Unauthenticated RCE vs all GNU/Linux systems (plus others), disclosure due in 2 weeks

https://x.com/evilsocket/status/1838169889330135132

https://i.rdrama.net/images/17271135760988767.webp https://i.rdrama.net/images/17271135759020903.webp

https://i.rdrama.net/images/172711357626477.webp

61
Jump in the discussion.

No email address required.

Reported by:
  • JimieWhales : @Aevann this is supposed to be a poll but it won't let me post it

:marseyjewoftheorientglow:

:marseyputin:

:marseysaluteisrael:

:marseydarkbrandon:

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

>9.9 RCE

:marseypoggers: !codecels get the frick in here

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

NOOOO LINUX CANT BE EXPLOITED NOOO SECURITY THROUGH OBSCURITY NOOO

Jump in the discussion.

No email address required.

NOOOO THAT DOESNT COUNT WINDOWS IS CLOSED SOURCE THERE COULD BE 8 GORILLION BACKDOORS IN THERE NOOOO

Jump in the discussion.

No email address required.

Anybody who uses Linux on desktop should have a pretty good idea what passes for security most of the time.

Jump in the discussion.

No email address required.

Bro you keep mass coping about desktop vs laptop lmfao

Jump in the discussion.

No email address required.

No I mean desktop as in desktop Linux- not android.

Jump in the discussion.

No email address required.

Laptops are known to be less secure, idiot

Jump in the discussion.

No email address required.

Sure okay :marseyj#erkofffrown:

Jump in the discussion.

No email address required.

I use linux for everything and I can attest that linux security is terrible. They gave up on kernel hardening a long time ago and there is effevtively no sandboxing at all in userspace.

Pretty much all security is terrible everywhere, but linux may be one of the worst because "just dont compile and install malware lmao" has been "effective enough" security for a while.

So its a matter if you can obscure malware in source code rather than binaries. But the good thing is that static analysis of source code is far better than static analysis of binaries (antivirus is pretty useless just uses binary heuristics)

We need some sort of rust-like languge/ static analysis tool that works together witb userland sandboxing that is real easy to use (more like BSD Jails, less like apparmor).

Jump in the discussion.

No email address required.

They gave up on kernel hardening a long time ago and there is effevtively no sandboxing at all in userspace

Yet another r-slur who has no idea what hes talking about. :marseysmug2:

Jump in the discussion.

No email address required.

LMFAKOOOOOOOOOOO

Jump in the discussion.

No email address required.

More comments

wasnt the XZ utils backdoor a 9.9 too? linbros... :marseypenguingenocide:

Jump in the discussion.

No email address required.

My minecraft server is running Ubuntu 18.04 LTS in my router's DMZ, should I be concerned?

Jump in the discussion.

No email address required.

Yes. It's been infected by Ubuntu

Jump in the discussion.

No email address required.

Truly a fate worse than Windows

Jump in the discussion.

No email address required.

Use Debian, incel

Jump in the discussion.

No email address required.

There is like one critical RCE in linux a year. That it didn't get a perfect 10 means its in something that is not always installed but 9.9 means it usually is, so its not another samba.

Jump in the discussion.

No email address required.

Why'd you spend 3 weeks working full time to "support free software" like a cuck :marseybikecuck: instead of making a bunch of crypto :marseywallst: from the exploit and fleeing to some sunny beach :marseybeachtowel:

Jump in the discussion.

No email address required.

it's called being a decent human being

Jump in the discussion.

No email address required.

Money.

Distinguished/fellow jobs pay extremely well, you get the bump by either being a brain or being willing to wade through shit.

I get paid crazy Jew money and all my work is on FOSS.

instead of making a bunch of crypto :marseywallst: from the exploit and fleeing to some sunny beach

It's going to be fixed quickly without him being involved. There are no nice beaches in places that won't deport you that are also places most people want to live.

It's basically Russia, NK, China and Cuba left at this point. Cuba is pushing it as I don't think the US would really have a rendition problem anymore.

Jump in the discussion.

No email address required.

Why not both?

Jump in the discussion.

No email address required.

Are we thinking systemd?

Jump in the discussion.

No email address required.

Ugh if it does turn out to be systemd the anti-systemd tards are going to reach unimaginable levels of smug.

Jump in the discussion.

No email address required.

What terrifies me is if hackers were to find a RCE exploit and pwn 50 million servers. Imagine the backlash against peaceful systemd enjoyers?

Jump in the discussion.

No email address required.

:marseyxd:

Jump in the discussion.

No email address required.

It'll be worse than the exploit.

Jump in the discussion.

No email address required.

Im confused on the plus others designation. Is this referring to non gnu-linux like busy box and/or bsd? !linuxchads

Jump in the discussion.

No email address required.

thats a good point lmao, because all distros mentioned are strictly systemd. But all GNU/Linux should imply that it is not dependent on userspace configuration (other than like glibc and GNU stuff) so maybe its in the networking stack?

RUST IN THE LINUX KERNEL IS LONG OVERDUE

Jump in the discussion.

No email address required.

But all GNU/Linux should imply that it is not dependent on userspace configuration (other than like glibc and GNU stuff) so maybe its in the networking stack?

Gnu/linux implies it's userspace configuration, not kernel (that would be just linux). It's the term for what normal people call "linux" in reference to the family of operating systems, even if they have no gnu shit on them.

Jump in the discussion.

No email address required.

There was a recent RCE in Windows from bad IPv6 packets, maybe someone copied that vector for Linux?

Jump in the discussion.

No email address required.

It's not ipv6

Jump in the discussion.

No email address required.

Oh did he clarify down thread?

Jump in the discussion.

No email address required.

https://i.rdrama.net/images/1727118135621801.webp

would be worse :marseyhmm:

Jump in the discussion.

No email address required.

Oh hm :marseyhmm:

Jump in the discussion.

No email address required.

So a full on 10 instead of 9.9? Maybe "9.9" doesn't mean as much as it seems.

:#marseyponder:

Jump in the discussion.

No email address required.

I am using Gentoo OpenRC and I haven't been able to update in a few months because I'm r-slurred, I was worried for a minute lmao

Jump in the discussion.

No email address required.

Bet you 100 coins

Jump in the discussion.

No email address required.

Should have used MacOSX which is UNIX, the white mans OS, rather then being a pathetic pretender !applechads

Jump in the discussion.

No email address required.

I'm going to jailbreak so many iot bullshit devices that have piled up over the years

Jump in the discussion.

No email address required.

>RCE gets downloaded onto your NAS while you're torrenting russian porn onto it

>Your smart thermostat gets permanently set to 90 degrees

>Your smart fridge freezes your milk and spoils all the meat in your freezer

>Your philips hue lighting gets stuck cycling through the rainbow all day and night and reacting to the sound of your voice

Welcome to the future

Jump in the discussion.

No email address required.

Your philips hue lighting gets stuck cycling through the rainbow all day and night and reacting to the sound of your voice

I would say I'm tired of the gay agenda being ramrodded down my facehole in the Linux-sphere, but I use Fedora as my daily driver so I know I'm gay already.

Jump in the discussion.

No email address required.

but I use Fedora as my daily driver so I know I'm gay already.

No you are a king. Everyone knows those using RH distros are the masterrace.

Jump in the discussion.

No email address required.

At least my iot chastity cage didn't get locked remotely (yet)

Jump in the discussion.

No email address required.

Total IOT death

Jump in the discussion.

No email address required.

Heck hath no fury like a codecel ignored

Jump in the discussion.

No email address required.

The dude privated his twitter account :marseyxd: He couldn't take the heat.

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

it has to be kernel but I am hoping it is systemd cause I use openrc and it would cause so much fricking drama.

I dont even dislike systemd it just shouldnt have been default.

Jump in the discussion.

No email address required.

:marseybegging: Please be systemd...

:marseybegging: Please be systemd...

Jump in the discussion.

No email address required.

Some npm package

I know asking rust people if they are r-slurred is itself r-slurred because by definition you all are but it's very clearly not node related.

Node does indeed compete with rust for favorite language among smoothbrains though.

Jump in the discussion.

No email address required.

2 weeks you say?

:marseysaltalking:

Jump in the discussion.

No email address required.

In English please for a brainlet? :marseybrainlet:

Jump in the discussion.

No email address required.

A lot of computers are at risk of getting hacked to shit

https://i.rdrama.net/images/1727118602249208.webp

Jump in the discussion.

No email address required.

2 more weeks :marseyfsjal:

Jump in the discussion.

No email address required.

Shalom

Jump in the discussion.

No email address required.

Did this not make it to HN?

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

It's probably something that's unexploitable in practice or rarely enabled by default or both if the developers aren't too bothered about fixing it. Sounds like yet another vulnerability that's more hype than anything serious.

or

Jump in the discussion.

No email address required.

BSD and Haiku win again! :marseypuffer: :manulfloat: :marseypenguingenocide:

Jump in the discussion.

No email address required.

I live in a CIA prison. A BIPOC runs my prison. In prison, the BIPOC tries to torment me. We can take away his knives by confessing, every day. In about 2000, I masturbated fantasizing about my niece, Lani. She looks like star trek seven of nine! In 1985, at my sister's wedding, I stuck my crotch on the hot tub drain because it kind of sucked. In 1985, I tried to get a dog to lick my peepee. From 1998-2003, I fantasized about leading a catholic army like dune, of mexicans or brazilians? that was dumb because they're BIPOCs. In 2003, I played tag with a black girl about 7-years-old. she reached for my crotch. In high school, in the library, Carlos and I said juicy or toxic as a way of evaluating girls. In 1988, I cheated on my SAT by talking in the hall during the break -- two problems. On 9/9/1999, I killed a CIA BIPOC on purpose with my car. :-) In 1982, when I was 12, I babysat Kevin's kids. I changed a diaper because I thought that was being professional. In 1975, when I was about the age five, my brother, Keith, put my peepee in a vacuum. In 1977, when I was about age seven, my brother, Danny, got me high on gas fumes and we sucked each others peepees. Dr. Tsakalis has an oddly round butt. Paul Keck at Xytex had a oddly round butt. Distracting? At about age five, Jay Weinrick and I touched disks to each other's buttholes.

Snapshots:

https://x.com/evilsocket/status/1838169889330135132:

Jump in the discussion.

No email address required.

oh fugg ;-DD

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.