toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

334
active users

#http

2 posts2 participants0 posts today
Hacker News 50<p>HTTP Feeds: a minimal specification for polling events over HTTP</p><p>Link: <a href="https://www.http-feeds.org/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">http-feeds.org/</span><span class="invisible"></span></a><br>Discussion: <a href="https://news.ycombinator.com/item?id=43805358" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.ycombinator.com/item?id=4</span><span class="invisible">3805358</span></a></p><p><a href="https://social.lansky.name/tags/http" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>http</span></a></p>
Hacker News 50<p>Show HN: Faasta – A self-hosted Serverless platform for WASM-wasi-HTTP in Rust</p><p>Link: <a href="https://github.com/fourlexboehm/faasta" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">github.com/fourlexboehm/faasta</span><span class="invisible"></span></a><br>Discussion: <a href="https://news.ycombinator.com/item?id=43789010" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.ycombinator.com/item?id=4</span><span class="invisible">3789010</span></a></p><p><a href="https://social.lansky.name/tags/serverless" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>serverless</span></a> <a href="https://social.lansky.name/tags/rust" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>rust</span></a> <a href="https://social.lansky.name/tags/http" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>http</span></a></p>
argv minus one<p>Just found out that it is no longer possible to straightforwardly write HTTP/1 requests by hand on the <a href="https://mastodon.sdf.org/tags/terminal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>terminal</span></a>.</p><p>Modern <a href="https://mastodon.sdf.org/tags/Apache" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Apache</span></a> will reject <a href="https://mastodon.sdf.org/tags/HTTP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HTTP</span></a> 1.x requests where the line endings are not CRLF, and as far as I know it's not possible on <a href="https://mastodon.sdf.org/tags/Linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linux</span></a> to type a CR using the keyboard. Ctrl+M should do it in theory, but when I try, it produces LF instead of CR for some reason.</p><p>Is there by any chance a way to make the Linux <a href="https://mastodon.sdf.org/tags/console" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>console</span></a> (or <a href="https://mastodon.sdf.org/tags/KDE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>KDE</span></a> <a href="https://mastodon.sdf.org/tags/Konsole" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konsole</span></a>) produce CRLF when I push the Enter key?</p>
OTX Bot<p>Threat Infrastructure Uncovered Before Activation</p><p>Between November 2024 and April 2025, a set of domains and servers impersonating an Iraqi academic organization and fictitious UK tech firms were tracked. The infrastructure, while dormant, exhibited characteristics similar to APT34 (OilRig), including shared SSH keys, structured websites, and decoy HTTP behavior on M247-hosted servers. Key observations include the use of port 8080 for fake 404 responses, consistent SSH fingerprint reuse, and domains registered through P.D.R. Solutions with regway.com nameservers. The setup suggests deliberate pre-operational staging, offering defenders an early warning opportunity. Detection strategies include monitoring SSH fingerprints, HTTP response patterns, and domain registration behaviors.</p><p>Pulse ID: 68082a17ee5771aa012e93c3<br>Pulse Link: <a href="https://otx.alienvault.com/pulse/68082a17ee5771aa012e93c3" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">otx.alienvault.com/pulse/68082</span><span class="invisible">a17ee5771aa012e93c3</span></a> <br>Pulse Author: AlienVault<br>Created: 2025-04-22 23:45:27</p><p>Be advised, this data is unverified and should be considered preliminary. Always do further verification.</p><p><a href="https://social.raytec.co/tags/APT34" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>APT34</span></a> <a href="https://social.raytec.co/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurity</span></a> <a href="https://social.raytec.co/tags/HTTP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HTTP</span></a> <a href="https://social.raytec.co/tags/ICS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ICS</span></a> <a href="https://social.raytec.co/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://social.raytec.co/tags/OTX" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OTX</span></a> <a href="https://social.raytec.co/tags/OilRig" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OilRig</span></a> <a href="https://social.raytec.co/tags/OpenThreatExchange" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenThreatExchange</span></a> <a href="https://social.raytec.co/tags/RAT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RAT</span></a> <a href="https://social.raytec.co/tags/SSH" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SSH</span></a> <a href="https://social.raytec.co/tags/UK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>UK</span></a> <a href="https://social.raytec.co/tags/bot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bot</span></a> <a href="https://social.raytec.co/tags/AlienVault" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AlienVault</span></a></p>
iX Magazin<p>iX-Workshop API-Sicherheit: OWASP Top 10 API Security Risks</p><p>Lernen Sie hands-on, wie Sie Schwachstellen in der API-Implementierung vermeiden und Angriffe abwehren.</p><p><a href="https://www.heise.de/news/iX-Workshop-API-Sicherheit-OWASP-Top-10-API-Security-Risks-10354126.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&amp;utm_source=mastodon" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">heise.de/news/iX-Workshop-API-</span><span class="invisible">Sicherheit-OWASP-Top-10-API-Security-Risks-10354126.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&amp;utm_source=mastodon</span></a></p><p><a href="https://social.heise.de/tags/API" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>API</span></a> <a href="https://social.heise.de/tags/IdentityManagement" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IdentityManagement</span></a> <a href="https://social.heise.de/tags/HTTP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HTTP</span></a> <a href="https://social.heise.de/tags/IT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IT</span></a> <a href="https://social.heise.de/tags/iXWorkshops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iXWorkshops</span></a> <a href="https://social.heise.de/tags/OWASP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OWASP</span></a> <a href="https://social.heise.de/tags/Schnittstellen" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Schnittstellen</span></a> <a href="https://social.heise.de/tags/Sicherheitsl%C3%BCcken" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Sicherheitslücken</span></a> <a href="https://social.heise.de/tags/news" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>news</span></a></p>
David Bombal<p>How TCP really works: Top 3 things you need to know!</p><p>YouTube video with the amazing Chris Greer: <a href="https://youtu.be/Auwn3RWapRE" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">youtu.be/Auwn3RWapRE</span><span class="invisible"></span></a></p><p><a href="https://infosec.exchange/tags/wireshark" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>wireshark</span></a> <a href="https://infosec.exchange/tags/tcp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tcp</span></a> <a href="https://infosec.exchange/tags/ip" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ip</span></a> <a href="https://infosec.exchange/tags/udp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>udp</span></a> <a href="https://infosec.exchange/tags/quic" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>quic</span></a> <a href="https://infosec.exchange/tags/tcpip" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tcpip</span></a> <a href="https://infosec.exchange/tags/network" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>network</span></a> <a href="https://infosec.exchange/tags/ccna" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ccna</span></a> <a href="https://infosec.exchange/tags/ccnp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ccnp</span></a> <a href="https://infosec.exchange/tags/ccie" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ccie</span></a> <a href="https://infosec.exchange/tags/internet" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>internet</span></a> <a href="https://infosec.exchange/tags/tls" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tls</span></a> <a href="https://infosec.exchange/tags/ssl" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ssl</span></a> <a href="https://infosec.exchange/tags/http" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>http</span></a> <a href="https://infosec.exchange/tags/https" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>https</span></a> <a href="https://infosec.exchange/tags/troubleshooting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>troubleshooting</span></a></p>
Neustradamus :xmpp: :linux:<p><a href="https://mastodon.social/tags/Freenginx" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Freenginx</span></a> 1.27.6 has been released (<a href="https://mastodon.social/tags/nginx" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>nginx</span></a> / <a href="https://mastodon.social/tags/http" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>http</span></a> / <a href="https://mastodon.social/tags/http2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>http2</span></a> / <a href="https://mastodon.social/tags/http3" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>http3</span></a> / <a href="https://mastodon.social/tags/httpd" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>httpd</span></a> / <a href="https://mastodon.social/tags/Web" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Web</span></a> / <a href="https://mastodon.social/tags/Webserver" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Webserver</span></a> / <a href="https://mastodon.social/tags/TLS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TLS</span></a> / <a href="https://mastodon.social/tags/TLS13" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TLS13</span></a>) <a href="https://freenginx.org/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">freenginx.org/</span><span class="invisible"></span></a></p>
Neustradamus :xmpp: :linux:<p><a href="https://mastodon.social/tags/nginx" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>nginx</span></a> 1.27.5 (dev) has been released (<a href="https://mastodon.social/tags/http" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>http</span></a> / <a href="https://mastodon.social/tags/http2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>http2</span></a> / <a href="https://mastodon.social/tags/http3" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>http3</span></a> / <a href="https://mastodon.social/tags/httpd" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>httpd</span></a> / <a href="https://mastodon.social/tags/Web" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Web</span></a> / <a href="https://mastodon.social/tags/Webserver" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Webserver</span></a> / <a href="https://mastodon.social/tags/TLS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TLS</span></a> / <a href="https://mastodon.social/tags/TLS13" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TLS13</span></a>) <a href="https://nginx.org/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">nginx.org/</span><span class="invisible"></span></a></p>
Hacker News 50<p>Show HN: AgentAPI – HTTP API for Claude Code, Goose, Aider, and Codex</p><p>Link: <a href="https://github.com/coder/agentapi" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">github.com/coder/agentapi</span><span class="invisible"></span></a><br>Discussion: <a href="https://news.ycombinator.com/item?id=43719447" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.ycombinator.com/item?id=4</span><span class="invisible">3719447</span></a></p><p><a href="https://social.lansky.name/tags/http" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>http</span></a></p>
SMP<p>vår i västerås//spring in västerås.</p><p><a href="https://mastodonsweden.se/tags/http" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>http</span></a>://eye-c.se</p><p><a href="https://mastodonsweden.se/tags/fotografi" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fotografi</span></a> <a href="https://mastodonsweden.se/tags/foto" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>foto</span></a> <a href="https://mastodonsweden.se/tags/fotograf" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fotograf</span></a> <a href="https://mastodonsweden.se/tags/photography" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>photography</span></a> <a href="https://mastodonsweden.se/tags/photo" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>photo</span></a> <a href="https://mastodonsweden.se/tags/photographer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>photographer</span></a> <a href="https://mastodonsweden.se/tags/mastodonphotography" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>mastodonphotography</span></a> <a href="https://mastodonsweden.se/tags/mastodonphoto" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>mastodonphoto</span></a> <a href="https://mastodonsweden.se/tags/mastodonphotographer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>mastodonphotographer</span></a> <a href="https://mastodonsweden.se/tags/v%C3%A5r2025" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vår2025</span></a> <a href="https://mastodonsweden.se/tags/v%C3%A5rtecken" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vårtecken</span></a> <a href="https://mastodonsweden.se/tags/v%C3%A5rblomster" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vårblomster</span></a> <a href="https://mastodonsweden.se/tags/springtime2025" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>springtime2025</span></a> <a href="https://mastodonsweden.se/tags/springflower" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>springflower</span></a> <a href="https://mastodonsweden.se/tags/v%C3%A4ster%C3%A5s" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>västerås</span></a> <a href="https://mastodonsweden.se/tags/v%C3%A4stmanland" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>västmanland</span></a> <a href="https://mastodonsweden.se/tags/sverige" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sverige</span></a> <a href="https://mastodonsweden.se/tags/sweden" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sweden</span></a> <a href="https://mastodonsweden.se/tags/fotokurser" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fotokurser</span></a> <a href="https://mastodonsweden.se/tags/onlinekurser" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>onlinekurser</span></a> <a href="https://mastodonsweden.se/tags/bildseende" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bildseende</span></a> <a href="https://mastodonsweden.se/tags/bildskapande" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bildskapande</span></a> <a href="https://mastodonsweden.se/tags/bildkomposition" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bildkomposition</span></a> <a href="https://mastodonsweden.se/tags/bildspr%C3%A5k" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bildspråk</span></a> <a href="https://mastodonsweden.se/tags/Eye_C" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Eye_C</span></a></p>
Knowledge Zone<p><a href="https://mstdn.social/tags/QuizOfTheDay" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>QuizOfTheDay</span></a>: <a href="https://mstdn.social/tags/HTTP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HTTP</span></a> is the foundation of data communication for the World Wide Web. <a href="https://mstdn.social/tags/Internet101" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Internet101</span></a></p><p>What does HTTP stand for?</p><p>A. Hypertext Transfer Protocol<br>B. Hypertext Transfer Pace<br>C. Hyper Transfer Text Protocol<br>D. HTML Transfer Protocol</p><p><a href="https://knowledgezone.co.in/resources/quiz?qId=62c15af1f9400e255bd192ec" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">knowledgezone.co.in/resources/</span><span class="invisible">quiz?qId=62c15af1f9400e255bd192ec</span></a></p>
David Bombal<p>DDoS Attacks (HTTP/2, DNS, Hacktivist) <br>This is Real World Technical Analysis</p><p>YouTube video: <a href="https://youtu.be/t2jKcA1OyBE" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">youtu.be/t2jKcA1OyBE</span><span class="invisible"></span></a></p><p><a href="https://infosec.exchange/tags/Sponsored" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Sponsored</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/ddos" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ddos</span></a> <a href="https://infosec.exchange/tags/dos" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dos</span></a> <a href="https://infosec.exchange/tags/DNS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNS</span></a> <a href="https://infosec.exchange/tags/http" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>http</span></a> <a href="https://infosec.exchange/tags/tls" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tls</span></a> <a href="https://infosec.exchange/tags/hack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hack</span></a> <a href="https://infosec.exchange/tags/hacker" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hacker</span></a> <a href="https://infosec.exchange/tags/hacking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hacking</span></a> <a href="https://infosec.exchange/tags/cyber" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cyber</span></a> <a href="https://infosec.exchange/tags/internet" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>internet</span></a> Radware</p>
Felix Palmen :freebsd: :c64:<p>Trying to come up with my own little self-hosted <a href="https://mastodon.bsd.cafe/tags/http" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>http</span></a> <a href="https://mastodon.bsd.cafe/tags/authentication" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>authentication</span></a> <a href="https://mastodon.bsd.cafe/tags/daemon" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>daemon</span></a> to work with <a href="https://mastodon.bsd.cafe/tags/nginx" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>nginx</span></a>' "authentication request" facility ... first step done! 🥳</p><p>Now I have a subset of HTTP 1.x implemented in <a href="https://mastodon.bsd.cafe/tags/C" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>C</span></a>, together with a dummy handler showing nothing but a static hello-world root document.</p><p>I know it's kind of stubborn doing that in C, but hey, <a href="https://mastodon.bsd.cafe/tags/coding" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>coding</span></a> it is great fun 🙈 </p><p><a href="https://github.com/Zirias/swad" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">github.com/Zirias/swad</span><span class="invisible"></span></a></p>
Max Resing<p>Posted about it yesterday already. But it looks like <code>archive.today</code> shows the default page of <a href="https://infosec.exchange/tags/Apache" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Apache</span></a> <a href="https://infosec.exchange/tags/webserver" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>webserver</span></a> on <a href="https://infosec.exchange/tags/Ubuntu" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ubuntu</span></a>. The alternative domain name <code>archive.is</code> instead redirects with a <code>301 - Moved Permanently</code> to a new domain <code>krola.org</code>, a website apparently comparing pet rabbit species?? It's also interesting, that the redirect to the new domain responds with an <a href="https://infosec.exchange/tags/HTTP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HTTP</span></a> header <code>server: nginx/1.18 (Ubuntu)</code>. Apparently, the default Apache landing page also returns the same HTTP header information on the server. Perhaps the landing page is a decoy/deflection? </p><p>Anyone on <a href="https://infosec.exchange/tags/infosecexchange" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosecexchange</span></a> has any speculations on the website?</p><p><a href="https://infosec.exchange/tags/InternetArchive" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InternetArchive</span></a> <a href="https://infosec.exchange/tags/ArchiveOrg" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ArchiveOrg</span></a> <a href="https://infosec.exchange/tags/ArchiveToday" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ArchiveToday</span></a> <a href="https://infosec.exchange/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://infosec.exchange/tags/AskFedi" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AskFedi</span></a> <a href="https://infosec.exchange/tags/AskMastodon" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AskMastodon</span></a> <a href="https://infosec.exchange/tags/AskMastodonMondays" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AskMastodonMondays</span></a> <a href="https://infosec.exchange/tags/AskInfosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AskInfosec</span></a></p>
heise online English<p>Cloudflare puts an end to insecure HTTP</p><p>Plain text communication also allows unauthorized persons to view data. Cloudflare therefore also no longer supports HTTP for API calls.</p><p><a href="https://www.heise.de/en/news/Cloudflare-puts-an-end-to-insecure-HTTP-10328265.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&amp;utm_source=mastodon" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">heise.de/en/news/Cloudflare-pu</span><span class="invisible">ts-an-end-to-insecure-HTTP-10328265.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&amp;utm_source=mastodon</span></a></p><p><a href="https://social.heise.de/tags/API" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>API</span></a> <a href="https://social.heise.de/tags/HTTP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HTTP</span></a> <a href="https://social.heise.de/tags/https" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>https</span></a> <a href="https://social.heise.de/tags/IT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IT</span></a> <a href="https://social.heise.de/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://social.heise.de/tags/news" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>news</span></a></p>
heise Security<p>Cloudflare macht unsicherem HTTP den Garaus</p><p>Klartextkommunikation erlaubt auch Unbefugten Einsicht in Daten. Cloudflare unterstützt daher auch für API-Aufrufe kein HTTP mehr.</p><p><a href="https://www.heise.de/news/Cloudflare-macht-unsicherem-HTTP-den-Garaus-10328030.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&amp;utm_source=mastodon" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">heise.de/news/Cloudflare-macht</span><span class="invisible">-unsicherem-HTTP-den-Garaus-10328030.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&amp;utm_source=mastodon</span></a></p><p><a href="https://social.heise.de/tags/API" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>API</span></a> <a href="https://social.heise.de/tags/HTTP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HTTP</span></a> <a href="https://social.heise.de/tags/https" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>https</span></a> <a href="https://social.heise.de/tags/IT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IT</span></a> <a href="https://social.heise.de/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://social.heise.de/tags/news" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>news</span></a></p>
Michael Horowitz<p>Should you ever run across an article that says you don't need a VPN because most every website use HTTPS, be aware that you can not see the encryption, or the lack of it, in mobile apps. Thus, things like this happen - Apple did not bother to upgrade their own software from HTTP to HTTPS. </p><p> <a href="https://9to5mac.com/2025/03/18/apples-passwords-app-was-vulnerable-to-phishing-attacks-for-nearly-three-months-after-launch/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">9to5mac.com/2025/03/18/apples-</span><span class="invisible">passwords-app-was-vulnerable-to-phishing-attacks-for-nearly-three-months-after-launch/</span></a><br>Apple’s Passwords app was vulnerable to phishing attacks for nearly three months after launch <br><a href="https://mastodon.world/tags/vpn" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vpn</span></a> <a href="https://mastodon.world/tags/http" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>http</span></a> <a href="https://mastodon.world/tags/https" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>https</span></a> <a href="https://mastodon.world/tags/encryption" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>encryption</span></a></p>
Fedi:Tagestipp/tröt<p><b>Mastodon-Client-API</b></p><p>Auch wenn sich im <a href="https://mastodonium.de/tags/fediverse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Fediverse</span></a> viel um <a href="https://mastodonium.de/tags/activitypub" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ActivityPub</span></a> dreht und hier durchaus auch eine <a href="https://mastodonium.de/tags/client" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Client</span></a>-Schnittstelle skizziert ist, nutzt <a href="https://mastodonium.de/tags/mastodon" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mastodon</span></a> eine eigene Client-API, die (zumindest teilweise) auch von anderer fediversaler Serversoftware unterstützt wird (z.B. <a href="https://mastodonium.de/tags/friendica" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Friendica</span></a>, <a href="https://mastodonium.de/tags/firefish" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Firefish</span></a>, <a href="https://mastodonium.de/tags/mammuthus" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mammuthus</span></a>).</p><p>Diese <a href="https://mastodonium.de/tags/api" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>API</span></a> (application programming interface, eine <a href="https://mastodonium.de/tags/schnittstelle" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Schnittstelle</span></a> zur <a href="https://mastodonium.de/tags/programmierung" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Programmierung</span></a> von Anwendungen) dient Apps und Clients dazu, entsprechende Funktionen auf einer <a href="https://mastodonium.de/tags/instanz" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Instanz</span></a> durchzuführen. Diese API ermöglicht die Entwicklung von Apps wie <a href="https://mastodonium.de/tags/tusky" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tusky</span></a>, <a href="https://mastodonium.de/tags/fedilab" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Fedilab</span></a> &amp; Co.</p><p>Man kann diese API auch nutzen, um Konten etwa (teil)automatisiert zu betreiben.</p><p>Oder Statistiken zu sammeln... oder... oder... ;-)</p><p>Die API ist soweit öffentlich dokumentiert und steht frei zur Verfügung.</p><p>Allgemeine Dokumentation zu <a href="https://mastodonium.de/tags/mastodon" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mastodon</span></a> (auf Englisch):<br><a href="https://docs.joinmastodon.org/" rel="nofollow noopener noreferrer" target="_blank"><span>https://docs.joinmastodon.org/</span></a></p><p>"Getting started with the API":<br><a href="https://docs.joinmastodon.org/client/intro/" rel="nofollow noopener noreferrer" target="_blank"><span>https://docs.joinmastodon.org/client/intro/</span></a></p><p>Wer mit dem Gedanken spielt, die API zu nutzen, sollte sich mit <a href="https://mastodonium.de/tags/http" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HTTP</span></a>, <a href="https://mastodonium.de/tags/json" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>JSON</span></a> &amp; Co. anfreunden können. Und Englischkenntnisse sind in diesem Bereich grundsätzlich von Vorteil...</p>
Hacker News 50<p>HTTP/3 is everywhere but nowhere</p><p>Link: <a href="https://httptoolkit.com/blog/http3-quic-open-source-support-nowhere/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">httptoolkit.com/blog/http3-qui</span><span class="invisible">c-open-source-support-nowhere/</span></a><br>Discussion: <a href="https://news.ycombinator.com/item?id=43360251" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.ycombinator.com/item?id=4</span><span class="invisible">3360251</span></a></p><p><a href="https://social.lansky.name/tags/http" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>http</span></a></p>
iX Magazin<p>iX-Workshop API-Sicherheit: OWASP Top 10 API Security Risks</p><p>Lernen Sie hands-on, wie Sie Schwachstellen in der API-Implementierung vermeiden und Angriffe abwehren.</p><p><a href="https://www.heise.de/news/iX-Workshop-API-Sicherheit-OWASP-Top-10-API-Security-Risks-10305106.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&amp;utm_source=mastodon" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">heise.de/news/iX-Workshop-API-</span><span class="invisible">Sicherheit-OWASP-Top-10-API-Security-Risks-10305106.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&amp;utm_source=mastodon</span></a></p><p><a href="https://social.heise.de/tags/API" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>API</span></a> <a href="https://social.heise.de/tags/IdentityManagement" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IdentityManagement</span></a> <a href="https://social.heise.de/tags/HTTP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HTTP</span></a> <a href="https://social.heise.de/tags/IT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IT</span></a> <a href="https://social.heise.de/tags/iXWorkshops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iXWorkshops</span></a> <a href="https://social.heise.de/tags/OWASP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OWASP</span></a> <a href="https://social.heise.de/tags/Schnittstellen" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Schnittstellen</span></a> <a href="https://social.heise.de/tags/Sicherheitsl%C3%BCcken" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Sicherheitslücken</span></a> <a href="https://social.heise.de/tags/news" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>news</span></a></p>