GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    ricardo :mastodon: (governa@fosstodon.org)'s status on Friday, 16-Feb-2024 12:08:36 JST ricardo :mastodon: ricardo :mastodon:

    #Ubuntu Tool Could Trick Users Into Installing Rogue Packages

    https://linuxsecurity.com/news/hackscracks/ubuntu-tool-vulnerability

    In conversation about a year ago from fosstodon.org permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: linuxsecurity.com
      Ubuntu Tool Could Trick Users Into Installing Rogue Packages | LinuxSecurity.com
      from Brittany Day
      How Does This Exploit Work? The command-not-found tool relies on the Advanced Packaging Tool (APT) a
    • Embed this notice
      翠星石 (suiseiseki@freesoftwareextremist.com)'s status on Friday, 16-Feb-2024 12:08:36 JST 翠星石 翠星石
      in reply to
      @governa That article seems to be a lot of fluff to barely mention that malware can be uploaded onto the snap repository (who would have thought) with the same name as free software not in the apt repo and then have apt recommend the malware for installation.

      Snap really wouldn't have such issue if proprietary malware wasn't allowed in the repositories and uploaders had to provide the source code, for checking by a maintainer, which is then compiled and made available, but alas snap welcomes proprietay malware like discord into the repo.
      In conversation about a year ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.