Diane Bruce is a user on octodon.social. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

since the "new atheme" idiots are busy playing serious business security embargo games, I figured out the vulnerability for the rest of us.

they completely fucked up their mitigation of CVE-2016-4478, making it entirely pointless because THEY DID NOT UNDERSTAND PASCAL STRINGS ARE NOT THE SAME AS C STRINGS (good job guys, maximum security here)

full analysis here:
github.com/atheme/atheme/commi

IF YOU ARE RUNNING ATHEME CLOSE THE XMLRPC EXPOSURE BECAUSE THESE GUYS ARE TRUE MORONS THAT IS ALL

or consider rm'ing your ircd, that also works well.

@Elizafox @kaniini I think I could have been done a hell of a lot better.