Robert Gützkow

IT security, software engineering and digital art. he/him

Robert Gützkow boosted:
2026-01-20

lol seclists.org/oss-sec/2026/q1/89

telnetd server invokes /usr/bin/login (normally running as root) passing the value of the USER environment variable received from the client as the last parameter.

If the client supply a carefully crafted USER environment value being the string "-f root", and passes the telnet(1) -a or --login parameter to send this USER environment to the server, the client will be automatically logged in as root bypassing normal authentication processes

In telnetd for a decade 💀

Robert Gützkow boosted:
2026-01-14

You don't need to pay Apple or start a new subscription to unleash your creativity. We asked creatives what free software they use to get the job done and here are their picks.

A thread 🧵

kde.org/for/creators/

#creativity #design #audio #art #video

Robert Gützkow boosted:
2025-12-27

At the gpg.fail talk and omg #39c3

You can just put a \0 in the Hash: header and then newlines and inject text in a cleartext message.

Won’t even blame PGP here. C is unsafe at any speed.

gpg has not fixed it yet.

Robert Gützkow boosted:
Blender 🔶Blender
2025-12-10

The Blender project remembers Germano Cavalcante, long-time Blender contributor. Our hearts go out to his family and friends in Brazil. blender.org/news/remembering-g

2025-12-10

@Blender It is incredibly sad to hear that Germano has passed away. Leukemia and cancer in general is just a horrible illness. I will always remember him fondly for his development work on Blender. It's a tough realization that we won't ever see his Batman avatar pop up again in any of the issues or commits because he is gone. I hope his family has good support to navigate this difficult time.

Robert Gützkow boosted:
2025-12-09

Notepad++ have released a new version to fix the auto update process being hijacked notepad-plus-plus.org/news/v88

I reported the vulnerability, it is being hijacked by threat actors in China. doublepulsar.com/small-numbers

Robert Gützkow boosted:
2025-12-03

There is an unauthenticated remote code execution vulnerability in React Server Components.

Even if your app does not implement any React Server Function endpoints it may still be vulnerable if your app supports React Server Components.

If your app’s React code does not use a server, your app is not affected by this vulnerability.

CVE-2025-55182

Mastodon server not impacted btw.

react.dev/blog/2025/12/03/crit

Robert Gützkow boosted:
2025-11-28

We're back with five more apps up for adoption at our fundraiser:

- LabPlot: A powerful data analysis and visualization tool that accepts data in all kinds of formats.

- Okular: Your one-stop app for viewing all kinds of documents. Okular supports annotations, digital signing, and more.

- KStars: Your private planetarium that also helps you schedule and execute your observation and astrophotography sessions.

kde.org/fundraisers/yearend202

#fundraiser #FreeSoftware

[More >]

A screenshot of LabPlot showing different types of graphs.A screenshot of Okular, showing a document with lots of annotation, like post-its, drawings, labels, etc.A screenshot of KStars showing a starscape and the observation planner.
Robert Gützkow boosted:
2025-11-25

Over the last 12 months, watchTowr Labs uncovered thousands of leaked credentials: cloud keys, AD creds, API tokens, even KYC data - already being abused.

Join us on our journey into “innocent” developer tools.

labs.watchtowr.com/stop-puttin

2025-11-24

If you're deploying linkerd and pods do not run properly due to readiness probes failing with a 403, check if your unmeshed application responds with a redirect (302) to the readiness probe. Apparently linkerd does not follow redirects, unlike EKS, processes the response as an error and then treats this as an authentication issue. #k8s #mtls #devsecops #linkerd #linkerd2 #servicemesh

Robert Gützkow boosted:
Blender 🔶Blender
2025-11-18

Blender Foundation and the online developer community proudly present Blender 5.0!

ACES, Adaptive Subdivision, HDR, Storyboarding, Geometry Nodes, 588 bugs fixed, and so much more.

📖Changelog & Download: blender.org/download/releases/

📺 Video Recap: youtube.com/watch?v=4wEqD-jK0DU

Robert Gützkow boosted:
2025-11-15
2025-11-14

@JacquesLucke I won't be able to make it this time.

Robert Gützkow boosted:
Blender 🔶Blender
2025-11-13

Did Blender help you this year? Help back!

If every active user contributed $5 this month, Blender would be funded for the entire year 2026.

Professional 3D software. No subscriptions. No limits. Just your support.

Do your part. Donate today.

blender.org/news/give-back-to-

Oti the penguin, showing a good example of "giving back".
Robert Gützkow boosted:
Blender 🔶Blender
2025-11-13

Blender 5.0 has entered Release Candidate stage! 🚀

Please take some time to try it, test your add-ons, files (backup first!), and report any bugs you find.

⬇️ Download: builder.blender.org/download/d
📖 What's New: developer.blender.org/docs/rel
🐞 Report: Help→Report a Bug

Robert Gützkow boosted:
2025-11-03

MIT have also silently, without noting on the pages, started rewriting their website to remove references to their own work. They've also changed the URLs of the pages to remove references.

Left, before: archive.ph/SckSr

Right, after: mitsloan.mit.edu/ideas-made-to

Robert Gützkow boosted:
2025-11-02

Something very important to know in your threat model if you use Tor Browser on Windows:

By default it installs to your Desktop folder, which is by default mirrored to OneDrive at Microsoft. Microsoft has access to your OneDrive content for cybersecurity analysis via privacy carve outs. The Tor folder contains sensitive content.

The solution is to install at root of C: drive.

2025-11-02

Anybody else getting loads of notification mails by Shodan today for the same systems over and over? #shodan

2025-10-24

@filippo Does GitHub allow to have pipeline definitions in a separate repository like GitLab does? Thought that concept was interesting, but obviously brings other challenges regarding compatibility with changes of time and release branches with long-term support.

Robert Gützkow boosted:
2025-10-23

Microsoft are rolling out Gaming Copilot to all Windows 11 PCs (excluding in China).

Enabled by default, silent install, takes screenshots and trains MS AI by default.

It installed on my Windows 11 Professional PC 🫡 it’s also not dependent on an NPU or Copilot+

doublepulsar.com/microsoft-bui

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst