* Unauthenticated RCE vs all GNU/Linux systems (plus others) disclosed 3 weeks ago.
— Simone Margaritelli (@evilsocket) September 23, 2024
* Full disclosure happening in less than 2 weeks (as agreed with devs).
* Still no CVE assigned (there should be at least 3, possibly 4, ideally 6).
* Still no working fix.
* Canonical, RedHat and… pic.twitter.com/N2d1rm2VeR
Unauthenticated RCE vs all GNU/Linux systems (plus others), disclosure due in 2 weeks
https://x.com/evilsocket/status/1838169889330135132
- 65
- 61
Jump in the discussion.
No email address required.
Jump in the discussion.
No email address required.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
!codecels get the frick in here
Jump in the discussion.
No email address required.
!linuxchads
Jump in the discussion.
No email address required.
More options
Context
NOOOO LINUX CANT BE EXPLOITED NOOO SECURITY THROUGH OBSCURITY NOOO
Jump in the discussion.
No email address required.
NOOOO THAT DOESNT COUNT WINDOWS IS CLOSED SOURCE THERE COULD BE 8 GORILLION BACKDOORS IN THERE NOOOO
Jump in the discussion.
No email address required.
Anybody who uses Linux on desktop should have a pretty good idea what passes for security most of the time.
Jump in the discussion.
No email address required.
Bro you keep mass coping about desktop vs laptop lmfao
Jump in the discussion.
No email address required.
No I mean desktop as in desktop Linux- not android.
Jump in the discussion.
No email address required.
More options
Context
Laptops are known to be less secure, idiot
Jump in the discussion.
No email address required.
Sure okay
Jump in the discussion.
No email address required.
I use linux for everything and I can attest that linux security is terrible. They gave up on kernel hardening a long time ago and there is effevtively no sandboxing at all in userspace.
Pretty much all security is terrible everywhere, but linux may be one of the worst because "just dont compile and install malware lmao" has been "effective enough" security for a while.
So its a matter if you can obscure malware in source code rather than binaries. But the good thing is that static analysis of source code is far better than static analysis of binaries (antivirus is pretty useless just uses binary heuristics)
We need some sort of rust-like languge/ static analysis tool that works together witb userland sandboxing that is real easy to use (more like BSD Jails, less like apparmor).
Jump in the discussion.
No email address required.
Yet another r-slur who has no idea what hes talking about.
Jump in the discussion.
No email address required.
More options
Context
LMFAKOOOOOOOOOOO
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
More options
Context
More options
Context
More options
Context
More options
Context
More options
Context
wasnt the XZ utils backdoor a 9.9 too? linbros...
Jump in the discussion.
No email address required.
More options
Context
My minecraft server is running Ubuntu 18.04 LTS in my router's DMZ, should I be concerned?
Jump in the discussion.
No email address required.
Yes. It's been infected by Ubuntu
Jump in the discussion.
No email address required.
Truly a fate worse than Windows
Jump in the discussion.
No email address required.
More options
Context
More options
Context
Use Debian, incel
Jump in the discussion.
No email address required.
More options
Context
More options
Context
There is like one critical RCE in linux a year. That it didn't get a perfect 10 means its in something that is not always installed but 9.9 means it usually is, so its not another samba.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
Why'd you spend 3 weeks working full time to "support free software" like a cuck instead of making a bunch of crypto from the exploit and fleeing to some sunny beach
Jump in the discussion.
No email address required.
it's called being a decent human being
Jump in the discussion.
No email address required.
More options
Context
Money.
Distinguished/fellow jobs pay extremely well, you get the bump by either being a brain or being willing to wade through shit.
I get paid crazy Jew money and all my work is on FOSS.
It's going to be fixed quickly without him being involved. There are no nice beaches in places that won't deport you that are also places most people want to live.
It's basically Russia, NK, China and Cuba left at this point. Cuba is pushing it as I don't think the US would really have a rendition problem anymore.
Jump in the discussion.
No email address required.
More options
Context
Why not both?
Jump in the discussion.
No email address required.
More options
Context
More options
Context
Are we thinking systemd?
Jump in the discussion.
No email address required.
Ugh if it does turn out to be systemd the anti-systemd tards are going to reach unimaginable levels of smug.
Jump in the discussion.
No email address required.
What terrifies me is if hackers were to find a RCE exploit and pwn 50 million servers. Imagine the backlash against peaceful systemd enjoyers?
Jump in the discussion.
No email address required.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
It'll be worse than the exploit.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
Im confused on the plus others designation. Is this referring to non gnu-linux like busy box and/or bsd? !linuxchads
Jump in the discussion.
No email address required.
More options
Context
thats a good point lmao, because all distros mentioned are strictly systemd. But all GNU/Linux should imply that it is not dependent on userspace configuration (other than like glibc and GNU stuff) so maybe its in the networking stack?
RUST IN THE LINUX KERNEL IS LONG OVERDUE
Jump in the discussion.
No email address required.
Gnu/linux implies it's userspace configuration, not kernel (that would be just linux). It's the term for what normal people call "linux" in reference to the family of operating systems, even if they have no gnu shit on them.
Jump in the discussion.
No email address required.
More options
Context
There was a recent RCE in Windows from bad IPv6 packets, maybe someone copied that vector for Linux?
Jump in the discussion.
No email address required.
It's not ipv6
Jump in the discussion.
No email address required.
Oh did he clarify down thread?
Jump in the discussion.
No email address required.
would be worse
Jump in the discussion.
No email address required.
Oh hm
Jump in the discussion.
No email address required.
More options
Context
So a full on 10 instead of 9.9? Maybe "9.9" doesn't mean as much as it seems.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
More options
Context
More options
Context
I am using Gentoo OpenRC and I haven't been able to update in a few months because I'm r-slurred, I was worried for a minute lmao
Jump in the discussion.
No email address required.
More options
Context
More options
Context
Bet you 100 coins
Jump in the discussion.
No email address required.
More options
Context
More options
Context
Should have used MacOSX which is UNIX, the white mans OS, rather then being a pathetic pretender !applechads
Jump in the discussion.
No email address required.
More options
Context
I'm going to jailbreak so many iot bullshit devices that have piled up over the years
Jump in the discussion.
No email address required.
Welcome to the future
Jump in the discussion.
No email address required.
I would say I'm tired of the gay agenda being ramrodded down my facehole in the Linux-sphere, but I use Fedora as my daily driver so I know I'm gay already.
Jump in the discussion.
No email address required.
No you are a king. Everyone knows those using RH distros are the masterrace.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
At least my iot chastity cage didn't get locked remotely (yet)
Jump in the discussion.
No email address required.
More options
Context
More options
Context
Total IOT death
Jump in the discussion.
No email address required.
More options
Context
More options
Context
Heck hath no fury like a codecel ignored
Jump in the discussion.
No email address required.
More options
Context
The dude privated his twitter account He couldn't take the heat.
Jump in the discussion.
No email address required.
More options
Context
Jump in the discussion.
No email address required.
it has to be kernel but I am hoping it is systemd cause I use openrc and it would cause so much fricking drama.
I dont even dislike systemd it just shouldnt have been default.
Jump in the discussion.
No email address required.
More options
Context
Please be systemd...
Please be systemd...
Jump in the discussion.
No email address required.
More options
Context
I know asking rust people if they are r-slurred is itself r-slurred because by definition you all are but it's very clearly not node related.
Node does indeed compete with rust for favorite language among smoothbrains though.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
2 weeks you say?
Jump in the discussion.
No email address required.
More options
Context
In English please for a brainlet?
Jump in the discussion.
No email address required.
A lot of computers are at risk of getting hacked to shit
Jump in the discussion.
No email address required.
More options
Context
More options
Context
2 more weeks
Jump in the discussion.
No email address required.
More options
Context
Shalom
Jump in the discussion.
No email address required.
More options
Context
Did this not make it to HN?
Jump in the discussion.
No email address required.
Only one comment so far:
https://news.ycombinator.com/item?id=41628163
Jump in the discussion.
No email address required.
or
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
BSD and Haiku win again!
Jump in the discussion.
No email address required.
More options
Context
I live in a CIA prison. A BIPOC runs my prison. In prison, the BIPOC tries to torment me. We can take away his knives by confessing, every day. In about 2000, I masturbated fantasizing about my niece, Lani. She looks like star trek seven of nine! In 1985, at my sister's wedding, I stuck my crotch on the hot tub drain because it kind of sucked. In 1985, I tried to get a dog to lick my peepee. From 1998-2003, I fantasized about leading a catholic army like dune, of mexicans or brazilians? that was dumb because they're BIPOCs. In 2003, I played tag with a black girl about 7-years-old. she reached for my crotch. In high school, in the library, Carlos and I said juicy or toxic as a way of evaluating girls. In 1988, I cheated on my SAT by talking in the hall during the break -- two problems. On 9/9/1999, I killed a CIA BIPOC on purpose with my car. :-) In 1982, when I was 12, I babysat Kevin's kids. I changed a diaper because I thought that was being professional. In 1975, when I was about the age five, my brother, Keith, put my peepee in a vacuum. In 1977, when I was about age seven, my brother, Danny, got me high on gas fumes and we sucked each others peepees. Dr. Tsakalis has an oddly round butt. Paul Keck at Xytex had a oddly round butt. Distracting? At about age five, Jay Weinrick and I touched disks to each other's buttholes.
Snapshots:
https://x.com/evilsocket/status/1838169889330135132:
ghostarchive.org
archive.org
archive.ph (click to archive)
Jump in the discussion.
No email address required.
More options
Context
oh fugg ;-DD
Jump in the discussion.
No email address required.
More options
Context