Log inSign up
Log inSign up
David Leadbeater
132 posts
David Leadbeater profile banner
@davidgl

David Leadbeater

@davidgl
Open Source Software Engineer 👨‍💻 and Security. Mostly post at 🐘 infosec.exchange/@dgl
🇦🇺
dg.cx/me
Joined April 2008
400 Following
319 Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @davidgl
    David Leadbeater
    @davidgl
    Oct 7, 2025
    You have a bash command line of "exec program ..." and you control "..." can you make it do something different? What if it is somewhat sanitised for shell metacharacters? If you can inject $[+] it will make bash error on that line and run the next. 👀 dgl.cx/2025/10/bash-a…
  • @davidgl
    David Leadbeater
    @davidgl
    Jul 31, 2025
    I'll be speaking at BSides Canberra: cfp.bsidescbr.com.au/bsides-canberr… -- this will cover my recent find of an RCE in Git (dgl.cx/2025/07/git-cl…) and how that and some other vulnerabilities could be used against developers.
    1
  • @davidgl
    David Leadbeater
    @davidgl
    Jan 1, 2025
    New blog post: Ghostty 1.0.0 terminal security; dgl.cx/2024/12/ghostt… (CVE-2024-56803)
  • @davidgl
    David Leadbeater
    @davidgl
    Jul 31, 2023
    For once a non-security terminal thing. I'm sure someone else has written this but I couldn't find it; here's a simple script that makes commit IDs in "git log" clickable (in many terminals): gist.github.com/dgl/ef848e75c0…
  • @davidgl
    David Leadbeater
    @davidgl
    Mar 14, 2023
    Thank you to everyone who attended my @_everythingopen talk, with more of my terminal research. I've published the Docker image PoC that I demoed, see
    infosec.exchange
    David Leadbeater (@[email protected])
    Thank you to everyone who attended my @[email protected] talk. I've published the Docker image that I demoed which can be used to test whether you're vulnerable to the kubectl issue...
Edit with