So yeah, um, this is not okay. It is not discoverable and could easily leak sensitive information. Auth credentials even, seriously? Also Chrome does this too. And it is preserved across `mv` to another filesystem.https://twitter.com/gynvael/status/1077671412847046657 …
-
Show this thread
-
Filed it as a security bug with Chrome. Not expecting to get any bounty out of it, but there's a better chance the security team will appreciate how dangerous this is.
3 replies 1 retweet 32 likesShow this thread -
That was fast! Wget 1.20.1 was just released with this behavior disabled by default, and made safer when enabled. We also have a CVE for it too, CVE-2018-20483. Thanks
@ruehsen!1 reply 12 retweets 85 likesShow this thread -
This Tweet is unavailable.
Replying to @sdelang_asu @ruehsen
To be fair, this varies *very* widely depending on the project and the bug :-)
7:50 AM - 27 Dec 2018
0 replies
0 retweets
2 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
$ getfattr -d -m - test
user.xdg.origin.url="https://user:passwd@gynvael.coldwind.pl/"