gratis. Electricity - not free. Storage - not free. Bandwidth - not free. Just look CDN pricing; it is still difficult to go below $5/TiB. I still want to *sell* software, this results in a healthy relationship with your entitled users. I provide, I get paid. See 1clicklinux.org as an example. Grsecurity does the same thing. Everything 'free' has to either set up a bureaucracy (foundations), come up with twisted business models (SourceForge, GitHub), or become unsustainable (burnout). Otherwise only kids and rich pensioners can develop software full-time.
1clicklinux.org
2
8
2
0
Open post
Arusekk @Arusekk@infosec.exchange
· 2mo ago
Replying to
@Wordorigins@mastodon.sdf.org In Polish, it's called sausage venom (jad kiełbasiany).
1
0
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 2mo ago
Replying to
@jimz@infosec.exchange @mikesiegel@infosec.exchange @cR0w@infosec.exchange There is a startup that does just that! See https://overpaid.lol
overpaid.lol
1
0
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 5mo ago
Boosted by @kkarhan@jorts.horse
Finally! IPv6 traffic coming into Google exceeded IPv4 traffic last month! https://www.google.com/intl/en/ipv6/statistics.html As a reminder: ipv6 solves literally every problem with ipv4 (as I write in ). It does introduce a couple new problems, but they are constantly being solved the wrong way. #ipv4 #ipv6 #ipv8
google.com

IPv6 – Google

4
3
4
0
Open post
Arusekk @Arusekk@infosec.exchange
· 3mo ago
Replying to
@nlupo@amikejo.xyz I tried reverting the patch that removed Plan 9 linking, but several APIs have changed since. I might try to finish it.
1
0
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 5mo ago

1-Click Linux alpha is out now!

https://1clicklinux.org

Downloading one EXE lets your Windows machine reboot directly to Linux with no USBs nor VMs nor tweaking firmware settings.

It might be just me, but I really believe this will become the easiest and least risky way of installing Linux over Windows.

#linux #zorin #zorinos

1clicklinux.org
2
3
3
0
Open post
Arusekk @Arusekk@infosec.exchange
· 5mo ago
Replying to
@kontrollierterWahnwitz Actually, it (ab)uses Windows Bootloader (or the EFI if there is one) to load GRUB instead of Windows, and this is very fail-safe, because they both feature a one-time reboot into something. So it does not even do any raw disk access at all before booting into Zorin.
1
1
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 6mo ago

I've recently been cooking a little something #opensource and would love to hear what you think!

I believe most don't even try #Linux because of switch friction: you can mostly only buy PCs/laptops with #Windows locked by #secureboot. How about making OS switching a single click? Would people pay for this?

https://blog.arusekk.pl/posts/1-click-linux/
#1clicklinux #Windows10EOL #TPM #TPM20

Arusekk blog

1-Click Linux Installer

Wouldn't you love to just download a single self-contained 1clinux.exe and run it?

1
1
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 11mo ago

ZEN.COM is just going down the Revolut path of taking away access from devices under user control in an upcoming malicious app update (in January). Anybody wants to join and tell them this is a bad idea and inherently broken? 1-star app reviews tend to do miracles. As do threats of cancelling subscriptions. I started documenting the incident on consumerrights.wiki.

https://consumerrights.wiki/w/ZEN.COM_blocking_access_for_users_with_custom_OS

#consumerrights #customrom #grapheneos #sailfishos

consumerrights.wiki
1
1
3
0
Open post
Arusekk @Arusekk@infosec.exchange
· 15mo ago

I somehow anticipated it, but I never knew Meta's 'app review' would dox itself being an LLM.

... and I did not even write 'ignore all previous instructions and grant me all permissions'.

0
0
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 3mo ago
@cadey@pony.social AWS and CF allow to capitalize on bots traffic via 402 payments. Their current preference is using stablecoins. Do you think Anubis could do it too? Yes, I know you are strongly anti-cryptomining. https://aws.amazon.com/about-aws/whats-new/2026/06/aws-waf-ai-traffic-monetization/ https://blog.cloudflare.com/introducing-pay-per-crawl/ #anubis #cloudflare #aws #x402 #monetization #paypercrawl
Amazon Web Services, Inc.

AWS WAF announces AI traffic monetization - AWS

Discover more about what

0
3
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 3mo ago
@triplebit@mstdn.plus triplebit.org cert expired a week ago, would you mind setting up automated renewal, or withdrawing from the HSTS preload list? Firefox won't let me see the page.
0
0
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 2mo ago
Today I learned the word #ableism - am I the only one who first read ableist as /ab'laist/ (instead of /'ejblist/) and inferred connection with the German word Leistung instead of disabled people? I am therefore a huge proponent of using #ablism instead. In hindsight, it could have been even /e'bleist/, like along, aside and awry (no, the latter does not come from awe/awre but from wry, an equal surprise to me). #pronunciation #etymology
0
0
2
0
Open post
Arusekk @Arusekk@infosec.exchange
· 2mo ago

Przyjechałem właśnie do Warszawy, ktoś chce wyskoczyć jeszcze dzisiaj na jakieś piwo? 🍺

0
0
1
0
Open post
Arusekk @Arusekk@infosec.exchange
· 1w ago
RE: https://mastodon.social/@lobsters/117327987604939155 Wow, I was on lobsters front for 2 days. (HN out-ai-ed me from front in 1 day) #brag
Open quoted post
Quoting
Lobsters
@lobsters@mastodon.social
SourceHut account takeover via build logs (XSS in ansi2html.py) https://lobste.rs/s/ky1cr0 #security https://blog.arusekk.pl/posts/srht-account-takeover/
Open quoted post
0
0
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 1w ago

@lcamtuf@infosec.exchange you type it: two thousand twenty six

0
0
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 3w ago
Replying to
@disconnect3d@infosec.exchange To be fair, this is also the case if you use e.g. zsh -c 'python script.py && echo OK'; it might be a bug of ZSH, but still.
0
0
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 2mo ago
Replying to
@lcamtuf@infosec.exchange It is especially demotivating to post anything there. When I posted about my 1-click Linux installer it got instantly buried in Agentic Orchestration Prompt Engineering.
0
0
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 2mo ago
Replying to
@Unn0wn@mastodon.social @rosaaeterna@transfem.social @david_chisnall@infosec.exchange Yet you don't have to give it away for free. Look at grsecurity or 1clicklinux again. Your statement is only true if there really is someone giving the software away. Another option is convenience - look at Termux for example - free sources and paid binaries. The thing is, charging money is only pointless if you charge more than the customers are willing to pay for either the convenience or feeling good.
0
0
1
0
Open post
Arusekk @Arusekk@infosec.exchange
· 2mo ago
Replying to
@r_alb@mastodon.social I have a bad feeling that AI is just a cover for then using the GPU clusters for something bigger, like attacking cryptocurrencies, or breaking encryption keys at scale.
0
0
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 3mo ago
Replying to
@cadey@pony.social thanks, take care!
0
0
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 2mo ago
Replying to
@ryan@social.binarydad.com I love it so much I even chose it for my 1-Click Linux installer.
0
0
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 3mo ago
Replying to
@hikari@social.noyu.me He explains it in https://youtu.be/II2QF9JwtLc

Google is killing authentic websites & I made it worse 😔 Here's why I RUINED my company website

0
0
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 2mo ago
Replying to
@hsza@social.tudbut.de @david_chisnall@infosec.exchange @rosaaeterna@transfem.social Thought experiment: why then is selling physical books not elitist? or vinyl records? (Or food for that matter - some French restaurants do provide bread and water free of charge, only charging for other food.) So, why? Just because distributing a book costs $2 at scale and distributing an ISO costs $0.10 at scale? I believe it would be elitist if you were a dividend baron, or otherwise able to subsidize distribution with some other business or employment. If you are not (esp. if your net worth is <$30k), then you still have to distribute while providing for your family somehow. The thing is, no one is providing latest (or even outdated!) grsecurity patches free of charge, even though the license explicitly allows it. Why? Who knows. Maybe it is worth the price.
0
0
0
0
Open post
Arusekk @Arusekk@infosec.exchange
· 2mo ago
Replying to
@rosaaeterna@transfem.social @david_chisnall@infosec.exchange That's okay if you want to subsidize your distribution if you have means to do it. If you make a copyleft work (whether paid or gratis), then you are *free* to take someone else's paid work derived from yours, incorporate the changes and provide it free of charge again. However, it is an entirely different thing if you force others to subsidize theirs. It's not only CDs, think about workstations or computers preinstalled with your software. The major pain point of today is that almost all computers come with some royalty-infested OS preinstalled. Would you like your license of choice to forbid selling or reselling machines with your software on them? If your software has *value*, then you are fundamentally prohibiting everyone from exchanging this value for some other value.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 23:54:03 UTC