David Leadbeater
@dgl.infosec.exchange.ap.brid.gy
1 followers 0 following 6 posts
Monitoring 📊, SRE, Open Source, Security 🔐. Emoji fan 🦸‍♂️. Just your average cynical Brit 🇬🇧 in 🇦🇺. He/him. 🌉 bridged from ⁂ https://infosec.exchange/@dgl, follow @ap.brid.gy to interact
Posts Media Videos Starter Packs
dgl.infosec.exchange.ap.brid.gy
If you have a bash command line of "exec program ..." and you can control the "..." can you make it not run the exec and do something different? The answer is yes. Even if "..." is somewhat sanitised for shell metacharacters. If you can inject $+] it will make bash error on that line and run the […]
Original post on infosec.exchange
infosec.exchange
dgl.infosec.exchange.ap.brid.gy
For those of you who saw my BSides Canberra talk, here's a vulnerability I couldn't talk about in the talk, yet, but is very much in the spirit of it: https://dgl.cx/2025/10/bash-a-newline-ssh-proxycommand-cve-2025-61984
Bash a newline: Exploiting SSH via ProxyCommand, again (CVE-2025-61984)
dgl.cx
dgl.infosec.exchange.ap.brid.gy
I probably should have polished my @ComfyConAU talk. Instead I got sidetracked into wondering just how much I could tunnel over DNS: https://dgl.cx/2025/09/images-over-dns
Images over DNS
dgl.cx
dgl.infosec.exchange.ap.brid.gy
Noticed my SLAAC IPv6 address happens to end in :fade. Fade to black?
dgl.infosec.exchange.ap.brid.gy
I'll be speaking at BSides Canberra: https://cfp.bsidescbr.com.au/bsides-canberra-2025/talk/8TWF8X/ -- this will cover my recent find of an RCE in Git and how that and some other vulnerabilities could be used against developers. #bsides #security