jub0bs

#infosec enthusiast • #golang dev & trainer • minor contributor to the Go project • minimalist • atheist • chaotic good • trying to make sense of the Web • he/him
Free Go course: github.com/jub0bs/go-course-be

Free 🇵🇸!

2025-12-13

☝️Unpopular opinion: most Gophers should (re-)read @joshbloch's Effective Java book. Much (though not all) of the wisdom it contains is transferable to #golang.

2025-12-12

@ck I concur! Especially since Go 1.22's enhanced routing patterns and Go 1.25's support for cross-origin protection.

tip.golang.org/doc/go1.22#enha

tip.golang.org/doc/go1.25#neth

2025-12-12

Difficult to disagree with this post by Efron Licht: Gin, #golang's arguably most popular Web framework, is pretty bad and should be avoided at all costs. 🙅

eblog.fly.dev/ginbad.html

2025-11-21

Your weekly reminder to migrate from rs/cors to jub0bs/cors. 😇

github.com/rs/cors/issues/198

jub0bs boosted:
2025-11-11

Monotonic Collections: a middle ground between immutable and fully mutable

This post covers several topics around collections (sets, lists, maps/dictionaries, queues, etc) that I’d like to see someone explore more fully. To my knowledge, there are many alternative collection libraries for Java and for many other languages, but I’m not aware of any that provide support for monotonic collections. What is a monotonic collection, I hear you ask? Well, I’m about to answer that.

neilmadden.blog/2025/11/11/mon

2025-11-09

@neilmadden Bloch states this principle in his classic 2007 talk entitled "How to design a good API and why it matters":

youtube.com/watch?v=heh4OeB9A-

Effective Java doesn't contain the exact same maxim, but you could argue that several of its items (e.g. "Design and document for inheritance or else prohibit it") convey a similar idea.

2025-11-09

"A good API should be, not only easy to use, but also hard to misuse." (Josh Bloch)

github.com/rs/cors/issues/197

#golang #CORS

2025-11-04

Productivity tip: don't have kids; don't have cats. 😬

jub0bs boosted:
2025-10-08

The recording of "HTTP/1.1 must die: the desync endgame" has now landed on YouTube. Enjoy! youtube.com/watch?v=zr5y6Bapbn

2025-09-25

"Bonjour. Je suis Nicolas Sarkozy, et j'ai le grand plaisir de lire 'Le temps des oranges' pour Audible." 😂

2025-09-24

CVE-2025-10630: REDoS in Zabbix plugin for Grafana dashboard (fixed in v6.0.2)

To anybody relying on some PCRE engine (such as github.com/dlclark/regexp2): either forbid users to submit arbitrary patterns or enforce some reasonable timeout on matching.

#websecurity #golang

youtu.be/Z_mYyBYP4ZI

2025-09-24

🤦 #AIslop in action! Grafana's fix to CVE-2025-10630 in v6.0.0 of their Zabbix plugin happened to be way off base, but this AI tool fails to figure it out and happily lulls Grafana users into a false sense of security.

miggo.io/vulnerability-databas

2025-09-23

💡 Judiciously ponder the design of a function that operates on user input and returns a slice or a map, lest it constitute a denial-of-service vector. If you're not careful, a single malicious request may cause a huge spike in allocations.

cwe.mitre.org/data/definitions

#golang #websecurity

2025-09-19

@alex This is so satisfying when it happens.

jub0bs boosted:
2025-09-09

This variety of catastrophe is why I disagree with the default policy to be to download the latest version. Newer is not always better, especially in an industry rife with scammers.

cyberplace.social/@GossiTheDog

2025-09-04

When the stars align, a one-character change can have a surprisingly significant impact on performance. 🤩

In this case, omitting a superfluous index in a slice expression was enough to make the enclosing function inlineable. ⚡

github.com/golang/go/pull/75269

#golang

2025-09-04

⚡ If you find yourself implementing an iterator on some recursive data structure, do check out the doc comment of golang.org/x/tools/gopls/inter. Very useful performance tip by Alan Donovan! #golang

jub0bs boosted:
Michael Stapelberg 🐧🐹😺zekjur@mas.to
2025-09-03
jub0bs boosted:
Gareth Heyes :verified:gaz@infosec.exchange
2025-09-01

WAFs still blocking your payloads? Try our newest pointer capture tricks. Our XSS cheat sheet just got an upgrade thanks to Muhammad Ahsan.

portswigger.net/web-security/c

<input type=range ongotpointercapture=alert(1)>
<input type=range onlostpointercapture=alert(1)>

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst