Lemmy.ca
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Treasure@feddit.org to Cybersecurity@sh.itjust.worksEnglish ·
edit-2
8 months ago

Unauthenticated RCE vs all GNU/Linux systems to be fully disclosed in 2 weeks with no working fix yet

nitter.poast.org

external-link
message-square
19
link
fedilink
  • cross-posted to:
  • [email protected]
  • [email protected]
39
external-link

Unauthenticated RCE vs all GNU/Linux systems to be fully disclosed in 2 weeks with no working fix yet

nitter.poast.org

Treasure@feddit.org to Cybersecurity@sh.itjust.worksEnglish ·
edit-2
8 months ago
message-square
19
link
fedilink
  • cross-posted to:
  • [email protected]
  • [email protected]
Verifying your browser | Nitter
nitter.poast.org
external-link

EDIT: Original post seems to have been removed, try this Nitter mirror instead.

alert-triangle
You must log in or register to comment.
  • kbal@fedia.io
    link
    fedilink
    arrow-up
    15
    arrow-down
    1
    ·
    8 months ago

    Okay, who’s giving odds on this one coming anywhere close to living up to its billing?

    • CameronDev@programming.dev
      link
      fedilink
      English
      arrow-up
      9
      ·
      8 months ago

      The claims are well into the “I found a unicorn” territory, I’m tipping its either “If you misconfigure this, its unsafe”, or its a real vuln, and its significantly harder to exploit that they are claiming.

    • CameronDev@programming.dev
      link
      fedilink
      English
      arrow-up
      2
      ·
      7 months ago

      https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/

      Definitely interesting

  • bigkahuna1986@lemmy.ml
    link
    fedilink
    English
    arrow-up
    10
    ·
    8 months ago

    Unauthenticed RCE vs all GNU/Linux systems

    So this would probably be SSH related right? Otherwise what would all Linux systems have in common?

    • m-p{3}A
      link
      fedilink
      English
      arrow-up
      16
      arrow-down
      1
      ·
      8 months ago

      My bet is on Systemd.

      • thesmokingman@programming.dev
        link
        fedilink
        English
        arrow-up
        5
        ·
        8 months ago

        That’s not all GNU/Linux though. Either the OP doesn’t understand a very common container OS, Alpine, doesn’t use systemd (also Void Linux and others outside the container space) or it’s something else.

      • Luci
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        1
        ·
        8 months ago

        Oh that would be baaaad

        • BoofStroke@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          4
          ·
          8 months ago

          And unsurprising

          • burgersc12@mander.xyz
            link
            fedilink
            English
            arrow-up
            4
            ·
            8 months ago

            How would this be unsurprising? Is systemd known for this kind of thing or something?

            • m-p{3}A
              link
              fedilink
              English
              arrow-up
              5
              ·
              8 months ago

              https://pwnies.com/systemd-bugs/

    • CameronDev@programming.dev
      link
      fedilink
      English
      arrow-up
      5
      ·
      8 months ago

      Not all Linux’s have SSH enabled, especially out of the box.

      They have some other posts about IPv6 parsing (also not universal), but that doesnt sound like an “easy” RCE.

    • schizo@forum.uncomfortable.business
      link
      fedilink
      English
      arrow-up
      4
      ·
      8 months ago

      If it were SSH though, wouldn’t that ALSO include a wider blast radius than just Linux systems?

      Like OpenSSH is used all over the damn place, unless I guess there’s something specific about the issue that limits it to Linux hosts for some reason?

      • SpaceMan9000@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        8 months ago

        He claims the blast radius is bigger, not just Linux. He also claims to be in talks with Apple. So the educated guess would still be openssh

  • superkret@feddit.org
    link
    fedilink
    English
    arrow-up
    8
    ·
    edit-2
    8 months ago

    It supposedly affects all GNU/Linux systems, there’s no fix, existed for 10 years, severity of 9.9, but there’s an “easy workaround”.
    I’m curious.

    • Nougat@fedia.io
      link
      fedilink
      arrow-up
      11
      ·
      8 months ago

      easy workaround

      Turn the power off?

      • Bakkoda@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 months ago

        Rj45 to 110v adapter is more funnerer.

    • Treasure@feddit.orgOP
      link
      fedilink
      English
      arrow-up
      8
      ·
      8 months ago

      Me too, I’m looking forward to the writeup.

      • CameronDev@programming.dev
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 months ago

        https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/

  • englislanguage@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    2
    ·
    8 months ago

    If this is true (or at least plausible to the relevant people), the author of that Twitter post will probably be on the radar of any shady government agency worldwide. Not a nice situation to be in.

Cybersecurity@sh.itjust.works

cybersecurity@sh.itjust.works

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

  • Be respectful. Everyone should feel welcome here.
  • No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
  • No Ads / Spamming.
  • No pornography.

Community Rules

  • Idk, keep it semi-professional?
  • Nothing illegal. We’re all ethical here.
  • Rules will be added/redefined as necessary.

If you ask someone to hack your “friends” socials you’re just going to get banned so don’t do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 146 users / day
  • 556 users / week
  • 1.5K users / month
  • 4.76K users / 6 months
  • 146 local subscribers
  • 7.16K subscribers
  • 2.72K Posts
  • 5.22K Comments
  • Modlog
  • mods:
  • Kid@sh.itjust.works
  • Lanky_Pomegranate530@midwest.social
  • BE: 0.19.11
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org