frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies and WSDL

https://labs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/
12•campuscodi•1d ago

Comments

eek2121•1d ago
Well, that was a wild read. I'm surprised it isn't getting more traction.

So, full disclosure, I'm no longer a developer due to disabilities, including one that keep me from being able to write code, however: I love C# and .NET, and a good portion of my early career was working with C#, .NET, and SOAP. That being said, Microsoft's response to this bug alone have turned me off to the language and framework. They clearly don't take security seriously. They favor possible compatibility issues over the hijacking of a bunch of servers on the internet. That attitude is not okay. I bet a simple code scan could probably find a whole bunch of endpoints that are vulnerable to this.

I would not be surprised if some of their own web applications are affected by this vulnerability.

Thanks for the read.

butvacuum•1d ago
Note- 1) this is .Net Framework- which is in a holding pattern. 2) this requires inherently insecure code to be written- 3) I can't find it right now- but I seem to recall there being an option when defining the service in a web.config to write to a file instead of a http endpoint- ostensibly for development purposes.

These don't completely negate a WONTFIX response though- after all, .Net Framework 4.?? Disabled XML External Entities and schema loading by default.

PostgreSQL AI Query Extension

https://benodiwal.github.io/pg_ai_query/
1•sbuttgereit•2m ago•0 comments

Ask HN: What sensors do you have around the house?

1•gessha•5m ago•0 comments

Clean energy found in old coal mines

https://techxplore.com/news/2025-11-energy-coal.html
1•PaulHoule•5m ago•0 comments

Show HN: Built an AI Song Creator with stem separation and commercial rights

https://aisongcreator.app
1•alexwang123•6m ago•0 comments

A Giant Ball Will Help This Man Survive a Year on an Iceberg

https://www.outsideonline.com/outdoor-adventure/exploration-survival/how-giant-ball-will-help-man...
1•areoform•6m ago•0 comments

Tell HN: The Python Software Foundation is now showing banner ads

1•inesranzo•7m ago•0 comments

MFA for students with limited technology?

https://old.reddit.com/r/msp/comments/1je8vez/mfa_for_students_with_limited_technology/
1•sipofwater•8m ago•1 comments

Spare Thoughts on App Design

https://www.kitlangton.com/posts/spare-thoughts-on-app-design
1•4dm1r4lg3n3r4l•8m ago•0 comments

Show HN: I audited 500 K8s pods. Java wastes ~48% RAM, Go ~18%

https://github.com/WozzHQ/wozz
1•wozzio•8m ago•1 comments

AI as a WordPress Fundamental

https://make.wordpress.org/core/2025/12/04/ai-as-a-wordpress-fundamental/
1•pavel_lishin•10m ago•1 comments

Columbia University Faculty Behaving Badly

https://reason.com/volokh/2025/12/11/columbia-university-faculty-behaving-badly/
2•leephillips•15m ago•0 comments

What Happens When You Crash a Bicycle at 175mph [video]

https://www.youtube.com/watch?v=x6qzMagQSjM
1•celias•17m ago•1 comments

Research Veteran Yardeni Ends 15-Year Tech Bet with Underweight Mag 7 Call

https://www.bloomberg.com/news/articles/2025-12-08/yardeni-says-underweight-mag-7-in-shift-from-t...
1•xqcgrek2•17m ago•0 comments

Show HN: High-Performance Order Matching Engine in C++20 (2.2M ops/SEC)

https://github.com/PIYUSH-KUMAR1809/order-matching-engine
1•kpiyush8826•18m ago•0 comments

Operation Bluebird wants to relaunch "Twitter," says Musk abandoned the brand

https://arstechnica.com/information-technology/2025/12/can-twitter-fly-again-startup-wants-to-pry...
2•jaredwiener•19m ago•1 comments

The Wild West of post-POSIX IO Interfaces [video]

https://www.youtube.com/watch?v=abDWZ9D8kEE
1•matt_d•19m ago•0 comments

Six New Tips for Better Coding with Agents

https://steve-yegge.medium.com/six-new-tips-for-better-coding-with-agents-d4e9c86e42a9
1•gmays•23m ago•0 comments

Z8086: Rebuilding the 8086 from Original Microcode

https://nand2mario.github.io/posts/2025/z8086/
1•nand2mario•27m ago•0 comments

Listen to Mixtapes from Before

https://intertapes.net/
1•poniko•31m ago•0 comments

My First Impressions of MeshCore Off-Grid Messaging

https://mtlynch.io/first-impressions-of-meshcore/
1•mtlynch•33m ago•0 comments

I built a tool to restore old family photos without ruining them with AI

https://forevi.ai
1•poznerd•33m ago•1 comments

Designing Electronics That Works

https://nostarch.com/designingelectronics
2•0x54MUR41•33m ago•0 comments

Most LLM cost isn't compute – it's identity drift (110-cycle GPT-4o benchmark)

https://github.com/sigmastratum/documentation/blob/main/sigma-runtime/SR-EI-03/benchmark_report_S...
1•teugent•34m ago•1 comments

Show HN: PlanEat AI, an AI iOS app for weekly meal plans and smart grocery lists

1•franklinm1715•34m ago•0 comments

A Post-Incident Control Test for External AI Representation

https://zenodo.org/records/17921051
1•businessmate•35m ago•1 comments

اdifference gbps overview find answers

1•shahrtjany•36m ago•0 comments

Measuring Impact of Early-2025 AI on Experienced Open-Source Dev Productivity

https://arxiv.org/abs/2507.09089
1•vismit2000•37m ago•0 comments

Show HN: Lazy Demos

http://demoscope.app/lazy
1•admtal•39m ago•0 comments

AI-Driven Facial Recognition Leads to Innocent Man's Arrest (Bodycam Footage) [video]

https://www.youtube.com/watch?v=B9M4F_U1eEw
3•niczem•39m ago•1 comments

Annual Production of 1/72 (22mm) scale plastic soldiers, 1958-2025

https://plasticsoldierreview.com/ShowFeature.aspx?id=27
2•YeGoblynQueenne•40m ago•0 comments