Sign in

Michal Špaček

@spazef0rze.bsky.social
1.2K followers 52 following 93 posts

In your web, securing your app. Hacker, webdev, speaker, engineer. Security shoptet.cz, ex-report-uri.com, ex-teenager. HTTPS = How To Transfer Private Sh💩. Also infosec.exchange/@spazef0rze

PostsRepliesMedia
Michal Špaček @spazef0rze.bsky.social · 30/09/2026
Microsoft has added a native Linux containers support to Windows via CLI and API and is planning to further develop it. Imagine traveling back in time 20 years and posting this to a random online discussion forum 😅 blogs.windows.com/windowsdevel...
blogs.windows.com
WSL containers is now generally available
WSL is central to our commitment to making Windows the best place to build, run and manage Linux workloads. As AI, cloud-native development, containers, and open-source ecosystems continue to converge...
060
Michal Špaček @spazef0rze.bsky.social · 26/09/2026
Sometimes it's the small things. Thanks Chrome Dev Tools, "Edit and resend as fetch" saves me a lot of "Copy as fetch, Ctrl+V, damn this is not the console window"-moments.
020
Michal Špaček @spazef0rze.bsky.social · 19/09/2026
If you google Bletchley Park you get this cool on-topic Easter egg
000
Michal Špaček @spazef0rze.bsky.social · 16/09/2026
For some time, I've been using mx[1-4].smtp.goog for my DNS MX records - Google's unofficial DNSSEC signed MX. It was even official for a short time about a year ago: web.archive.org/web/20250904... but that link now redirects to a page that just says to use smtp.google.com. But recently...
100
Michal Špaček @spazef0rze.bsky.social · 15/08/2026
I just learned there's a .CYOU ("See you") top-level domain. I fully expected it to be a typo of a .CZ domain (because Czech and English keyboards have swapped Y and Z, and even I personally sometimes type .CY instead of .CZ), but no, not a typo. And there's also the .ICU ("I see you") domain 🙄
010
Michal Špaček @spazef0rze.bsky.social · 26/05/2026
After many JS-related supply chain attacks, there's a new PHP one! "The attacker replaced many or all release tags in four laravel-lang/ repositories with malicious lookalikes that point to their own commits which contained malware." snyk.io/blog/laravel...
snyk.io
Laravel Lang Supply Chain Advisory | Snyk
Laravel Lang Packagist releases were republished with malicious code. Learn how the supply chain attack worked, what was stolen, and how to respond.
000
Michal Špaček @spazef0rze.bsky.social · 24/05/2026
Whenever I see an email like this (in my spambox), with a Google Form asking for your email and a repo URL, all I can see is yet another supply chain attack in the making. I wouldn't want to run a legit competition nowadays 😅 (Disclaimer: I have no idea what KaiCode is)
001
Michal Špaček @spazef0rze.bsky.social · 30/04/2026
Detailed report from DigiCert (thanks!) about "a limited number of code signing certificates, few of which were then used to sign malware". At the beginning a ZIP file with a .scr executable, and some time later 60 revoked Code Signing certificates. bugzilla.mozilla.org/show_bug.cgi...
bugzilla.mozilla.org
2033170 - DigiCert: Misissued code signing certificates
ASSIGNED (dcbugzillaresponse) in CA Program - CA Certificate Compliance. Last updated 2026-04-28.
010
Michal Špaček @spazef0rze.bsky.social · 04/04/2026
The Axios supply chain attack post mortem notes show how it was done: via a fake cloned company on a fake Teams call. The two comments with details: github.com/axios/axios/... and github.com/axios/axios/...
030
Michal Špaček @spazef0rze.bsky.social · 28/03/2026
Here's your (ir)regular reminder that HTTPS certificates without the CN (Common Name) field are completely valid. For example the 6-day certificates from Let's Encrypt do not have a CN as per the "shortlived" profile letsencrypt.org/docs/profiles/
letsencrypt.org
Profiles
A profile is a collection of characteristics that describe both the validation process required to get a certificate, and the final contents of that certificate. For the vast majority of Let’s Encrypt...
000
Michal Špaček @spazef0rze.bsky.social · 25/03/2026
I always find entering personal details into a website to tell them to stop processing my personal data a bit absurd. This biz data enrichment company is processing my personal phone number. They told me to fill out this form, so I did. Now I'm asking how they process my data I have entered 😅
110
Michal Špaček @spazef0rze.bsky.social · 16/03/2026
My favorite XSS trick when you can add only attributes (when < and > are removed from the input) is to add onfocus=alert(1) and autofocus: <input value="" onfocus="..." autofocus=""> To not create a loop, I add this.blur(), otherwise alert() steals the focus, and then the field gains it once again.
041
Michal Špaček @spazef0rze.bsky.social · 13/03/2026
Naming is hard, so that's why my PHPStan extension called "Disallowed **Calls**" now supports disallowing **properties** 😅 Also a Friday the 13th release 👻 (at least in my timezone) github.com/spaze/phpsta...
github.com
Release Can disallow properties · spaze/phpstan-disallowed-calls
Naming is hard, so that's why this Disallowed Calls extension now supports disallowing instance and static properties, and enum properties with disallowProperties (#378) Other (mostly) internal cha...
000
Michal Špaček @spazef0rze.bsky.social · 27/01/2026
When issuing a HTTPS certificate, the CA needs to make sure you own the domain, and one of the many methods is via email where they'll email you a link. This method will be discouraged in March 2026, disabled in March 2028. See security.googleblog.com/2025/12/http... + cabforum.org/2025/11/20/b...
security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
Posted by Chrome Root Program Team Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the...
010
Michal Špaček @spazef0rze.bsky.social · 29/12/2025
Instead of `cat`, I use `bat`, "a cat(1) clone with wings." github.com/sharkdp/bat It supports syntax, line nrs, git etc. I have it aliased to `cat`. If you'd like to concat multiple files into one (`cat 1 2 3 > foo`), you should run the original like `\cat`, seems faster, in my case up to 10x.
github.com
GitHub - sharkdp/bat: A cat(1) clone with wings.
A cat(1) clone with wings. Contribute to sharkdp/bat development by creating an account on GitHub.
020
Michal Špaček @spazef0rze.bsky.social · 18/12/2025
Best news I've discovered today is that ripgrep is also available for Windows and you can install it with winget (winget install ripgrep). ripgrep is like the grep utility in Linux, but a bit faster, it also accepts grep's params github.com/burntsushi/r...
github.com
GitHub - BurntSushi/ripgrep: ripgrep recursively searches directories for a regex pattern while respecting your gitignore
ripgrep recursively searches directories for a regex pattern while respecting your gitignore - BurntSushi/ripgrep
011
Reposted by Michal Špaček
Per Thorsheim @thorsheim.bsky.social · 09/12/2025
Michal Špaček @spazef0rze.bsky.social presenting his talk "Password Reuse Is a Dumpster Fire – We Brought a Hose" at #PasswordsCon in Prague, December 2, 2025. youtu.be/AuCNgoDf-5c
youtu.be
Michal Špaček: Password Reuse Is a Dumpster Fire – We Brought a Hose
YouTube video by Per Thorsheim
034
Michal Špaček @spazef0rze.bsky.social · 28/11/2025
Looking at my access logs, the easiest way to block web scanners & bots is to block requests with a User-Agent header that says "old browser" where old is -10 major versions and older😁 For example Chrome is v142 and bots use Chrome/120, 116 etc. It's mostly a fun idea but it seems like I need a PoC😅
020
Michal Špaček @spazef0rze.bsky.social · 29/10/2025
TIL that OCI stands for "Oracle Cloud Infrastructure" and also "Open Container Initiative". I've first learned about the former ("Oracle Cloud Infrastructure") and just spent 5 minutes trying to understand a bug where they used OCI in the latter meaning ("resolves remote OCI artifacts")
020
Reposted by Michal Špaček
Eiji Kitamura / えーじ @agektmr.com · 10/10/2025
Chrome for Android can now help users adopt passkeys more seamlessly. If a user signs in with a saved password , your website can request that an associated password manager (in many cases on Chrome is Google Password Manager) creates a passkey automatically. developer.chrome.com/blog/automat...
developer.chrome.com
Automatic passkey creation in Chrome for Android  |  Blog  |  Chrome for Developers
Chrome for Android can now automatically create passkeys after password sign-in, helping users transition to passkeys with less friction.
045
Michal Špaček @spazef0rze.bsky.social · 24/09/2025
My random number generator just did a Dilbert
Upper part of the image is a Dilbert comic titled "Tour of Accounting" where in the first frame there's Dilbert presumably in hell, because there's a creature resembling a cute devil next to him. The creature is saying "Over here we have our random number generator." In the next frame there's another creature saying "Nine nine nine nine nine nine". In the last frame Dilbert asks "Are you sure that's random?" while the creature from the first frame responds "That's the problem with randomness, you can never be sure."

Below the strip is a screenshot of a code using a random number generator:
> random_int(0, 29)
= 9

> random_int(0, 29)
= 9
030
Michal Špaček @spazef0rze.bsky.social · 18/09/2025
Did you know Facebook has a Certificate Transparency monitoring tool? Never mind then, they're shutting it down anyway :-) developers.facebook.com/tools/ct
000
Michal Špaček @spazef0rze.bsky.social · 14/09/2025
Just noticed that my PHPStan extension to detect disallowed calls, methods, attributes, constants etc. has been installed more than 15M times, wow! Not bad for a weekend project (a long weekend since 2018). PHPStan itself has 300M installs, so 5% of all PHPStans installs use the extension, nice! :-)
160
Michal Špaček @spazef0rze.bsky.social · 23/08/2025
HTTPS certificates can exist without the CN (Common Name) field. It's not used for validation, instead browsers use the SAN (Subject Alternative Names) field. But if your tool uses CN for anything, e.g. to show a "name" for management purposes, check whether the tool works with CN-less certificates
111
Michal Špaček @spazef0rze.bsky.social · 08/08/2025
There should be an HTTP response code in the 4xx range that would instruct the client to refresh their stale DNS records. Even after 48 hours some bots (looking at you Palo Alto Networks) are using the old IP for a hostname, while the DNS records have TTL of 5 minutes or so.
220
Michal Špaček @spazef0rze.bsky.social · 01/08/2025
Here's one information for you: should be more specific when phishing IT folks
Someone in my DMs:
Hi Do you have any debit card information you can share with me? I’m struggling atm. Need help

Me:
Yeah, it’s a matte plastic Visa debit card, issued by a local bank. Made in 2024. The chip’s shiny. Hope that helps!
030
Michal Špaček @spazef0rze.bsky.social · 01/08/2025
GiveWP (the donations WordPress plugin) managed to leak donors' emails into the donation form. And then they managed to mess up the communication :-( Nice resume of the problem at the Pi-hole blog as they were one of the affected sites pi-hole.net/blog/2025/07... Go and learn how to communicate.
pi-hole.net
Compromised Donor Emails: A post-mortem – Pi-hole
000
Michal Špaček @spazef0rze.bsky.social · 29/07/2025
Setting up a new server and I'm so happy I can do it remotely because it must be absolutely cold in the data center
A Linux login screen after signing in, shows "Temperature: -273.1 C"
120
Michal Špaček @spazef0rze.bsky.social · 28/07/2025
My last name (Špaček) means starling in Czech. This guy used my veeery distant relative to store an image, nice 😁 Looking forward to an update to RFC 1149 where you don't need a small scroll of paper but instead use the carrier itself to store the data.
110
Michal Špaček @spazef0rze.bsky.social · 26/07/2025
I was today years old when I found out that the name of the company who's created Wolfenstein 3D and Doom, id Software, is pronounced "id software", "id" as in "kid", not "eye dee software" That's some 30 years after playing the games... en.wikipedia.org/wiki/Id_Soft...
en.wikipedia.org
id Software - Wikipedia
150
Michal Špaček @spazef0rze.bsky.social · 23/07/2025
It's been 0 days since git reflog saved my ass (and files) again. Instead of rebase this branch, I did reset this branch, losing my commits. `git reflog`, find out what happened (reset at {46} and {48} in the pic), then `git branch name id` (id ends with 67 at {50}, commits are back.
161
Michal Špaček @spazef0rze.bsky.social · 09/07/2025
What do you do when you can't sleep? I fine-tune my HTTP reasons 💤
A screenshot from a terminal with a curl output that shows an HTTP response with "HTTP/1.1 404 This is a not found page source trust me bro" HTTP status code and reason, followed by some other standard HTTP response headers like Date, Content-Type, Transfer-Encoding and Connection, all with rather expected values.
020
Michal Špaček @spazef0rze.bsky.social · 07/07/2025
I've asked ChatGPT to generate me a temp profile picture and when I've praised the creation it didn't know what to say, so it gave me back some JSON with a prompt that has resembled my instructions. ChatGPT then claimed, multiple times that I asked for the JSON 😁 I haven't talked about JSON before.
Screenshot of ChatGPT sending me my temp pic, my reaction "fuck me thats cool" with ChatGPT responding back with some JSON.
020
Michal Špaček @spazef0rze.bsky.social · 26/06/2025
Stored XSS via an archive file stored in a RAR archive, nice 😁 Fixed in WinRAR 7.12 released yesterday.
020
Michal Špaček @spazef0rze.bsky.social · 25/06/2025
I have a battery powered outdoor camera, it can last several weeks on a single charge in that environment. But suddenly, the battery went from 20% to 0% overnight. I was curious what happened so I checked the last pic it has recorded. Yeah, thanks little fella 😂
120
Reposted by Michal Špaček
Per Thorsheim @thorsheim.bsky.social · 19/06/2025
1) I call BULLSHIT on this latest claim of a 16-billion record data breach "that no one's ever heard of". Let me explain why (thread). cc @dangoodin.bsky.social cybernews.com/security/bil...
cybernews.com
The 16-billion-record data breach that no one’s ever heard of
Researchers discovered 16 billion exposed login credentials from infostealer malware, creating unprecedented risks for account takeovers.
4164
Michal Špaček @spazef0rze.bsky.social · 11/05/2025
My mobile Chrome got bored and started spinning the site settings icon whenever I reload the page. It does that on 2nd reload but only on this particular site. What sorcery is that? What is Chrome trying to tell me? I don't see anything unusual when I click it. Or am I just tripping?
110
Michal Špaček @spazef0rze.bsky.social · 08/05/2025
When your boss tells you to go phishing but you can't just be bothered today.
A screenshot of a direct message that says: "Hey is there any chance I can use your card to buy something for my school work pls"
040
Reposted by Michal Špaček
WebExpo Conference @webexpo.bsky.social · 05/05/2025
🔐 Discover how Sec-HTTP headers and Content Security Policy (CSP) can help you create fast, good, and cheap solutions all at once. At WebExpo 2024, @spazef0rze.bsky.social explained how fetch metadata protects public tools like an internal email generator without needing extra logins.
webexpo.net
Content Security Policy & fetch metadata: Your new security Swiss-army knife
May 28-30, 2025
031
Michal Špaček @spazef0rze.bsky.social · 16/04/2025
CA/B Forum, a group of certificate authorities and browsers, voted for reducing HTTPS server certificate validity period from 398 days to 47 days eventually. The changes are currently in a review period, soon to be added to the so called Baseline Requirements.
120
Michal Špaček @spazef0rze.bsky.social · 08/04/2025
Certbot, the tool to get HTTPS certificates from Let's Encrypt and other CAs, has released version 4.0. Notable changes are the support for profiles, which is how you can select which certificate type you'd like. The 6-day certificates from Let's Encrypt later this year will be a special profile.
github.com
Release Certbot 4.0.0 · certbot/certbot
Added The --preferred-profile and --required-profile flags allow requesting a profile. https://datatracker.ietf.org/doc/draft-aaron-acme-profiles/ Changed Certificates now renew with 1/3rd of l...
131
Michal Špaček @spazef0rze.bsky.social · 08/04/2025
It doesn't happen very often, but a new timezone was created earlier this year in March. It's called America/Coyhaique and has been created because a region called Aysén has stopped shifting from UTC-4 to -3 and will stay UTC-3 all year round, joining the Magallanes region below.
130
Michal Špaček @spazef0rze.bsky.social · 14/03/2025
PHP has a function to compare two hashes (non-password hashes): hash_equals. It has two parameters: known_string and user_string and I never knew which one is which, because even the known_string was a user string once 😅 The manual page was rewritten some time ago and it's now much better:
130
Reposted by Michal Špaček
Chris Wysopal @weld.bsky.social · 05/03/2025
Newcomers to password cracking should learn that in 1991 the 1st well known password cracker @alecmuffett.bsky.social's Crack introduced applying rules & permutations to dictionary words, such as substituting numbers for letters, reversing words, appending digits, & other common user habits. 1/3
34115
Michal Špaček @spazef0rze.bsky.social · 27/02/2025
Some time ago, my mobile Chrome seemingly removed the option to view page source by prefixing the URL with `view-source:`. It always goes to Google whenever I hit Enter on the on-screen keyboard. Not sure why, but now you have to select/tap the other item in the URL bar, the one with the globe.
120
Michal Špaček @spazef0rze.bsky.social · 13/02/2025
New Safari is going to show a warning when HTTPS uses 3DES cipher suites which should not really be used anymore github.com/WebKit/WebKi... The warning will be similar to the TLS 1.0/1.1 warning. Safari Tech Preview 213 already shows it webkit.org/blog/16461/r...
github.com
Treat 3DES cipher suites as legacy TLS by achristensen07 · Pull Request #38873 · WebKit/WebKit
732ecf6 Treat 3DES cipher suites as legacy TLS https://bugs.webkit.org/show_bug.cgi?id=285774 rdar://138948491 Reviewed by Chris Dumez. This treats it the same as TLS 1.0 and 1.1, which cause a w...
040
Michal Špaček @spazef0rze.bsky.social · 07/02/2025
Let's Encrypt is ending their certificate expiration notification emails in June letsencrypt.org/2025/01/22/e... I liked the service not as primary means of notifying me I should renew my certs, but as a notification that the renewal has failed. A renewal failure usually means I messed something up.
letsencrypt.org
Ending Support for Expiration Notification Emails
Since its inception, Let&rsquo;s Encrypt has been sending expiration notification emails to subscribers that have provided an email address to us. We will be ending this service on June 4, 2025. The d...
110
Michal Špaček @spazef0rze.bsky.social · 24/01/2025
Nice 0-click deanonymization attack targeting Signal and Discord using Cloudflare cache metadata in the Cf-Ray HTTP header that contains the data center code (e.g. PRG for Prague). The reporter found a way to ask Cloudflare datacenters if the resource is cached there gist.github.com/hackermondev...
gist.github.com
Unique 0-click deanonymization attack targeting Signal, Discord and hundreds of platform
Unique 0-click deanonymization attack targeting Signal, Discord and hundreds of platform - research.md
020
Michal Špaček @spazef0rze.bsky.social · 18/01/2025
Had to send someone a hard drive with some data and wanted to know if no one had copied them when the drive was in the hands of the courier company. Yes, that's "tamper-evident" nail polish and tape 💅
3192
Michal Špaček @spazef0rze.bsky.social · 21/12/2024
"We and our 1276 technology partners ask you to consent to the use of cookies to store and access personal data on your device." 1276... technology... partners. I don't usually see those popups, my content blocker hides them, but this one caught my attention... that's a crazy number.
Privacy notice on thedrive.com that starts "We and our 1276 technology partners ask you to consent to the use of cookies to store and access personal data on your device."
240