2026-03-16 15:42:04
from my link log —
One hundred curl graphs.
https://daniel.haxx.se/blog/2026/03/15/one-hundred-curl-graphs/
saved 2026-03-15 https://
from my link log —
One hundred curl graphs.
https://daniel.haxx.se/blog/2026/03/15/one-hundred-curl-graphs/
saved 2026-03-15 https://
RE: https://mastodon.social/@cheeaun/116052332060770274
Now that the poll is done, thinking if something like this make sense?
Ok, so I have this HP-server in my garage that I've had for years.
I decided to plug it in, add drives and connect the iLO port.
Ofcourse, I have forgotten the iLO password - and I dont have a monitor that I can use to reset it via the BIOS.
I do remember this vulnerability from a couple of years ago, that where I could get the password (or change it) for the Administrator user with a curl post request.
But I can't find it.
Help
Me: I'm having a problem with your website. Here's full debugging information from developer tools in three browsers, a curl request showing all headers and content, and the URLs and error text.
Them: Can you send us a screenshot?
“Time and energy that is completely wasted while also hampering our will to live.”
I can relate.
https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/
curl https://somerandomdevelopertool | sudo bash
ayfkm
How did we get here
Overrun with AI slop, cURL scraps bug bounties to ensure "intact mental health"
The onslaught includes LLMs finding bogus vulnerabilities and code that won’t compile. The project developer for one of the Internet’s most popular networking tools is scrapping its vulnerability reward program after being overrun by a spike in the submission of low-quality reports, much of it AI-generated slop.
🤖
The curl project plans to end its HackerOne bug bounty program at the end of January, citing a surge in low-quality AI-generated vulnerability reports (Lawrence Abrams/BleepingComputer)
https://www.bleepingcomputer.com/news/securi…
It is 2025 and projects want me to curl an url to install. #dontcurlthaturl
curl 3.11 for Workgroups
Don't miss today's packed Metacurity for the most critical infosec developments you need to know, including
--DOGE workers shared SSN data with outsiders, derailed DISA operations,
--UK launches national fraud reporting service,
--China blames Taiwan for cyberattacks,
--EU proposes freezing out Chinese tech suppliers,
--New Zealand launches Manage My Health breach probe,
--Curl ends its bug bounty program due to AI flood,
--Cloudflare fixes WAF…
"A package’s value isn’t primarily its implementation code. Anyone can rewrite curl in Rust in a weekend, as Daniel Stenberg has heard many times. What they can’t rewrite is the twenty years of bug reports, the weird edge cases someone hit in production and took the time to fix, the arguments in issue threads that eventually settled on the right behavior. That knowledge is spread across the package’s history and it grew organically. No prompt captures it."
https://nesbitt.io/2026/01/30/will-ai-make-package-managers-redundant.html
Excellent piece by @…
Two cats (Clove & Erie) were sleeping next to me in bed. Twig, who is the youngest cat of the group, hops on the bed and wakes them both up by BITING THEIR FACES, one at a time. Then he's like "let's cuddle!", tries to curl up next to them, and they both hiss/swat at him.
Now he's downstairs, meowing/crying loudly. What a doofus!
#CatDrama
Don’t trust, verify
#supplyChainAttack
I'm going to put on a Hawaiian shirt, curl into a fetal position, and play "Walking on Sunshine" on a continuous loop until I believe it's warmer than it actually is. It's gotta work.
Another day of dealing with the headache caused by Unixy text processing tools, close to writing a custom one for my purpose instead of chaining up a pipeline of... 4? 5?
curl, csplit, head, sed... aaaah...
Wrapping it all in a Makefile turned out to be hard yet again, so part of it is delegated to a shell script.
Idea: a moltbot that agentically finds shell scripts online and `curl | bash`es them as root to see what they do
I wonder if there is a list of websites that support
curl -H "Accept: text/markdown" aka serving markdown directly.
then there could actually be a "browser" on remarkable tablets.
I also still wonder how firefox does the "read mode"
RE: https://mastodon.gamedev.place/@Erikmitk/116130738430887169
I shouldn’t have used the word cookies there. People keep replying with curl related jokes about cookies and it’s super annoying. I just had a genuine real world question! 😵💫
Ok, das hatte ich auch noch nicht:
Mein Mailprogramm konnte plötzlich nicht mehr zu em bestimmten Mailkonto¹ verbinden. Kommt vor. Ich betreib den Server selbst, mach mich also an's Debuggen, seh aber nichts in den Logs.² Ich schau in die Fehlerkonsole, probier curl³, telnet, … keine Ausgaben, einfach keine Verbindung.
Im lokalen Subnetz des Servers geht IMAP, auch per Proxy, nur von mir zu Hause nicht. Also bau ich ein VPN, und hoppla, curl über IPv6 geht, über IPv4 nicht…<…
Cowboys Tabbed ‘Best’ Fit for Projected $40 Million Star https://heavy.com/sports/nfl/dallas-cowboys/tabbed-best-fit-projected-40-million-star/
Ich richte mir einen "Burner-Rechner" ein, auf dem claude code dann seine lean scripte ausführen darf.
Vanilla Ubuntu hat ca. 5 (?) Paketmanager drauf, oder? (apt, snap, ...?) Keiner davon enthält tailscale (in einer Version ohne bekannte Sicherheitslücken), astral-uv, claude code, ...
Mir scheint, der plattformübergreifende Paketmanager these days ist:
"curl [..]install.sh | sh"![]()