RyotaK's Avatar

RyotaK

@ryotak.net

Security researcher? | Icon: https://twitter.com/MelvilleTw | Keybase: http://keybase.io/ryotak | Threads: http://threads.net/ryotkak | Misskey: http://misskey.io/@ryotak

189
Followers
37
Following
15
Posts
10.07.2023
Joined
Posts Following

Latest posts by RyotaK @ryotak.net

Preview
Clone2Leak: Your Git Credentials Belong To Us Introduction Hello, Iโ€™m RyotaK ( @ryotkak ), a security engineer at GMO Flatt Security Inc. In October 2024, I was hunting bugs for the GitHub Bug Bounty program. After investigating GitHub Enterprise...

I published a blog post about six vulnerabilities in Git/GitHub-related projects. They all result in credential leakage when cloning a malicious repository, so be sure to update the Git installation!

flatt.tech/research/pos...

27.01.2025 10:54 ๐Ÿ‘ 8 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Thank you so much for reading it!

10.12.2024 04:08 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Thank you for reading it ;)

07.12.2024 12:38 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection Introduction Hello, Iโ€™m RyotaK (@ryotkak ), a security engineer at Flatt Security Inc. A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt on my router.1 After ac...

If you're interested in the technical details, I wrote the blog post here: flatt.tech/research/pos...

For the further details, please check out the announcement from the OpenWrt team: lists.openwrt.org/pipermail/op... (2/2)

07.12.2024 09:47 ๐Ÿ‘ 17 ๐Ÿ” 8 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1

[PSA]
If you're using OpenWrt router and have used the Attended sysupgrade, firmware-selector.openwrt[.]org or CLI upgrade previously, I recommend you to re-flash your firmware.

Due to a security issue, it was possible to pollute the firmware images delivered to these tools. (1/2)

07.12.2024 09:47 ๐Ÿ‘ 9 ๐Ÿ” 2 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection Introduction Hello, Iโ€™m RyotaK (@ryotkak ), a security engineer at Flatt Security Inc. A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt on my router.1 After ac...

OpenWrtใฎใƒ“ใƒซใƒ‰็”จใ‚ตใƒผใƒใƒผใซ่„†ๅผฑๆ€งใ‚’ๅ ฑๅ‘Šใ—ใพใ—ใŸใ€‚

Attended sysupgradeใ€firmware-selector.openwrt[.]orgใ‚ใ‚‹ใ„ใฏCLIใ‹ใ‚‰ใฎใ‚ขใƒƒใƒ—ใ‚ฐใƒฌใƒผใƒ‰ใ‚’้ŽๅŽปใซๅฎŸๆ–ฝใ—ใŸๅ ดๅˆใ€ๆ”นใ–ใ‚“ใ•ใ‚ŒใŸใƒ•ใ‚กใƒผใƒ ใ‚ฆใ‚งใ‚ขใŒ้…ไฟกใ•ใ‚ŒใŸๅฏ่ƒฝๆ€งใŒๅฎŒๅ…จใซใฏๅฆๅฎšใงใใชใ„ใŸใ‚ใ€ใƒ•ใ‚กใƒผใƒ ใ‚ฆใ‚งใ‚ขใฎๅ†ๆ›ดๆ–ฐใ‚’ๆŽจๅฅจใ—ใพใ™ใ€‚

ๆŠ€่ก“็š„่งฃ่ชฌใซใคใ„ใฆใฏใ“ใกใ‚‰ใฎ่จ˜ไบ‹ใ‚’ใ”็ขบ่ชใใ ใ•ใ„ใ€‚ flatt.tech/research/pos...

ๅ…ฌๅผใ‹ใ‚‰ใฎ็™บ่กจใฏใ“ใกใ‚‰ใ‚’ใ”่ฆงใใ ใ•ใ„ใ€‚ lists.openwrt.org/pipermail/op...

07.12.2024 09:46 ๐Ÿ‘ 9 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

ใใฎใ†ใกใ‚„ใ‚‹: BlueskyใจTwitterใฎ่‡ชๅ‹•ใƒใ‚นใƒˆ

27.11.2024 12:39 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

ใญใ‚€

13.02.2024 07:11 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
[ใณใ˜ใ‚…ใƒใƒฅใƒผใƒณ๏ผ] ไฝ•ใซใงใ‚‚็‰›ไนณใ‚’ๆณจใๅฅณ | NHK
[ใณใ˜ใ‚…ใƒใƒฅใƒผใƒณ๏ผ] ไฝ•ใซใงใ‚‚็‰›ไนณใ‚’ๆณจใๅฅณ | NHK ใ€Œใณใ˜ใ‚…ใƒใƒฅใƒผใƒณ๏ผใ€ใฏๆ”พ้€ๅพŒ1้€ฑ้–“่ฆ‹้€ƒใ—้…ไฟกใ‚’ใ—ใฆใ„ใพใ™๏ผhttps://www.nhk.jp/p/bijutune/ts/MPPMVRL98N/plus/?cid=dchk-yt-1912-126-st็™บๆƒณใฎๆบใฏใƒ•ใ‚งใƒซใƒกใƒผใƒซใ€Œ็‰›ไนณใ‚’ๆณจใๅฅณใ€ใ€‚็ตตใฎไธญใฎๅฅณใŒๆณจใ„ใงใ„ใ‚‹็‰›ไนณใŒใ€ใ‚„ใ‘ใซ็ดฐใๆใ‹ใ‚Œใฆใ„ใ‚‹ใ€‚ใ“ใ‚Œใฏๆ–™็†ใฎไป•ไธŠ...

www.youtube.com/watch?v=pia0...

13.02.2024 04:57 ๐Ÿ‘ 2 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1

ใญใ“ใฑใฃใฑ

13.02.2024 04:41 ๐Ÿ‘ 2 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Blueskyใ€ใพใ ใƒ•ใ‚งใƒ‡ใƒฌใƒผใ‚ทใƒงใƒณใงใใชใ„ใฎใ‹

13.02.2024 03:03 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Dynamicใชๆณข

13.02.2024 02:29 ๐Ÿ‘ 5 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

UnstableใชTableใฏใ‹ใชใ‚ŠๅซŒใ ใช

13.02.2024 02:32 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

StableใชTable

12.02.2024 13:55 ๐Ÿ‘ 8 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

ใ‚ชใƒคใ‚ธใ‚ฎใƒฃใ‚ฐ็ณปใ‚จใƒณใ‚ธใƒ‹ใ‚ขใงใ‚ใ‚‹ใจใ“ใ‚ใฎ @ryotak.net

12.02.2024 13:28 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

@ryotak.net ใ€Œใ ใ„ใถTwitterใ ใชใใ€
@ryotak.net ใ€Œใ€Žใ ใ„ใถTwitterใ€ใฎใ€Ž๏พ€๏พž๏ฝฒ๏พŒ๏พž๏พ‚ใ€ใฎ้ƒจๅˆ†ใ€

12.02.2024 13:28 ๐Ÿ‘ 1 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

ใ ใ„ใถTwitterใฎๅคงไปใฎ้ƒจๅˆ† by RyotaK

12.02.2024 13:28 ๐Ÿ‘ 1 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

ใ˜ใ‚ƒใ‚ใ‚ใญใฆใ‚ใ•ใ‚“ใฏ้‚ชๆ‚ชใฎๆ‚ชใง

12.02.2024 13:25 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1

็‹ฌ่‡ชใƒ‰ใƒกใ‚คใƒณใƒจใ‚ท๏ผ

12.02.2024 13:20 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1