Sign in

Lorenzo Leonardini

@pianka.it
66 followers 160 following 12 posts

Computer scientist, cybersecurity guy, wannabe musician You might know me as "pianka" CTF player with @aboutblankets 🔗 sec.leonardini.dev

PostsRepliesMedia
Lorenzo Leonardini @pianka.it · 28/02/2025
Took me a while, but here is the full article! If you want to see some weird URL parsing behavior, here you can find a lot of them :) sec.leonardini.dev/blog/playing... Disclaimer: no exploits nor vulnerabilities in this post, just some broken code
sec.leonardini.dev
Playing with Bun's URL parser
During the latest SECCON CTF quals, I had the pleasure of reading the custom implementation of Bun's URL parser, and I found some... weird behaviors... Join me in this wonderful journey.
182
Lorenzo Leonardini @pianka.it · 02/01/2025
Currenly playing around with Bun's URL parser, and I must say it's pretty fun. It's not vulnerable as it's never used raw, but expect a few GH issues and a blog post about it. Spoiling the least interesting quirk to keep you on your toes :) Hopefully I'm not ruining anybody's future challenge :')
The URL `http://a@b@c` is parsed to as username `a`, password `b` and hostname `c`
080
Lorenzo Leonardini @pianka.it · 28/12/2024
TIL that in Go this snippet produces `/foo/bar`, and... I feel like that's.. wrong..? The HTTP server router does not handle this as `/foo/bar`, and parsing this with Node returns `/foo%2fbar` (which is what I expected) Does anyone have any insight on this?
u, _ := url.Parse("http://localhost/foo%2fbar")
fmt.Println(u.Path)
220
Lorenzo Leonardini @pianka.it · 22/11/2024
Yesterday my first PHP CVE was published: CVE-2024-11234. In some specific configurations, this vulnerability could allow for CRLF injection when using stream contexts. sec.leonardini.dev/blog/cve-202... Many thanks to @minimalblue.bsky.social for reviewing my original report
sec.leonardini.dev
CVE-2024-11234: Configuring a proxy in a PHP stream context might allow for CRLF injection in URIs 🐘
A vulnerability in PHP might allow an attacker to perform SSRF attacks when unsanitized user-controlled data is used in stream functions if a proxy is used.
0102
Reposted by Lorenzo Leonardini
Marco Squarcina @minimalblue.bsky.social · 21/11/2024
Sharing CVE-2024-11234 affecting PHP. This vulnerability could lead to CRLF injection when using Stream Contexts under certain conditions. Discovered and reported by @p1anka.bsky.social, I only reviewed the report some time ago! github.com/php/php-src/...
github.com
Configuring a proxy in a stream context might allow for CRLF injection in URIs
### Summary Configuring a proxy in a [stream context](https://www.php.net/manual/en/stream.contexts.php) might allow for CRLF injection in URIs, resulting in HTTP request smuggling attacks. #...
0101