EDIT: Original post seems to have been removed, try this Nitter mirror instead.

You are viewing a single thread.
View all comments
10 points

Unauthenticed RCE vs all GNU/Linux systems

So this would probably be SSH related right? Otherwise what would all Linux systems have in common?

permalink
report
reply
15 points

My bet is on Systemd.

permalink
report
parent
reply
5 points

That’s not all GNU/Linux though. Either the OP doesn’t understand a very common container OS, Alpine, doesn’t use systemd (also Void Linux and others outside the container space) or it’s something else.

permalink
report
parent
reply
3 points

Oh that would be baaaad

permalink
report
parent
reply
4 points

And unsurprising

permalink
report
parent
reply
5 points

Not all Linux’s have SSH enabled, especially out of the box.

They have some other posts about IPv6 parsing (also not universal), but that doesnt sound like an “easy” RCE.

permalink
report
parent
reply
4 points

If it were SSH though, wouldn’t that ALSO include a wider blast radius than just Linux systems?

Like OpenSSH is used all over the damn place, unless I guess there’s something specific about the issue that limits it to Linux hosts for some reason?

permalink
report
parent
reply
2 points

He claims the blast radius is bigger, not just Linux. He also claims to be in talks with Apple. So the educated guess would still be openssh

permalink
report
parent
reply

Cybersecurity

!cybersecurity@sh.itjust.works

Create post

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

  • Be respectful. Everyone should feel welcome here.
  • No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
  • No Ads / Spamming.
  • No pornography.

Community Rules

  • Idk, keep it semi-professional?
  • Nothing illegal. We’re all ethical here.
  • Rules will be added/redefined as necessary.

If you ask someone to hack your “friends” socials you’re just going to get banned so don’t do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !cybersecurity@lemmy.capebreton.social !securitynews@infosec.pub !netsec@links.hackliberty.org !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

Community stats

  • 1.6K

    Monthly active users

  • 894

    Posts

  • 1.8K

    Comments