top of page
Search

Small Winds - No. 04

Writer: Orel GispanOrel Gispan

Updated: Nov 1, 2024

A personal mini blog about infosec and life

Recently, YouTube reminded me of a piece I used to listen to: https://www.youtube.com/watch?v=2zcTKhohtJg.

This video includes the Minuet and Badinerie movements of Bach's Suite No. 2 in B minor. I became familiar with these pieces, specifically the Badinerie from the old 1993 "Bonus" PC game I played when I was younger. It turns out that my partner knows this game as well, so it was nostalgic and fun.


'Bonus' PC game

(🎮) I also play Little Nightmares II. It's a game where the character is small (young?) and weak, in a world full of nightmares and finds another little companion along the journey. I've never encountered a game in this genre with graphics, puzzles, and surroundings as creative and unique as this one (or maybe I just don't play a lot 🙃). They have surely succeeded in delivering the feeling of being weak and vulnerable in a world full of threats and surprises, along with self-belief and the feeling of being able to survive.


(🎥) Additionally, randomly chosen, I watched the South Korean sci-fi TV series The Silent Sea which is one of the best TV series I've ever watched.

New Things I learned

Weekly Thoughts and Updates

  • (📄) My first CVE was published 🎉 https://www.cve.org/CVERecord?id=CVE-2024-44807

    A few notes on this:

    • I didn't think it would be this easy to receive or publish a CVE. The internet is full of products and software, and every little vulnerability in them can be a CVE. It made me think that aside from helping the world of being more secure, unless the CVE is critical, interesting or complicated, the achievement feels slightly less significant to me now.

    • Thumbs up for D-ZERO (the vendor) for being very professional and efficient. Actually I interacted with several entities during this process, and while I'm not sure if this is typical, the Japanese handling process is very efficient. I wonder if it's related to trust. In the past, I contacted companies from different countries around the world and it's not uncommon for them to ignore the message.

  • (📄) Handling the CVE process because of this CVE publication (and because of another one I really wish to publish), made me think about going through various random CVEs. Since they usually have public references (as part of the requirement for CVE publication), I can read, learn from them and gain inspiration for vulnerabilities.

    It also increased my interest in doing code review for open source software and seeing if I find anything.

  • (🐛) A week ago I contacted the vendor of the product I found a high-critical vulnerability in, but still no reply from them, I'll wait another week and contact them again. Meanwhile I'm trying to see if any of the vulnerable companies using this product has VDP or BPP.

  • (🐋) I've finished the Docker course and now I'm preparing for the certification test.

  • (🔨) Got an idea for a tool that identifies the framework/programming language/etc. of web apps using different methods. I put it in my To Do/backlog list, and I will later check this idea..

 
 
 

Comments


Subscribe to my newsletter • Don’t miss out!

  • LinkedIn
bottom of page