David S.
dsanchez.bsky.social
David S.
@dsanchez.bsky.social
System & Network engineer @ LCPQ - FeRMI - UT3
Reposted by David S.
AlmaLinux OS 9.7 "Moss Jungle Cat" just dropped!

Updated compilers, enhanced security with post-quantum crypto, better container support.

Available now across all 4 architectures.

https://almalinux.org/blog/2025-11-17-almalinux_97_release/?utm_medium=social&utm_source=bluesky
General Availability of AlmaLinux OS 9.7 Stable!
AlmaLinux OS 9.7 Stable Now Available Hello Community! The AlmaLinux OS Foundation is announcing the general availability of AlmaLinux OS 9.7 codenamed “Moss Jungle Cat”! Installation ISOs are available on the mirrors now for all 4 architectures: Intel...
almalinux.org
November 25, 2025 at 9:19 PM
Reposted by David S.
Original post on mastodon.bsd.cafe
mastodon.bsd.cafe
November 19, 2025 at 8:45 AM
Et hop un Dell R420 dont la PERC inutilisable avec un Linux récent flashé en HBA : zfs on root et il peut resservir en tant que vénérable serveur de sauvegarde :-)

pool: ztank
state: ONLINE
November 14, 2025 at 5:15 PM
Reposted by David S.
📅 Ne manquez pas @capitoledulibre.org qui se tiendra ce week-end à l'ENSEEIHT, à Toulouse !

Pour vous inscrire et consulter le programme de l'événement, rendez-vous sur capitoledulibre.org.
Capitole du Libre 2025
capitoledulibre.org
November 12, 2025 at 3:15 PM
Bon je connais une PERC qui va se faire flash en IT mode... :D
November 12, 2025 at 10:53 PM
Reposted by David S.
[SUA 276-1] Upcoming Debian 13 Update (13.2)
lists.debian.org
November 12, 2025 at 8:58 PM
Titre un peu putaclic mais on y croit !

"Victoire pour le logiciel libre : Polytechnique claque la porte à Microsoft 365 ! www.generation-nt.com/actualites/p... "
https://www.generation-nt.com/actualites/polytechnique-microsoft-365-souverainete-numerique-logiciel-libre-2064086"
October 15, 2025 at 6:50 AM
Reposted by David S.
September 15, 2025 at 11:43 AM
Reposted by David S.
X11, Wayland : pourquoi la transition est-elle aussi longue ? - Un bon article de synthèse sur les 2 protocoles graphiques du monde Linux/BSD, par Next repartagé par Seb Sauvage #X11 #Wayland app.wallabag.it/share/68c3ef...
X11, Wayland : pourquoi la transition est-elle aussi longue ? - Next
This article has been shared by sebsauvage with wallabag.
app.wallabag.it
September 15, 2025 at 11:45 AM
Ils en loupent pas une les c***...
next.ink/198278/word-...
Word va sauvegarder automatiquement les documents dans le cloud - Next
next.ink
September 5, 2025 at 7:09 AM
Reposted by David S.
HTTP/1.1 Fatal Vulnerability Exposes Millions of Websites to Hostile Takeover
HTTP/1.1 Fatal Vulnerability Exposes Millions of Websites to Hostile Takeover
A critical vulnerability in the HTTP/1.1 protocol threatens tens of millions of websites with potential hostile takeovers through sophisticated desynchronization attacks.  This fundamental flaw in the decades-old protocol creates extreme ambiguity about where one request ends and the next begins, enabling attackers to manipulate web traffic and compromise entire infrastructures. Key Takeaways 1. HTTP/1.1 flaw exposes millions of websites to data theft and code injection attacks. 2. Upstream HTTP/2 is the only fix. 3. Major vendors don't support upstream HTTP/2 yet, leaving sites vulnerable. HTTP/1.1 Fatal Vulnerability PortSwigger reports that the vulnerability demonstrates how HTTP request smuggling attacks can bypass years of vendor-implemented security mitigations.  These desync attacks exploit the inherent weakness in HTTP/1.1’s message parsing mechanism, where attackers can craft malicious requests using techniques like Content-Length header manipulation and Transfer-Encoding: chunked discrepancies to confuse reverse proxies and backend servers. The impact of flourishing HTTP request smuggling is severe. According to the research , a single malicious HTTP request can cause websites to lose track of which responses belong to which users, resulting in massive disclosure of confidential information and users being randomly logged into other live accounts.  Furthermore, attackers can poison website caches with malicious JavaScript, gaining persistent control over web pages and enabling theft of passwords and credit card details. The vulnerability affects core infrastructure within multiple Content Delivery Networks (CDNs) , exposing millions of websites despite six years of attempted fixes by vendors.  Security experts emphasize that simply wrapping HTTP/1.1 in HTTPS provides no protection against these attacks, as the vulnerability exists at the protocol level rather than the encryption layer. Deploy HTTP/2 Upstream  The definitive solution requires migrating to upstream HTTP/2 connections between reverse proxies and origin servers. HTTP/2 eliminates the ambiguity that enables desync attacks by providing clear message boundaries and binary framing.  However, merely enabling HTTP/2 for client-facing connections is insufficient; the upstream connection to backend servers must also utilize HTTP/2 to prevent exploitation. For organizations unable to immediately deploy upstream HTTP/2, researchers recommend using the open-source HTTP Request Smuggler v3.0 tool to identify vulnerabilities, enabling request validation and normalization features, and considering disabling upstream connection reuse despite potential performance impacts.  Major vendors, including nginx, Akamai, CloudFront, and Fastly, currently lack upstream HTTP/2 support, leaving millions of websites vulnerable until these platforms implement the necessary upgrades. Equip your SOC with full access to the latest threat data from ANY.RUN TI Lookup that can Improve incident response -> Get 14-day Free Trial The post HTTP/1.1 Fatal Vulnerability Exposes Millions of Websites to Hostile Takeover appeared first on Cyber Security News .
cybersecuritynews.com
August 7, 2025 at 9:19 AM
Reposted by David S.
"We need to go deeper" version CPU :
Ring 0 is a highly-privileged state on CPUs.


Negative Ring Levels have even *higher* privilege. You just haven’t heard of them.


For X86, Ring -1 is Hardware Virtualization, Ring -2 is System Management Mode, Ring -3 is Intel ME / AMD PSP.

Arm get's even weirder:
August 7, 2025 at 11:12 AM
Reposted by David S.
Analyse des tickets rechargeables des transports de Toulouse : extraction depuis le tag NFC ST25TB et interprétation des données - Article par Maya #NFC maya.sh/tisseo.html
Analyse des nouveaux titres rechargeables des transports de Toulouse - Page perso de Maya
le site plus tellement secret de maya !!
maya.sh
August 7, 2025 at 11:45 AM
Reposted by David S.
PROXMOX VIRTUAL ENVIRONMENT v9.0 is available, see all details forum.proxmox.com/threads/prox...
August 6, 2025 at 10:31 AM
Reposted by David S.
PROXMOX BACKUP SERVER 4.0 is here! Packed with new features and improvements! See all detail forum.proxmox.com/threads/prox...
August 6, 2025 at 12:56 PM
Reposted by David S.
Un tableau listant des alternatives gratuites et/ou Open Source aux applications Adobe.
August 5, 2025 at 11:30 AM
Reposted by David S.
Le guide pour faire évoluer votre carrière !
August 4, 2025 at 4:31 PM
Reposted by David S.
🏖️🐻 Les Logiciels Libres de l'été, jour 45

IMMICH : Une solution Open Source de sauvegarde de photos et de vidéos des smartphones.
August 4, 2025 at 5:53 PM
Reposted by David S.
J'avais dit en live que j'avais un article de #blog sur #Firefox sous le coude, ben voilà, il est prêt, je vous le livre donc :
blog.seboss666.info/2025/08/fire...
Firefox, il bouge toujours ! (mais c'est compliqué)
Ça fait beaucoup trop longtemps que je n'ai pas parlé de Firefox ici (que je n'ai pas parlé du tout, d'ailleurs, si on considère la fréquence de publication, même si j'ai récemment sorti des trucs). P...
blog.seboss666.info
August 4, 2025 at 4:45 PM
Reposted by David S.
Learning Go concurrency patterns is getting easy with this amazing site
#golang

concurrency.rocks
August 5, 2025 at 5:19 AM
Reposted by David S.
Michael Prokop has posted a lengthy list of changes coming in the Debian "trixie" release (next official release version 13), due in early August 2025 #Debian #Linux michael-prokop.at/blog/2025/07...
mikas blog » Blog Archive » What to expect from Debian/trixie #newintrixie
michael-prokop.at
August 4, 2025 at 7:05 AM
Reposted by David S.
Hashcat, le meilleur casseur de mots de passe, est disponible en version 7.0.0. Une très grosse version, avec près de 900.000 lignes de code changées, des nouveaux algorithmes et techniques pour casser du secret ⬇️

github.com/hashcat/hash...
github.com
August 2, 2025 at 5:17 AM
Du nouveau de côté de MatInfo :-)
matinfo.fr/fr/notificat...
Notification MatInfo 6 | Matinfo
matinfo.fr
July 25, 2025 at 12:18 PM
Reposted by David S.
A good Introduction to Anubis, a Tool (written in Go) to block the hordes of AI crawlers via a proof-of-work Challenge - Article by LWN lwn.net/Articles/102...
Anubis sends AI scraperbots to a well-deserved fate
Few, if any, web sites or web-based services have gone unscathed by the locust-like hordes of A [...]
lwn.net
July 25, 2025 at 7:05 AM
Reposted by David S.
Avec les changements de conditions d'utilisation de WeTransfer, vous êtes sans doute à la recherche d'alternatives auto-hébergeables et open-sources. Voici donc ProjectSend qui vous permettra de partager vos fichiers avec un contrôle total ⬇️

github.com/projectsend/...
GitHub - projectsend/projectsend: ProjectSend is a free, open source software that lets you share files with your clients, focused on ease of use and privacy. It supports clients groups, system users ...
ProjectSend is a free, open source software that lets you share files with your clients, focused on ease of use and privacy. It supports clients groups, system users roles, statistics, multiple lan...
github.com
July 16, 2025 at 6:06 AM