"Mutant Rob" Robert Rothenberg
rrwo@infosec.exchange
<p>I was born on the Moon but kidnapped by astronauts and raised in the suburbs of Grumman. Eventually, I drifted along the Gulf Stream to Northern Europe.</p><p><a href="https://infosec.exchange/tags/Perl" class="mention hashtag" rel="tag">#<span>Perl</span></a> <a href="https://infosec.exchange/tags/InfoSec" class="mention hashtag" rel="tag">#<span>InfoSec</span></a></p>
Posts
-
View post
I've uploaded a new version of Plack-App-Prerender to #CPAN This is a #Plack #Perl application for a pre-rendering proxy using Chrome. This version fixes a potentially critical security issue, so if you use it, please upgrade ASAP. https://metacpan.org/release/RRWO/Plack-App-Prerender-v0.3.0
-
View post
Catalyst::View::Wkhtnltopdf new version uploaded to #CPAN with documentation and bug fixes https://metacpan.org/release/RRWO/Catalyst-View-Wkhtmltopdf-v0.6.3 #Perl #Catalyst
-
View post
I've taken over maintenance of Catalyst::View::Wkhtmltopdf, and released a new version with a security fix, among other changes. This is a view that returns a PDF instead from a HTML template. https://metacpan.org/release/RRWO/Catalyst-View-Wkhtmltopdf-v0.6.0 Note that #wkhtmltopdf is no longer maintained. This module will soon be deprecated. #Perl #Catalyst #CPAN
-
View post
Back in April the #Perl NOC turned off the #CPAN mail forwarding. https://log.perl.org/2026/04/cpanorg-email-forwarding-has-been-shut.html If you're like me, you've been using that for 25+ years, and it's everywhere (and unfortunately that includes spammer lists). Here's what you can do in the meantime, via @timlegge@mas.to @cpansec@fosstodon.org https://security.metacpan.org/2026/06/14/cpan.org-email-forwarding-shutdown.html
-
View post
I have a question about potential #Perl search modules to use. Search::Xapian is no longer being actively maintained. Lucy is retired. Are there good replacements?
-
View post
The tech industry habit of asking"Do you consent? Yes or Maybe Later" started in the 1990s with web browsers complaining that they weren't the default app.
-
View post
So Google decides to rebrand and change the app icons again... and I will be confused for a few days because marketing is more important than usability.
-
View post
I received one of my favourite* kind of bug report emails today. The entire message was: "The website doesn't work" Why it's obvious. I'll fix that error right away. Not really but it's Thursday and I want to seem cheerful.
-
View post
I've uploaded a new #Perl module to #CPAN https://metacpan.org/release/RRWO/Dist-Zilla-Plugin-AutomationPolicy-v0.1.1
-
View post
What's worse than an inconsistent API? How about one that doesn't behave as documented? What's worse than that? Getting AI slop response from support that ignores the question and refers to the incorrect documentation. Edit: I suspect the API and the docs have been written by "AI".
-
View post
"575 Pull Requests in Three Weeks: What Happens When #AI Meets #CPAN Maintenance" This is an interesting read, including the comments. https://blogs.perl.org/users/todd_rinaldo/2026/04/575-pull-requests-in-three-weeks-what-happens-when-ai-meets-cpan-maintenance.html #Perl #LLM #Claude
-
View post
"Musk's AI told me people were coming to kill me. I grabbed a hammer and prepared for war" Adam is one of 14 people the BBC has spoken to who have experienced delusions after using AI. They are men and women from their 20s to 50s from six different countries, using a wide range of AI models. https://www.bbc.co.uk/news/articles/c242pzr1zp2o In case you know of someone caught up in LLM mania https://www.thehumanlineproject.org/
-
View post
@lucydev Saying AI democratises art, writing or programming is like saying that a chef democratises cooking, or a maid democratises house cleaning.
-
View post
Are you still using the 2-argument open? (A short post on @cpansec by me.) https://security.metacpan.org/2025/06/06/two-arg-open.html #perl #security #infosec
-
View post
Vulnerabilities in the #Perl JSON::XS, Cpanel::JSON::XS and JSON::SIMD modules via @cpansec If you have applications that handle JSON from untrusted sources (e.g. a web API), then you need to upgrade. CVE-2025-40928: JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact CVE-2025-40929: Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing...
-
View post
The @cpansec CPAN Author's Guide to Random Data for Security has been updated. https://security.metacpan.org/docs/guides/random-data-for-security.html #perl #cpan #security
-
View post
CVE-2025-40925: Starch versions 0.14 and earlier generate session ids insecurely via @cpansec https://lists.security.metacpan.org/cve-announce/msg/32910601/ #perl #cve #security
-
View post
It seems that the residential proxies have shifted to using Dominican IP addresses for the past few days. I guess when they've destroyed the online reputation of one country, they need another to trash. #infosec
-
View post
MetaCPAN @metacpan now displays security advisories when you are viewing a module with advisories. #Perl #CPAN #security #infosec #CVE @cpansec
-
View post
A variation of the "make money by not doing what we promised the customer and hope they give up on calling customer service after several tries" business steategy is the "pretend we never received the payment" strategy. I've wasted two hours fighting with one company about this. "We bill for the previous month. You owe for January." "Yes, I paid you in February." "No, that was the previous month." "No, December was paid. The bill f...
-
View post
#TIL that both My Neighbor Totoro and Grave of the Fireflies were released on the same bill in 1988. The dual billing was considered "one of the most moving and remarkable double bills ever offered to a cinema audience". https://en.wikipedia.org/wiki/My_Neighbor_Totoro#Releaae I'm not sure that I could have watched both films in the same sitting.
-
View post
It's 2026 and the solution to many software issues is still "make backups, erase all of the data and reinstall".
-
View post
I came across a bug report that I filed 20+ years ago for some software... and I don't remember what that software even did. I don't use it anymore.
-
View post
There's nothing like starting service with a new company only to receive an email threatening to cancel service within 48 hours because if a payment problem. Bonus: the billing link is at a different website than the company, so it makes one wonder if it's a very good phishing attempt because your name, email and invoice number might be have been leaked. Extra Bonus: clicking on the link shows an error message that the payment is being processed. Double-Plus-Ungood Bonus: calling cust...