<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: pentestercrab</title><link>https://news.ycombinator.com/user?id=pentestercrab</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 05 May 2026 08:36:02 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=pentestercrab" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[When Dawkins met Claude – Could this AI be conscious?]]></title><description><![CDATA[
<p><a href="https://archive.ph/Rq5bw" rel="nofollow">https://archive.ph/Rq5bw</a></p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47972481">https://news.ycombinator.com/item?id=47972481</a></p>
<p>Points: 60</p>
<p># Comments: 422</p>
]]></description><pubDate>Fri, 01 May 2026 08:36:19 +0000</pubDate><link>https://unherd.com/2026/04/is-ai-the-next-phase-of-evolution/</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=47972481</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47972481</guid></item><item><title><![CDATA[Ruby Array Pack Bleed]]></title><description><![CDATA[
<p>Article URL: <a href="https://nastystereo.com/security/ruby-pack.html">https://nastystereo.com/security/ruby-pack.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46520566">https://news.ycombinator.com/item?id=46520566</a></p>
<p>Points: 62</p>
<p># Comments: 1</p>
]]></description><pubDate>Tue, 06 Jan 2026 23:46:24 +0000</pubDate><link>https://nastystereo.com/security/ruby-pack.html</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=46520566</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46520566</guid></item><item><title><![CDATA[Ruby Array Pack Bleed – Impacts Ruby 1.6.7 to 4.0.0]]></title><description><![CDATA[
<p>Article URL: <a href="https://nastystereo.com/security/ruby-pack.html">https://nastystereo.com/security/ruby-pack.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46432066">https://news.ycombinator.com/item?id=46432066</a></p>
<p>Points: 9</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 30 Dec 2025 11:14:30 +0000</pubDate><link>https://nastystereo.com/security/ruby-pack.html</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=46432066</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46432066</guid></item><item><title><![CDATA[Inline Style Exfiltration: leaking data with chained CSS conditionals]]></title><description><![CDATA[
<p>Article URL: <a href="https://portswigger.net/research/inline-style-exfiltration">https://portswigger.net/research/inline-style-exfiltration</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=45039468">https://news.ycombinator.com/item?id=45039468</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 27 Aug 2025 13:33:58 +0000</pubDate><link>https://portswigger.net/research/inline-style-exfiltration</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=45039468</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45039468</guid></item><item><title><![CDATA[Marshal madness: A brief history of Ruby deserialization exploits]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.trailofbits.com/2025/08/20/marshal-madness-a-brief-history-of-ruby-deserialization-exploits/">https://blog.trailofbits.com/2025/08/20/marshal-madness-a-brief-history-of-ruby-deserialization-exploits/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44960942">https://news.ycombinator.com/item?id=44960942</a></p>
<p>Points: 25</p>
<p># Comments: 4</p>
]]></description><pubDate>Wed, 20 Aug 2025 11:41:33 +0000</pubDate><link>https://blog.trailofbits.com/2025/08/20/marshal-madness-a-brief-history-of-ruby-deserialization-exploits/</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=44960942</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44960942</guid></item><item><title><![CDATA[Breaking the Sorting Barrier for Directed Single-Source Shortest Paths]]></title><description><![CDATA[
<p>Article URL: <a href="https://arxiv.org/abs/2504.17033">https://arxiv.org/abs/2504.17033</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44844257">https://news.ycombinator.com/item?id=44844257</a></p>
<p>Points: 99</p>
<p># Comments: 3</p>
]]></description><pubDate>Sat, 09 Aug 2025 05:34:09 +0000</pubDate><link>https://arxiv.org/abs/2504.17033</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=44844257</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44844257</guid></item><item><title><![CDATA[New comment by pentestercrab in "Google's shortened goo.gl links will stop working next month"]]></title><description><![CDATA[
<p>There seems to have been a recent uptick in phishers using goo.gl URLs. Yes, even without new URLs being accepted by registering expired domains with an old reference.</p>
]]></description><pubDate>Fri, 25 Jul 2025 15:58:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=44684668</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=44684668</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44684668</guid></item><item><title><![CDATA[New comment by pentestercrab in "Former cybersecurity chief Chris Krebs leaves SentinelOne after executive order"]]></title><description><![CDATA[
<p>The risky.biz podcast episode got pulled too: <a href="https://bsky.app/profile/patrick.risky.biz/post/3lmioqiobks2y" rel="nofollow">https://bsky.app/profile/patrick.risky.biz/post/3lmioqiobks2...</a></p>
]]></description><pubDate>Wed, 16 Apr 2025 23:32:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=43711463</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=43711463</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43711463</guid></item><item><title><![CDATA[New Method to Leverage Unsafe Reflection and Deserialisation to RCE on Rails]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.elttam.com/blog/rails-sqlite-gadget-rce/">https://www.elttam.com/blog/rails-sqlite-gadget-rce/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=43263040">https://news.ycombinator.com/item?id=43263040</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 05 Mar 2025 05:00:39 +0000</pubDate><link>https://www.elttam.com/blog/rails-sqlite-gadget-rce/</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=43263040</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43263040</guid></item><item><title><![CDATA[Escaping Ruby's Gem:SafeMarshal Sandbox]]></title><description><![CDATA[
<p>Article URL: <a href="https://nastystereo.com/security/ruby-safe-marshal-escape.html">https://nastystereo.com/security/ruby-safe-marshal-escape.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=42657575">https://news.ycombinator.com/item?id=42657575</a></p>
<p>Points: 2</p>
<p># Comments: 1</p>
]]></description><pubDate>Fri, 10 Jan 2025 17:14:34 +0000</pubDate><link>https://nastystereo.com/security/ruby-safe-marshal-escape.html</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=42657575</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42657575</guid></item><item><title><![CDATA[Escaping Ruby's Gem:SafeMarshal Sandbox]]></title><description><![CDATA[
<p>Article URL: <a href="https://nastystereo.com/security/ruby-safe-marshal-escape.html">https://nastystereo.com/security/ruby-safe-marshal-escape.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=42513334">https://news.ycombinator.com/item?id=42513334</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 26 Dec 2024 05:30:27 +0000</pubDate><link>https://nastystereo.com/security/ruby-safe-marshal-escape.html</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=42513334</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42513334</guid></item><item><title><![CDATA[RubyGem's Gem:SafeMarshal buffer overrun with length larger than fit into a byte]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/rubygems/rubygems/pull/8305">https://github.com/rubygems/rubygems/pull/8305</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=42347679">https://news.ycombinator.com/item?id=42347679</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 07 Dec 2024 06:22:37 +0000</pubDate><link>https://github.com/rubygems/rubygems/pull/8305</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=42347679</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42347679</guid></item><item><title><![CDATA[CORS Vulnerabilities in Go: Vulnerable Patterns and Lessons]]></title><description><![CDATA[
<p>Article URL: <a href="https://pentesterlab.com/blog/golang-cors-vulnerabilities">https://pentesterlab.com/blog/golang-cors-vulnerabilities</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=42308815">https://news.ycombinator.com/item?id=42308815</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 03 Dec 2024 17:38:59 +0000</pubDate><link>https://pentesterlab.com/blog/golang-cors-vulnerabilities</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=42308815</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42308815</guid></item><item><title><![CDATA[Shiny Vulnerabilities in R's Most Popular Web Framework]]></title><description><![CDATA[
<p>Article URL: <a href="https://nastystereo.com/security/r-shiny-bugs.html">https://nastystereo.com/security/r-shiny-bugs.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=42297365">https://news.ycombinator.com/item?id=42297365</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 02 Dec 2024 15:54:15 +0000</pubDate><link>https://nastystereo.com/security/r-shiny-bugs.html</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=42297365</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42297365</guid></item><item><title><![CDATA[PentesterLab: Web Hacking and Security Code Review 600 exercises and 700 videos]]></title><description><![CDATA[
<p>Article URL: <a href="https://pentesterlab.com/">https://pentesterlab.com/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=42257187">https://news.ycombinator.com/item?id=42257187</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 27 Nov 2024 16:16:25 +0000</pubDate><link>https://pentesterlab.com/</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=42257187</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42257187</guid></item><item><title><![CDATA[Cross-Site Post Requests Without a Content-Type Header – CSRF Attack]]></title><description><![CDATA[
<p>Article URL: <a href="https://nastystereo.com/security/cross-site-post-without-content-type.html">https://nastystereo.com/security/cross-site-post-without-content-type.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=42254457">https://news.ycombinator.com/item?id=42254457</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 27 Nov 2024 09:28:30 +0000</pubDate><link>https://nastystereo.com/security/cross-site-post-without-content-type.html</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=42254457</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42254457</guid></item><item><title><![CDATA[Execute commands by sending JSON? Ruby deserialization vulnerabilities]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.blog/security/vulnerability-research/execute-commands-by-sending-json-learn-how-unsafe-deserialization-vulnerabilities-work-in-ruby-projects/">https://github.blog/security/vulnerability-research/execute-commands-by-sending-json-learn-how-unsafe-deserialization-vulnerabilities-work-in-ruby-projects/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=42234085">https://news.ycombinator.com/item?id=42234085</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 25 Nov 2024 07:44:32 +0000</pubDate><link>https://github.blog/security/vulnerability-research/execute-commands-by-sending-json-learn-how-unsafe-deserialization-vulnerabilities-work-in-ruby-projects/</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=42234085</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42234085</guid></item><item><title><![CDATA[JWT Libraries Block Algorithm Confusion: Key Lessons for Code Review]]></title><description><![CDATA[
<p>Article URL: <a href="https://pentesterlab.com/blog/jwt-algorithm-confusion-code-review-lessons">https://pentesterlab.com/blog/jwt-algorithm-confusion-code-review-lessons</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=42233831">https://news.ycombinator.com/item?id=42233831</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 25 Nov 2024 06:45:10 +0000</pubDate><link>https://pentesterlab.com/blog/jwt-algorithm-confusion-code-review-lessons</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=42233831</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42233831</guid></item><item><title><![CDATA[Chosen-Prefix Collisions on AES-Like Hashing]]></title><description><![CDATA[
<p>Article URL: <a href="https://eprint.iacr.org/2024/1888">https://eprint.iacr.org/2024/1888</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=42233648">https://news.ycombinator.com/item?id=42233648</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 25 Nov 2024 06:01:51 +0000</pubDate><link>https://eprint.iacr.org/2024/1888</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=42233648</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42233648</guid></item><item><title><![CDATA[New comment by pentestercrab in "Ruby 3.4 Universal RCE Deserialization Gadget Chain"]]></title><description><![CDATA[
<p>Once again GTFOBins[0] proving to be a valuable resource.<p>[0] <a href="https://gtfobins.github.io/" rel="nofollow">https://gtfobins.github.io/</a></p>
]]></description><pubDate>Mon, 25 Nov 2024 06:01:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=42233644</link><dc:creator>pentestercrab</dc:creator><comments>https://news.ycombinator.com/item?id=42233644</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42233644</guid></item></channel></rss>