[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / r / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip / qa] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: 1724619387806328.jpg (96 KB, 1029x728)
96 KB
96 KB JPG
>* Unauthenticated RCE vs all GNU/Linux systems (plus others) disclosed 3 weeks ago.
>* Full disclosure happening in less than 2 weeks (as agreed with devs).
>* Still no CVE assigned (there should be at least 3, possibly 4, ideally 6).
>* Still no working fix.
>* Canonical, RedHat and others have confirmed the severity, a 9.9, check screenshot.
>* Devs are still arguing about whether or not some of the issues have a security impact.
https://x.com/evilsocket/status/1838169889330135132
Not a shitpost, unauthenticated RCE affecting to all Linux distros announced today and will be made public soon
>>
File: 1718710097947581.jpg (46 KB, 312x1039)
46 KB
46 KB JPG
>>
>>102523339
what does unauthenticated mean in this context, that it hasn't been reproduced?
>>
>>102523392
As in, an attacker does not need to be logged in to the system
>>
File: GYKJ6edW8AAOlsy.png (6 KB, 529x71)
6 KB
6 KB PNG
>>102523339
Oh god, I'm getting Rust vibes incoming.
>>
>>102523339
>No information about what it actually is
cool story bro
>>
network stack exploit or what?
>>
>>102523339
Oh no, another NSA backdoor about to be nailed shut.
>>
>2 weeks
>>
>>102523512
https://www.evilsocket.net/
https://github.com/evilsocket

probably
>>
>>102523339
>Discovered 3 weeks ago
>Full disclosure in less than 2 weeks
>No working fix
>Checks pretty much all the boxes of extreme vuln
Something doesn't add up here, frens
>>
>>102523476
Accurate.
>>
>>102523582
>Legba
>>
>>102523628
He lives on the cuckslope, correct.
>>
>Kernel vuln
>RCE
>LHL CIA impact
Whoever scored this is a 9.9 on the retard scale.
>>
>>102523339
>twitter link
at least archive that shit, not everyone has an x account
>>
Can any cyber security fags give a QRD on what this means? Is it a backdoor?
>>
File: 1714553876456166.jpg (291 KB, 1000x1000)
291 KB
291 KB JPG
>>102524444
https://nitter.poast.org/evilsocket/status/1838169889330135132
literally only because you got quads
>>
>>102524444
just create a burner with disposable email
>>
>>102524461
Ask the faggot vendors who are sitting on this
>>
>>102523582
based
>>
>>102524487
thanks, added to url rewriter.
>inb4 it's a vulnerability in token ring, infiniband or some other niche networking stack that wouldn't
be directly open to the Internet anyway
>>
>>102523339
with troons you get voolns
>>
>>102523339
> Devs are still arguing about whether or not some of the issues have a security impact.
nothingburger incoming
>>
bets on whether Asterinas will be affected?
>>
>>102523582
It's in the name. Rust eats holes through iron.
>>
File: 1704185082750036.png (228 KB, 583x210)
228 KB
228 KB PNG
>>102524869
>Asterinas
>>
If it was real he would have already sold it for a million bucks on zerodium
>>
Is it too soon to say
>2 more weeks
?
>>
>>102524948
>Full disclosure happening in less than 2 weeks (as agreed with devs).
>>102524905
only windows has a $1m rce on there actually
>>
>>102523582
Omg please let it be... LOL... I will get so much entertainment from Linux systems being absolute security messes due to Rust. I have been arguing vehemently for a very long time that "safe!" Rust is one of the most insecure and dangerous languages to ever exist.
>>
>>102525027
There's no way you're this retarded.
>>
>>102523339
Surely this isn't some nobody exaggerating for clout right guys
>>
>>102525088
I hate people that doesn't know how to dialogue, then start shouting things like otherwise they wouldn't listen (like they are forced to)
>>
>>102524759
now that i read it a bit more carefully, he mentions GNU/Linux systems are affected (plus others, linked vendors in second image include Apple and FreeBSD) and not the kernel itself. Also "Attack Vector: Network" can mean anything on the network stack.
So it's most likely some userspace daemon for some niche application layer TCP/IP based protocol, similar to blastRADIUS for example
>>
>>102524495
I can't. It required me to solve 50 captchas in a row (literally, with 1/50 progress status). I did that and it said I failed one without telling me which one and asked me to do all of it again. Humiliation ritual.
>>
>>102525123
I love nothingburgers, shows to people how only dumb stuff needs to be hyped
If it were something real it would happen suddenly like the crowdstrike issue

It's also funny how every non-linux issue is blamed on the linux kernel out of jealously, reminds me of that systemd efi fiasco that hardbricked computers which was also blamed on the kernel
>>
>>102525184
>systemd efi fiasco that hardbricked computers
I don't remember the kernel being blamed. I do remember systemd was blamed by retards.
>>
>>102523339
Just 2 more weeks
>>
>>102525088
All securityfags are like this. Anything to get their name and twitter handle in the press so they can leverage it into a corporate sinecure.
>>
>>102523339
Let us know when there are actual details.
>>
I'm betting some random userspace program open every port on UPnP by default, and somehow it's Linux's fault for allowing programs to open ports.
Remember when the NT Kernel had an IPv6 RCE that couldn't be blocked by a firewall? Funny how quickly the news stopped reporting it.
Screenshot this: in 2 months after the (likely nothingburger) issue has already been long solved there will still be a thread on page 1.
>>
>>102525330
>IPv6 RCE that couldn't be blocked by a firewall
literally only one guy here thought that and he kept spamming it despite all the evidence against it
>>
>>102525088
Basically /this - OP is probably the twittertard and has posted here (among a few other places) to try to get traction for >>102525249

>>102525244
Too slow bro >>102524948
>>
>>102525330
>there will still be a thread on page 1
All threads are on page 1 at least once.
>>
File: il_600x600.310634688.jpg (89 KB, 600x600)
89 KB
89 KB JPG
>>102523628
You called nigga?
>>
Hi Simone!
>>
>>102525352
>"Considering its harm, I will not disclose more details in the short term," the security researcher tweeted, adding that blocking IPv6 on the local Windows firewall won't block exploits because the vulnerability is triggered prior to it being processed by the firewall.
https://www.bleepingcomputer.com/news/microsoft/zero-click-windows-tcp-ip-rce-impacts-all-systems-with-ipv6-enabled-patch-now/
>>
File: 1706359542013237.jpg (131 KB, 1092x720)
131 KB
131 KB JPG
>>102523476
>>102523582
>>102525027
Literally his first comment after is that it's been present for more than a decade
>>102525355
I only posted this here because Ulf Frisk https://github.com/ufrisk (dude who actually knows his shit) reposted it
>>
>>102525088
Wow just like all sufficiently complicated software
>>
>>102525088
the issue is apparently affecting multiple OSes, yet his bitching about supposed endless mess of security holes mentioning exclusively in a Linux system "is going to be the writeup opening statement"? What a fucking retard.
>>102525330
>I'm betting some random userspace program open every port on UPnP by default, and somehow it's Linux's fault for allowing programs to open ports.
true, default credentials on userspace programs get CVEs too (see qBittorrent)
>>
>>102523339
For fucks' sake, I just installed Linux on a new computer. I'm not sure if the proprietary shitware I need can be run on FreeBSD.
>>
>>102525415
>FreeBSD
see
>>102523365
>>
>>102525415
>FreeBSD
anon... look at >>102523365
>Unauthenticated RCE vs all GNU/Linux systems (plus others)
>(plus others)
>>
>>102525440
>>102525442
FUUUUUUUCK! D:<
>>
>>102525415
Airgapped OpenBSD time saaar
>>
>>102525389
No proofs though
Two more weeks
>>
>Availability (A) = Low (L)
Meaning?
They give all kinds of shit a 10/10 even if the only way it can hit you is if you let code run on your machine, so let's wait before reacting
>>
>>102525478
OpenBSD is nice but I don't want to go back to integrated graphics.
>>
>>102525123
Yeah, the fact that this affects BSD as well as Linux is… suspicious, to say the least. It can’t be incredibly low-level if it affects all of them, right? Or is it part of Unix itself?
>>
>>102525389
Collecting the names of "security experts" from twitter and github doesn't give this any more credence.

Nice shout out tho Simone!
>>
>>102523339
>Not a shitpost
>twitter nobody with no proof
kill yourself, thanks.
>>
>>102523339
nobody will make an account on your shitty website, fuck off already
>>
>>102524487
>verifying your browser
bullshit
>>
>>102525123
>(((nothing ever happens)))
eat pork, faggot
>>
Thank god I don't use the network
>>
>>102525330
Who the fuck is dumb enough to leave UPnP enabled on their router?
>>
>>102523339
GKH just did a talk explaining how the Linux Kernel Security Team works
>no disclosure
>no CVE assigned until it's patched
>>
>>102523339
>plus others
why are you like this
>>
>>102523339
>tweet 404s
>no other source
>no real information
This is complete bullshit isn't it
>>
>>102526626
Maybe. It's not actionable anyhow.
>>
>>102526571
>LGBT+
>Linux
>GNU
>BSD
>Trannies
>plus others
>>
>>102523365
Another W for Windows
>>
>>102526820
ahaha, windows and winning? hahaha
>>
He limited the tweet publicity sus
https://archive.is/wwoQZ
>>
File: le-middle-finger.png (385 KB, 1728x882)
385 KB
385 KB PNG
>>102524487
>evilsocket
. . . protected account.
First twitter goes full retard on anonymous browsing
Now this asshat locks down their account.
Fuck all y'all.
>>
>>102523339
no doubt its nothing again
>>
>>102523476
good thing he never saw the source of windows or macos
>>
>>102527151
jidf is about to have their backdoor exposed so they are going all out on the harassment
>>
File: desu.png (663 KB, 650x652)
663 KB
663 KB PNG
>>102523339
>>
>>102525389
Trannies are revolting desu
>>
>>102525063
Transsexuals are disgusting freaks. I like to leap on even the slightest glimmer of suggestion of total tranny destruction... Any tranny failure is entertaining, except suicide is too far.



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.