<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Posts on Dave</title>
    <link>https://0dave.ch/posts/</link>
    <description>Recent content in Posts on Dave</description>
    <image>
      <title>Dave</title>
      <url>https://0dave.ch/static/img/me.webp</url>
      <link>https://0dave.ch/static/img/me.webp</link>
    </image>
    <language>en-us</language>
    <lastBuildDate>Wed, 18 Mar 2026 17:22:10 +0200</lastBuildDate>
    <atom:link href="https://0dave.ch/posts/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Kanboard CVE-2026-33058 Writeup</title>
      <link>https://0dave.ch/posts/cve-2026-33058/</link>
      <pubDate>Wed, 18 Mar 2026 17:22:10 +0200</pubDate>
      <guid>https://0dave.ch/posts/cve-2026-33058/</guid>
      <description>Walkthrough of the discovery of an authenticated SQL injection in Kanboard version &amp;lt;= 1.2.50 tracked as CVE-2026-33058</description>
    </item>
    <item>
      <title>Flying Whales in a Pot of Honey</title>
      <link>https://0dave.ch/posts/flying-whales-in-a-pot-of-honey/</link>
      <pubDate>Wed, 07 Jan 2026 08:40:00 +0200</pubDate>
      <guid>https://0dave.ch/posts/flying-whales-in-a-pot-of-honey/</guid>
      <description>What I&amp;rsquo;ve been up to in the last few weeks</description>
    </item>
    <item>
      <title>CVE-2025-6004 tl;dr</title>
      <link>https://0dave.ch/posts/cve-2025-6004-tldr/</link>
      <pubDate>Sun, 17 Aug 2025 11:23:40 +0200</pubDate>
      <guid>https://0dave.ch/posts/cve-2025-6004-tldr/</guid>
      <description>A tl;dr about account lockout bypass (CVE-2025-6004) in Hashicorp Vault</description>
    </item>
    <item>
      <title>Go Report [a vulnerability] Card</title>
      <link>https://0dave.ch/posts/goreportcard/</link>
      <pubDate>Sat, 07 Dec 2024 15:48:00 +0200</pubDate>
      <guid>https://0dave.ch/posts/goreportcard/</guid>
      <description>While publishing oauth-labs I stumbled upon a vulnerability in goreportcard</description>
    </item>
    <item>
      <title>ghmlwr: Malware on GitHub (retired)</title>
      <link>https://0dave.ch/posts/ghmlwr/</link>
      <pubDate>Sun, 01 Sep 2024 10:21:43 +0200</pubDate>
      <guid>https://0dave.ch/posts/ghmlwr/</guid>
      <description>New pet project ghmlwr</description>
    </item>
    <item>
      <title>Atlassian Research and Work</title>
      <link>https://0dave.ch/posts/atlassian-the-outtakes/</link>
      <pubDate>Wed, 28 Aug 2024 20:00:00 +0200</pubDate>
      <guid>https://0dave.ch/posts/atlassian-the-outtakes/</guid>
      <description>Atlassian Research and a short status update</description>
    </item>
    <item>
      <title>RFC5322, your XSS companion</title>
      <link>https://0dave.ch/posts/rfc5322-fun/</link>
      <pubDate>Mon, 01 Apr 2024 14:19:48 +0200</pubDate>
      <guid>https://0dave.ch/posts/rfc5322-fun/</guid>
      <description>Why RFC5322 email validation might lead to XSS vulnerabilities</description>
    </item>
    <item>
      <title>Parcel Tracking, I can haz PII plz?</title>
      <link>https://0dave.ch/posts/parcel-advice/</link>
      <pubDate>Fri, 08 Mar 2024 19:34:53 +0100</pubDate>
      <guid>https://0dave.ch/posts/parcel-advice/</guid>
      <description>This is a short one about a not-so-fun parcel tracking service that I came across after completing the check-out of my cat food order for my furry overlords</description>
    </item>
    <item>
      <title>Uncooperative Businesses</title>
      <link>https://0dave.ch/posts/uncooperative-businesses/</link>
      <pubDate>Thu, 15 Feb 2024 18:34:55 +0100</pubDate>
      <guid>https://0dave.ch/posts/uncooperative-businesses/</guid>
      <description>A short personal opinon piece about uncooperative businesses.</description>
    </item>
    <item>
      <title>AirTies Air4930 - Feature...?</title>
      <link>https://0dave.ch/posts/air4930/</link>
      <pubDate>Sat, 10 Feb 2024 13:55:51 +0100</pubDate>
      <guid>https://0dave.ch/posts/air4930/</guid>
      <description>A not-so-fun little feature of AirTies Air 4930.</description>
    </item>
    <item>
      <title>CVE-2023-31505 tl;dr</title>
      <link>https://0dave.ch/posts/cve-2023-31505-tldr/</link>
      <pubDate>Mon, 05 Feb 2024 20:45:13 +0100</pubDate>
      <guid>https://0dave.ch/posts/cve-2023-31505-tldr/</guid>
      <description>A tl;dr about an authenticated remote code execution (CVE-2023-31505) in Schlix CMS</description>
    </item>
  </channel>
</rss>

