Skip to content
  • Home Home Home, current page.
  • Moments Moments Moments, current page.

Saved searches

  • Remove
  • In this conversation
    Verified accountProtected Tweets @
Suggested users
  • Verified accountProtected Tweets @
  • Verified accountProtected Tweets @
  • Language: English
    • Bahasa Indonesia
    • Bahasa Melayu
    • Català
    • Čeština
    • Dansk
    • Deutsch
    • English UK
    • Español
    • Filipino
    • Français
    • Hrvatski
    • Italiano
    • Magyar
    • Nederlands
    • Norsk
    • Polski
    • Português
    • Română
    • Slovenčina
    • Suomi
    • Svenska
    • Tiếng Việt
    • Türkçe
    • Ελληνικά
    • Български език
    • Русский
    • Српски
    • Українська мова
    • עִבְרִית
    • العربية
    • فارسی
    • मराठी
    • हिन्दी
    • বাংলা
    • ગુજરાતી
    • தமிழ்
    • ಕನ್ನಡ
    • ภาษาไทย
    • 한국어
    • 日本語
    • 简体中文
    • 繁體中文
  • Have an account? Log in
    Have an account?
    · Forgot password?

    New to Twitter?
    Sign up
Foone's profile
foone
foone
foone
@Foone

Tweets

foone

@Foone

Hardware / software necromancer, collector of Weird Stuff, maker of Death Generators. (they/them) Patreon: http://patreon.com/foone  ko-fi: http://ko-fi.com/fooneturing 

San Leandro, CA
floppy.foone.org
Joined February 2008

Tweets

  • © 2021 Twitter
  • About
  • Help Center
  • Terms
  • Privacy policy
  • Cookies
  • Ads info
Dismiss
Previous
Next

Go to a person's profile

Saved searches

  • Remove
  • In this conversation
    Verified accountProtected Tweets @
Suggested users
  • Verified accountProtected Tweets @
  • Verified accountProtected Tweets @

Promote this Tweet

Block

  • Tweet with a location

    You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more

    Your lists

    Create a new list


    Under 100 characters, optional

    Privacy

    Copy link to Tweet

    Embed this Tweet

    Embed this Video

    Add this Tweet to your website by copying the code below. Learn more

    Add this video to your website by copying the code below. Learn more

    Hmm, there was a problem reaching the server.

    By embedding Twitter content in your website or app, you are agreeing to the Twitter Developer Agreement and Developer Policy.

    Preview

    Why you're seeing this ad

    Log in to Twitter

    · Forgot password?
    Don't have an account? Sign up »

    Sign up for Twitter

    Not on Twitter? Sign up, tune into the things you care about, and get updates as they happen.

    Sign up
    Have an account? Log in »

    Two-way (sending and receiving) short codes:

    Country Code For customers of
    United States 40404 (any)
    Canada 21212 (any)
    United Kingdom 86444 Vodafone, Orange, 3, O2
    Brazil 40404 Nextel, TIM
    Haiti 40404 Digicel, Voila
    Ireland 51210 Vodafone, O2
    India 53000 Bharti Airtel, Videocon, Reliance
    Indonesia 89887 AXIS, 3, Telkomsel, Indosat, XL Axiata
    Italy 4880804 Wind
    3424486444 Vodafone
    » See SMS short codes for other countries

    Confirmation

     

    Welcome home!

    This timeline is where you’ll spend most of your time, getting instant updates about what matters to you.

    Tweets not working for you?

    Hover over the profile pic and click the Following button to unfollow any account.

    Say a lot with a little

    When you see a Tweet you love, tap the heart — it lets the person who wrote it know you shared the love.

    Spread the word

    The fastest way to share someone else’s Tweet with your followers is with a Retweet. Tap the icon to send it instantly.

    Join the conversation

    Add your thoughts about any Tweet with a Reply. Find a topic you’re passionate about, and jump right in.

    Learn the latest

    Get instant insight into what people are talking about now.

    Get more of what you love

    Follow more accounts to get instant updates about topics you care about.

    Find what's happening

    See the latest conversations about any topic instantly.

    Never miss a Moment

    Catch up instantly on the best stories happening as they unfold.

    foone‏ @Foone 30 Jan 2020

    ahaha. CVE-2020-2100 came out today for Jenkins and a UDP amplification reflection attack, but it's actually far funnier: You can cause an infinite loop of bandwidth on any network with two Jenkins servers.

    5:59 PM - 30 Jan 2020
    • 138 Retweets
    • 344 Likes
    • Stanislav Pogrebnyak Глитчпанк и постапокалиптика Wifi Freak Benjamin Auger rail zamaletdinov rymkus Sam Mortenson Tiernan Stephane
    7 replies 138 retweets 344 likes
      1. New conversation
      2. foone‏ @Foone 30 Jan 2020

        foone Retweeted foone

        So Jenkins has a weird feature I've talked about before: You send a UDP packet to a broadcast address, and any jenkins servers will reply with some XML explaining where they are.https://twitter.com/Foone/status/1120763848313622530 …

        foone added,

        foone @Foone
        My favorite "wait, why, exactly?" Jenkins feature: Have you lost your local CI server? Just send a UDP packet to broadcast port 33848, and all local Jenkins servers will report back. $ echo 'ping' | socat -t5 - UDP-DATAGRAM:255.255.255.255:33848,broadcast pic.twitter.com/WCiSTisJST
        1 reply 10 retweets 70 likes
        Show this thread
      3. foone‏ @Foone 30 Jan 2020

        but the important thing is that they'll respond to ANY udp packet aimed at that port, with another UDP packet to that port, right?

        1 reply 3 retweets 48 likes
        Show this thread
      4. foone‏ @Foone 30 Jan 2020

        which means the message that triggers it can look like the message they send... Do you see where this is going?

        1 reply 0 retweets 44 likes
        Show this thread
      5. foone‏ @Foone 30 Jan 2020

        UDP is connectionless, so all you have to do is find the two jenkins IPs (which is easy, because of this broadcast thing), then spoof a packet as coming from one to the other.

        2 replies 2 retweets 43 likes
        Show this thread
      6. foone‏ @Foone 30 Jan 2020

        so you pretend to be Jenkins A and say "ANY JENKINS OUT THERE?" at B. B goes "HI! I am a Jenkins" and replies to A. A goes "Hi! I am a Jenkins" and replies to B. B goes "HI! I am a Jenkins" and replies to A. A goes "Hi! I am a Jenkins" and replies to B. B goes "HI! I am a Jenk

        3 replies 3 retweets 68 likes
        Show this thread
      7. foone‏ @Foone 30 Jan 2020

        congrats, you now have two servers which will forever spam traffic at each other until you restart them or your network falls over

        1 reply 4 retweets 64 likes
        Show this thread
      8. foone‏ @Foone 30 Jan 2020

        one of my previous employers had something like 20 jenkins servers when I left and they were working on ways to easily set up more.

        3 replies 1 retweet 50 likes
        Show this thread
      9. foone‏ @Foone 30 Jan 2020

        imagine it. 20 nodes, each spamming 19 others, and being spammed by 19 others.pic.twitter.com/SKFKrxBATt

        6 replies 3 retweets 65 likes
        Show this thread
      10. foone‏ @Foone 30 Jan 2020

        (graph from https://bl.ocks.org/bryik/a3d0d7a0d9d69e6afe0fd8b8b3becec1 …)

        1 reply 1 retweet 29 likes
        Show this thread
      11. End of conversation
      1. Reed Mideke‏ @reedmideke 30 Jan 2020
        Replying to @Foone

        pic.twitter.com/A7uLkZAUK6

        0 replies 1 retweet 49 likes
        Thanks. Twitter will use this to make your timeline better. Undo
        Undo

    Loading seems to be taking a while.

    Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

      Promoted Tweet

      false

      • © 2021 Twitter
      • About
      • Help Center
      • Terms
      • Privacy policy
      • Cookies
      • Ads info