nerdymark's Software Engineering & Cybersecurity Blog

Welcome to my digital homestead - a curated collection of projects, writeups, and experiments in Python, cybersecurity, and creative coding.

Here you'll find CTF writeups covering Azure OAuth privilege escalation, AWS S3 multi-service exploitation, Kubernetes SSRF attack chains, Terraform state poisoning, Go malware reverse engineering, and supply-chain compromises on GitHub Actions runners. You'll also find side projects like the Pokemon Sleep Roster Analyzer, an RDP/VNC network scanner 🔒, a LinkedIn feed analyzer 🔒 powered by Gemini, and word-puzzle solvers for Wordle and Hardle. Plus notes on building this Flask site, migrating to AWS, Bluesky cross-posting, and running a personal AI robot 🔒 out of my garage.

I'm Mark LaCore - Software Engineer by day, Raspberry Pi tinkerer by night. 25 years of turning caffeine into code, 20+ years of playing guitar, and a growing collection of CTF trophies. Explore the posts below, browse the CTF writeups, or drop me a line.

💬 1 comment

Merge upstream v1.9.0 (new sonde types, ka9q updates) keeping nerdscan mods # C...

File: .github/workflows/container.yml
 on:
 jobs:
   build:
     name: Build container image
-    runs-on: ubuntu-latest
+    runs-on: ${{ matrix.runner }}
     strategy:
+      fail-fast: false
       matrix:
-        platform: [linux/amd64, linux/386, linux/arm64, linux/arm/v6, linux/arm/v7]
+        include:
+          - platform: linux/amd64
+            runner: ubuntu-latest
+          - platform: linux/386
+            runner: ubuntu-latest
+          - platform: linux/arm64
+            runner: ubuntu-24.04-arm
+          - platform: linux/arm/v7
+            runner: ubuntu-24.04-arm
     steps:
       - name: Checkout repository
         uses: actions/checkout@v4
 jobs:
           provenance: false
           labels: ${{ steps.meta.outputs.labels }}
           outputs: type=local,dest=/tmp/build-output
-          cache-to: type=local,dest=/tmp/build-cache,mode=max
+          # Local cache shares layers between this pass and the final pass within
+          # the run; registry cache persists them across runs (skipping the
+          # emulated source compiles). Registry export only on non-PR events,
+          # since fork PRs get a read-only token.
+          cache-from: type=registry,ref=ghcr.io/${{ github.repository }}:buildcache-${{ env.PLATFORM }}
+          cache-to: |
+            type=local,dest=/tmp/build-cache,mode=max
+            ${{ github.event_name != 'pull_request' && format('type=registry,ref=ghcr.io/{0}:buildcache-{1},mode=max', github.repository, env.PLATFORM) || '' }}
           target: build
       - name: Final stage and push by digest
 jobs:
           provenance: false
           labels: ${{ steps.meta.outputs.labels }}
           outputs: type=image,name=ghcr.io/${{ github.repository }},push-by-digest=true,name-canonical=true,push=${{ github.event_name != 'pull_request' && 'true' || 'false' }}
-          cache-from: type=local,src=/tmp/build-cache
+          cache-from: |
+            type=local,src=/tmp/build-cache
+            type=registry,ref=ghcr.io/${{ github.repository }}:buildcache-${{ env.PLATFORM }}
       - name: Export digest
         if: ${{ github.event_name != 'pull_request' }}
File: .gitignore
 auto_rx/mXXmod
 auto_rx/mp3h1mod
 auto_rx/mts01mod
 auto_rx/weathex301d
+auto_rx/m10m20mod
+auto_rx/cf06ht03mod
+auto_rx/c50iq
 auto_rx/rd94rd41drop
 m10
 rs_module/rs92mod
 scan/reset_usb
 scan/rs_detect
 weathex/weathex301d
+dropsonde/rd94rd41drop
File: Dockerfile
 RUN git clone https://github.com/miweber67/spyserver_client.git /root/spyserver_
   cd /root/spyserver_client && \
   make
-# Compile ka9q-radio from source
-RUN git clone https://github.com/ka9q/ka9q-radio.git /root/ka9q-radio && \
-  cd /root/ka9q-radio && \
-  git checkout e1224dcd1991637ba8e1caa68cd802e1b22933de && cd src && \
-  make \
-    ARCHOPTS= \
-    tune powers pcmrecord
+# Compile ka9q-radio from source on 64-bit architectures.
+ARG TARGETARCH
+RUN case "$TARGETARCH" in \
+    amd64|arm64) \
+      git clone https://github.com/ka9q/ka9q-radio.git /root/ka9q-radio && \
+      cd /root/ka9q-radio && \
+      git checkout 8f36393f06c303e5e3d61e7550129da55e4816d2 && \
+      cd src && \
+      make ARCHOPTS= tune powers pcmrecord && \
+      install -m 0755 tune powers pcmrecord /root/target/usr/local/bin/ \
+      ;; \
+  esac
 # Copy in radiosonde_auto_rx.
 COPY . /root/radiosonde_auto_rx
 RUN apt-get update && \
   avahi-utils \
   libnss-mdns \
   avahi-utils \
+  libfftw3-dev \
   usbutils && \
   rm -rf /var/lib/apt/lists/*
-# Copy rtl-sdr from the build container.
+# Copy locally compiled utilities from the build container.
 COPY --from=build /root/target /
 RUN ldconfig
 COPY --from=build /root/spyserver_client/ss_client /opt/auto_rx/
 RUN ln -s ss_client /opt/auto_rx/ss_iq && \
   ln -s ss_client /opt/auto_rx/ss_power
-# Copy ka9q-radio utilities
-COPY --from=build /root/ka9q-radio/src/tune /usr/local/bin/
-COPY --from=build /root/ka9q-radio/src/powers /usr/local/bin/
-COPY --from=build /root/ka9q-radio/src/pcmrecord /usr/local/bin/
-
 # Allow mDNS resolution for ka9q-radio utilities
 RUN sed -i -e 's/files dns/files mdns4_minimal [NOTFOUND=return] dns/g' /etc/nsswitch.conf
Read more...
▲