RyotaK
ryotak.net
RyotaK
@ryotak.net
I published a blog post about six vulnerabilities in Git/GitHub-related projects. They all result in credential leakage when cloning a malicious repository, so be sure to update the Git installation!

flatt.tech/research/pos...
Clone2Leak: Your Git Credentials Belong To Us
Introduction Hello, I’m RyotaK ( @ryotkak ), a security engineer at GMO Flatt Security Inc. In October 2024, I was hunting bugs for the GitHub Bug Bounty program. After investigating GitHub Enterprise...
flatt.tech
January 27, 2025 at 10:54 AM
[PSA]
If you're using OpenWrt router and have used the Attended sysupgrade, firmware-selector.openwrt[.]org or CLI upgrade previously, I recommend you to re-flash your firmware.

Due to a security issue, it was possible to pollute the firmware images delivered to these tools. (1/2)
December 7, 2024 at 9:47 AM
OpenWrtのビルド用サーバーに脆弱性を報告しました。

Attended sysupgrade、firmware-selector.openwrt[.]orgあるいはCLIからのアップグレードを過去に実施した場合、改ざんされたファームウェアが配信された可能性が完全には否定できないため、ファームウェアの再更新を推奨します。

技術的解説についてはこちらの記事をご確認ください。 flatt.tech/research/pos...

公式からの発表はこちらをご覧ください。 lists.openwrt.org/pipermail/op...
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection
Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at Flatt Security Inc. A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt on my router.1 After ac...
flatt.tech
December 7, 2024 at 9:46 AM
そのうちやる: BlueskyとTwitterの自動ポスト
November 27, 2024 at 12:39 PM
ねむ
February 13, 2024 at 7:11 AM
February 13, 2024 at 4:41 AM
Bluesky、まだフェデレーションできないのか
February 13, 2024 at 3:03 AM
Reposted by RyotaK
Dynamicな波
February 13, 2024 at 2:29 AM
UnstableなTableはかなり嫌だな
February 13, 2024 at 2:32 AM
StableなTable
February 12, 2024 at 1:55 PM
Reposted by RyotaK
オヤジギャグ系エンジニアであるところの @ryotak.net
February 12, 2024 at 1:28 PM
Reposted by RyotaK
@ryotak.net 「だいぶTwitterだなぁ」
@ryotak.net 「『だいぶTwitter』の『ダイブツ』の部分」
February 12, 2024 at 1:28 PM
Reposted by RyotaK
だいぶTwitterの大仏の部分 by RyotaK
February 12, 2024 at 1:28 PM
じゃああねてあさんは邪悪の悪で
邪悪の邪が来てしまった…
ryotak.net RyotaK @ryotak.net · Feb 12
独自ドメインヨシ!
February 12, 2024 at 1:25 PM
独自ドメインヨシ!
February 12, 2024 at 1:20 PM