Sign in

RyotaK

@ryotak.net
201 followers 37 following 15 posts

Security researcher? | Icon: twitter.com/MelvilleTw | Keybase: keybase.io/ryotak | Threads: threads.net/ryotkak | Misskey: misskey.io/@ryotak

PostsRepliesMedia
RyotaK @ryotak.net · 27/01/2025
I published a blog post about six vulnerabilities in Git/GitHub-related projects. They all result in credential leakage when cloning a malicious repository, so be sure to update the Git installation! flatt.tech/research/pos...
flatt.tech
Clone2Leak: Your Git Credentials Belong To Us
Introduction Hello, I’m RyotaK ( @ryotkak ), a security engineer at GMO Flatt Security Inc. In October 2024, I was hunting bugs for the GitHub Bug Bounty program. After investigating GitHub Enterprise...
081
RyotaK @ryotak.net · 10/12/2024
Thank you so much for reading it!
000
RyotaK @ryotak.net · 07/12/2024
Thank you for reading it ;)
000
RyotaK @ryotak.net · 07/12/2024
If you're interested in the technical details, I wrote the blog post here: flatt.tech/research/pos... For the further details, please check out the announcement from the OpenWrt team: lists.openwrt.org/pipermail/op... (2/2)
flatt.tech
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection
Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at Flatt Security Inc. A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt on my router.1 After ac...
0178
RyotaK @ryotak.net · 07/12/2024
[PSA] If you're using OpenWrt router and have used the Attended sysupgrade, firmware-selector.openwrt[.]org or CLI upgrade previously, I recommend you to re-flash your firmware. Due to a security issue, it was possible to pollute the firmware images delivered to these tools. (1/2)
192
RyotaK @ryotak.net · 07/12/2024
OpenWrtのビルド用サーバーに脆弱性を報告しました。 Attended sysupgrade、firmware-selector.openwrt[.]orgあるいはCLIからのアップグレードを過去に実施した場合、改ざんされたファームウェアが配信された可能性が完全には否定できないため、ファームウェアの再更新を推奨します。 技術的解説についてはこちらの記事をご確認ください。 flatt.tech/research/pos... 公式からの発表はこちらをご覧ください。 lists.openwrt.org/pipermail/op...
flatt.tech
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection
Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at Flatt Security Inc. A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt on my router.1 After ac...
092
RyotaK @ryotak.net · 27/11/2024
そのうちやる: BlueskyとTwitterの自動ポスト
000
RyotaK @ryotak.net · 13/02/2024
ねむ
010
RyotaK @ryotak.net · 13/02/2024
www.youtube.com/watch?v=pia0...
youtube.com
[びじゅチューン!] 何にでも牛乳を注ぐ女 | NHK
「びじゅチューン!」は放送後1週間見逃し配信をしています!https://www.nhk.jp/p/bijutune/ts/MPPMVRL98N/plus/?cid=dchk-yt-1912-126-st発想の源はフェルメール「牛乳を注ぐ女」。絵の中の女が注いでいる牛乳が、やけに細く描かれている。これは料理の仕上...
022
RyotaK @ryotak.net · 13/02/2024
ねこぱっぱ
022
RyotaK @ryotak.net · 13/02/2024
Bluesky、まだフェデレーションできないのか
000
Reposted by RyotaK
そすうぽよ @poyo.me · 13/02/2024
Dynamicな波
052
RyotaK @ryotak.net · 13/02/2024
UnstableなTableはかなり嫌だな
020
RyotaK @ryotak.net · 12/02/2024
StableなTable
082
Reposted by RyotaK
あねてあ™ @ https://metaba.su @yr32.net · 12/02/2024
オヤジギャグ系エンジニアであるところの @ryotak.net
011
Reposted by RyotaK
あねてあ™ @ https://metaba.su @yr32.net · 12/02/2024
@ryotak.net 「だいぶTwitterだなぁ」 @ryotak.net 「『だいぶTwitter』の『ダイブツ』の部分」
012
Reposted by RyotaK
いがめた/igameta @igameta.com · 12/02/2024
だいぶTwitterの大仏の部分 by RyotaK
012
RyotaK @ryotak.net · 12/02/2024
じゃああねてあさんは邪悪の悪で
020
RyotaK @ryotak.net · 12/02/2024
独自ドメインヨシ!
020