unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Workshop Basel day three
See also: day one, day two.There is only one thing that is better t...
2026-7-16 20:1:14 | 阅读: 10 |
收藏
|
daniel.haxx.se - daniel.haxx.se
moq
workshop
client
eyeballs
shorter
Workshop Basel day two
If you missed it. I already described day one.Caffeinated and ready...
2026-7-15 20:7:14 | 阅读: 24 |
收藏
|
daniel.haxx.se - daniel.haxx.se
proxies
experiences
proxy
hear
expressed
Workshop Basel day one
On this hot summer’s day in Basel, Switzerland, the seventh HTTP worksh...
2026-7-14 20:25:28 | 阅读: 17 |
收藏
|
daniel.haxx.se - daniel.haxx.se
bots
meeting
beer
roughly
Do excellent vulnerability reports
Over the years, we have received, read and handled way over one thousand vulnerability reports f...
2026-6-29 07:47:43 | 阅读: 34 |
收藏
|
daniel.haxx.se - daniel.haxx.se
security
reproducer
software
reporters
submission
A curl mountain movie
One of my favorite visuals for known vulnerabilities in curl is the mou...
2026-6-26 11:34:0 | 阅读: 21 |
收藏
|
daniel.haxx.se - daniel.haxx.se
mountain
shape
movie
renders
Trailing dots are the worst
Trailing dots after hostnames in URLs remain my worst enemies. I wrote...
2026-6-25 07:48:2 | 阅读: 30 |
收藏
|
daniel.haxx.se - daniel.haxx.se
trailing
dots
numerical
psl
hsts
a CVE dispute
A few years years ago the curl project signed up and became a CNA. This means that we are master...
2026-6-24 21:38:52 | 阅读: 29 |
收藏
|
daniel.haxx.se - daniel.haxx.se
security
cna
wildcard
tl
attacker
curl 8.21.0
Release presentationAt 09:00 UTC (11:00 CEST) today I will do a tra...
2026-6-24 06:0:23 | 阅读: 30 |
收藏
|
daniel.haxx.se - daniel.haxx.se
2026
bugfixes
digest
reuse
security
QUERY with curl
RFC 10008 is brand new a specification detailing the new HTTP method ca...
2026-6-20 22:34:25 | 阅读: 28 |
收藏
|
daniel.haxx.se - daniel.haxx.se
limits
idempotent
repeated
concern
enclosed
curl summer of bliss
The curl project will not accept or otherwise handle any vulnerability...
2026-6-15 05:56:0 | 阅读: 31 |
收藏
|
daniel.haxx.se - daniel.haxx.se
2026
summer
bliss
security
github
A human in control
There seems to be a fair amount of people in either extremes in the current AI landscape. At one...
2026-6-10 07:8:26 | 阅读: 33 |
收藏
|
daniel.haxx.se - daniel.haxx.se
humans
mistakes
software
reviews
development
curl up 2026 summary
Getting curl developers and related enthusiasts into a single room to hang out i...
2026-5-28 15:25:2 | 阅读: 32 |
收藏
|
daniel.haxx.se - daniel.haxx.se
daniel
stenberg
jim
chubin
hdmi
The pressure
I’m doing Open Source primarily because I love it. The social aspects, the for-the-good angle an...
2026-5-26 06:1:39 | 阅读: 27 |
收藏
|
daniel.haxx.se - daniel.haxx.se
security
thirty
software
twelve
named globs with curl
One of the established power features of the curl command line tool is...
2026-5-16 20:58:26 | 阅读: 27 |
收藏
|
daniel.haxx.se - daniel.haxx.se
globs
glob
thousand
globbed
transfers
Mythos finds a curl vulnerability
yes, as in singular one.Back in April 2026 Anthropic caused a lot of media noise when they c...
2026-5-11 06:1:35 | 阅读: 46 |
收藏
|
daniel.haxx.se - daniel.haxx.se
security
mythos
analyzers
analysis
Approaching zero bugs?
In this era of powerful tools to find software bugs, we now see tools f...
2026-4-30 08:8:34 | 阅读: 37 |
收藏
|
daniel.haxx.se - daniel.haxx.se
bugfix
fewer
bugfixes
mistakes
Inspired
The picture was taken by mr Nasser and shared on social mediaIn appendix A o...
2026-4-30 06:49:47 | 阅读: 28 |
收藏
|
daniel.haxx.se - daniel.haxx.se
nasser
youtube
daniel
creator
teach
curl 8.20.0
You always find the new curl releases on the curl site!Release pres...
2026-4-29 06:27:1 | 阅读: 35 |
收藏
|
daniel.haxx.se - daniel.haxx.se
2026
proxy
reuse
security
bugfixes
High-Quality Chaos
嗯,用户让我帮忙总结一篇文章的内容,控制在100字以内,而且不需要用“文章内容总结”之类的开头。首先,我需要仔细阅读这篇文章,理解其主要观点。 文章主要讲的是一个叫做“高质混乱时代”的现象。作者提到他们关闭了curl项目的漏洞赏金计划,因为收到了太多低质量的AI生成报告。后来重新启用后,发现报告的质量和数量都有显著提升。几乎所有的报告都使用了AI工具,但质量很高。其他开源项目也面临同样的情况,预计今年curl项目会发布大量CVE漏洞。 接下来,我需要将这些要点浓缩到100字以内。要确保涵盖关键点:AI生成报告的增加、质量提升、其他项目的经历以及漏洞数量的预期增长。 可能会这样组织语言:“文章描述了当前开源项目面临的高质混乱时代,AI生成的安全报告数量激增且质量提升。curl项目重新启用漏洞赏金计划后发现报告频率翻倍,确认漏洞率恢复至2024年水平。其他如Apache httpd、Django等项目也经历类似趋势。预计2026年curl将发布近50个新漏洞。” 这样既涵盖了主要观点,又控制在了字数限制内。 </think> 文章描述了当前开源项目面临的高质混乱时代,AI生成的安全报告数量激增且质量提升。curl项目重新启用漏洞赏金计划后发现报告频率翻倍,确认漏洞率恢复至2024年水平。其他如Apache httpd、Django等项目也经历类似趋势。预计2026年curl将发布近50个新漏洞。...
2026-4-22 11:44:40 | 阅读: 29 |
收藏
|
daniel.haxx.se - daniel.haxx.se
2026
security
slop
explosion
Don’t trust, verify
嗯,用户让我总结一下这篇文章的内容,控制在一百个字以内,而且不需要特定的开头。首先,我需要通读整篇文章,抓住主要观点。 文章主要讲的是软件和数字安全应该依赖验证而不是信任。作者强调了对curl进行验证的重要性,并提到了很多潜在的安全威胁,比如恶意代码、漏洞、后门等等。然后详细描述了curl项目为了防止这些威胁所采取的各种措施,比如代码审查、测试、CI/CD配置安全、漏洞修复等。 接下来,我需要把这些内容浓缩到100字以内。重点包括:依赖验证而非信任,列举攻击风险,以及curl的安全措施如代码审查、测试和透明性。 要注意用词简洁,避免冗余。比如“攻击无处不在”可以概括多种威胁,“严格的代码审查和测试”则涵盖了具体的措施。 最后,确保总结流畅自然,不使用“文章内容总结”之类的开头。 </think> 软件和数字安全应依赖验证而非信任。文章列举了软件可能面临的多种攻击风险,并强调了对关键组件如curl进行验证的重要性。通过严格的代码审查、测试和透明的开发流程,确保软件的安全性与可靠性。...
2026-3-26 10:9:7 | 阅读: 33 |
收藏
|
daniel.haxx.se - daniel.haxx.se
software
security
malicious
ban
iterate
Previous
1
2
3
4
5
6
7
8
Next