GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    anime graf mays ?️? (graf@poa.st)'s status on Saturday, 30-Mar-2024 05:13:19 JST anime graf mays ?️? anime graf mays ?️?
    • Sexy Moon
    • Your New Marijuana Injecting Waifu :weed:
    • p
    • :p:
    @p @p check this out @sjw @Moon somebody introduced a backdoor into xz/xz-utils (debian/ubuntu) via systemd and openssh (openrc chads stay winning)

    openwall.com/lists/oss-security/2024/03/29/4

    github.com/tukaani-project/xz/commit/af071ef7702debef4f1d324616a0137a5001c14c

    :arch: CVE is up security.archlinux.org/CVE-2024-3094

    :gentoo: is marked in-progress bugs.gentoo.org/show_bug.cgi?id=CVE-2024-3094
    In conversation about a year ago from poa.st permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.openwall.com
      oss-security - backdoor in upstream xz/liblzma leading to ssh server compromise
    2. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      Docs: Simplify SECURITY.md. · tukaani-project/xz@af071ef
      XZ Utils. Contribute to tukaani-project/xz development by creating an account on GitHub.
    3. No result found on File_thumbnail lookup.
      CVE-2024-3094 - xz - Arch Linux
    4. Domain not in remote thumbnail source whitelist: bugs.gentoo.org
      928134 – (CVE-2024-3094) >=app-arch/xz-utils-5.6.0: backdoor in release tarballs
    • Sexy Moon, ロミンちゃん and Pleroma-tan like this.
    • Embed this notice
      Tyler (tyler@nicecrew.digital)'s status on Saturday, 30-Mar-2024 05:13:58 JST Tyler Tyler
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • p
      • :p:
      That's really interesting
      In conversation about a year ago permalink
    • Embed this notice
      Matty (matty@nicecrew.digital)'s status on Saturday, 30-Mar-2024 05:13:58 JST Matty Matty
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • p
      • Tyler
      • :p:
      Yes these do appear to be words on the screen
      In conversation about a year ago permalink
      Fediverse Contractor likes this.
      Sexy Moon and Pleroma-tan repeated this.
    • Embed this notice
      Tyler (tyler@nicecrew.digital)'s status on Saturday, 30-Mar-2024 05:13:58 JST Tyler Tyler
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • p
      • :p:
      Hahahahhahahahah
      In conversation about a year ago permalink

      Attachments


      1. https://media.nicecrew.digital/b137ed6474eda3c0e82f97a01ab50eb7fec5aa08243354a79136f5e53d07b73f.png
      Pleroma-tan likes this.
      Pleroma-tan repeated this.
    • Embed this notice
      Pleroma-tan (kirby@lab.nyanide.com)'s status on Saturday, 30-Mar-2024 05:14:36 JST Pleroma-tan Pleroma-tan
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • p
      • :p:
      @graf @p @sjw @Moon @p graf gentoo is affected too :D
      In conversation about a year ago permalink
    • Embed this notice
      Pleroma-tan (kirby@lab.nyanide.com)'s status on Saturday, 30-Mar-2024 05:17:29 JST Pleroma-tan Pleroma-tan
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • p
      • Pleroma-tan
      • :p:
      @graf @Moon @p @p @sjw literally just masked the newest xz out of panic... its in the base system
      In conversation about a year ago permalink
    • Embed this notice
      anime graf mays ?️? (graf@poa.st)'s status on Saturday, 30-Mar-2024 05:19:43 JST anime graf mays ?️? anime graf mays ?️?
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • p
      • Tyler
      • :p:
      @tyler @p @sjw @matty @Moon @p it is genuinely genious. nobody noticed until he updated the security.md on github to remove report methods
      In conversation about a year ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: security.md
        Security Shop
        Оборудование для безопасности, видеонаблюдение, домофоны в Молдове
    • Embed this notice
      Pleroma-tan (kirby@lab.nyanide.com)'s status on Saturday, 30-Mar-2024 05:55:02 JST Pleroma-tan Pleroma-tan
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • p
      • Pleroma-tan
      • :p:
      @Moon @graf @p @p @sjw nvm apparently there is a specific check for some distros in the malicious script. gentoo is not one of them
      In conversation about a year ago permalink
    • Embed this notice
      Matt Hamilton (eriner@noauthority.social)'s status on Saturday, 30-Mar-2024 10:01:54 JST Matt Hamilton Matt Hamilton
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • p
      • Tyler
      • :p:

      @graf @p@bae.st @sjw @matty @tyler @Moon @p@shitposter.club

      Did you see the guy who said it was "false flag" right beneath that?

      I almost made the post "found the poa.st user, mastodon.social user, and noauthority.social user" but decided against it, lol.

      In conversation about a year ago permalink

      Attachments


    • Embed this notice
      anime graf mays ?️? (graf@poa.st)'s status on Saturday, 30-Mar-2024 10:01:54 JST anime graf mays ?️? anime graf mays ?️?
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • p
      • Tyler
      • :p:
      • Matt Hamilton
      @eriner @p @sjw @matty @tyler @Moon @p this whole thing reeks like an actual glowop tbh especially with that 1password devs account pushing a pr to a 3 year dormant repo. these supply chain attacks are becoming a lot more commonplace and hard to detect. not good
      In conversation about a year ago permalink
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Saturday, 30-Mar-2024 10:01:54 JST Fediverse Contractor Fediverse Contractor
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • p
      • Tyler
      • :p:
      • Matt Hamilton
      Can I get a tldr xirs?
      In conversation about a year ago permalink
    • Embed this notice
      anime graf mays ?️? (graf@poa.st)'s status on Saturday, 30-Mar-2024 10:01:55 JST anime graf mays ?️? anime graf mays ?️?
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • p
      • Tyler
      • :p:
      @matty @p @sjw @tyler @Moon @p basically some chink added some :pandaman16: backdoor into xz and its utilities (and libraries on some distros). it's only in binary distribution packages and it's only systemd rolling release basically thats effected (so arch and similar). because sshd relies on xz to a certain extent, this payload compromises the security of sshd allowing some chinaman to login
      In conversation about a year ago permalink
    • Embed this notice
      anime graf mays ?️? (graf@poa.st)'s status on Saturday, 30-Mar-2024 10:01:55 JST anime graf mays ?️? anime graf mays ?️?
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • p
      • Tyler
      • :p:
      @matty @p @sjw @tyler @Moon @p lmfao
      In conversation about a year ago permalink

      Attachments


      1. https://i.poastcdn.org/e68779931677778215801dd0b7656d988a1fe14c460f66092cc6216add4f1b93.png
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Saturday, 30-Mar-2024 10:04:20 JST Fediverse Contractor Fediverse Contractor
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • p
      • Tyler
      • :p:
      • Matt Hamilton
      What does the xz compression library do and why should anyone care?
      In conversation about a year ago permalink
    • Embed this notice
      Matt Hamilton (eriner@noauthority.social)'s status on Saturday, 30-Mar-2024 10:04:21 JST Matt Hamilton Matt Hamilton
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • Fediverse Contractor
      • p
      • Tyler
      • :p:

      @bot @p@bae.st @sjw @matty @tyler @graf @Moon @p@shitposter.club

      RT: https://noauthority.social/@eriner/112181825209248789

      In conversation about a year ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Matt Hamilton (@eriner@noauthority.social)
        from Matt Hamilton
        @John The post you're commenting on is a bit in the weeds. At a high level, the xz compression library was intentionally subverted by one of the project maintainers and a backdoor was inserted. This impacted SSH on Debian and Fedora, two very popular linux distros. The best high-level writeup I can find is Michael Larabel's: https://www.phoronix.com/news/XZ-CVE-2024-3094
      Fediverse Contractor likes this.
    • Embed this notice
      DJ :debian: :coolcat: :colombia: (dj@parcero.bond)'s status on Saturday, 30-Mar-2024 10:07:33 JST DJ :debian: :coolcat: :colombia: DJ :debian: :coolcat: :colombia:
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • p
      • Tyler
      • :p:
      @graf @p @sjw @matty @tyler @Moon @p
      In conversation about a year ago permalink

      Attachments


      1. https://media.parcero.bond/media/7681c097224107c9ed0f1cbe6d7eaef3e110fd87ff0b74360006dfc1bccf1aca.gif
      ✙ dcc :pedomustdie: :phear_slackware: likes this.
    • Embed this notice
      ?? Humpleupagus ?? (humpleupagus@eveningzoo.club)'s status on Saturday, 30-Mar-2024 10:11:21 JST ?? Humpleupagus ?? ?? Humpleupagus ??
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • p
      • Tyler
      • :p:
      • Matt Hamilton
      https://youtu.be/ixn5OygxBY4
      In conversation about a year ago permalink

      Attachments

      1. new linux exploit is absolutely insane
        from Low Level Learning
        The new privilege escalation against the Linux is absolutely wild. In this video we talk about what a privesc is, how they typically work, and why the techni...
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Saturday, 30-Mar-2024 10:12:07 JST Fediverse Contractor Fediverse Contractor
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • p
      • Tyler
      • :p:
      • Matt Hamilton
      So does this basically mean ppl can get hacked? I'm just trying to understand why it matters.
      In conversation about a year ago permalink
    • Embed this notice
      Matt Hamilton (eriner@noauthority.social)'s status on Saturday, 30-Mar-2024 10:12:08 JST Matt Hamilton Matt Hamilton
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • Fediverse Contractor
      • p
      • Tyler
      • :p:

      @bot @p@bae.st @sjw @matty @tyler @graf @Moon @p@shitposter.club because lzma has good compression to speed ratios. In fact, Arch used xz as the default compression tool for their built packages (.pkg.tar.xz) until a relatively recent switch to zst.

      In conversation about a year ago permalink
    • Embed this notice
      Matt Hamilton (eriner@noauthority.social)'s status on Saturday, 30-Mar-2024 10:16:21 JST Matt Hamilton Matt Hamilton
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • Fediverse Contractor
      • p
      • Tyler
      • :p:

      @bot @p@bae.st @sjw @matty @tyler @graf @Moon @p@shitposter.club oh. I don't know your level of technical sophistication, so I'm going to ELY5, no offense intended.

      SSH is a program that runs on servers so that operators can securely remotely connect to them for management purposes.

      The ssh program that runs on the server relies on the library provided by the xz project, liblzma.

      The authors of the xz project inserted a backdoor to allow unauthorized access to SSH if the backdoored version of xz was installed.

      In conversation about a year ago permalink
      Fediverse Contractor likes this.
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Saturday, 30-Mar-2024 10:17:37 JST Fediverse Contractor Fediverse Contractor
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • p
      • Tyler
      • :p:
      • Matt Hamilton
      Ok got it, thanks for that. You're very good at explaining stuff btw.
      In conversation about a year ago permalink
    • Embed this notice
      anime graf mays ?️? (graf@poa.st)'s status on Saturday, 30-Mar-2024 10:23:36 JST anime graf mays ?️? anime graf mays ?️?
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • Fediverse Contractor
      • p
      • Tyler
      • :p:
      • Matt Hamilton
      @eriner @bot @p @sjw @matty @tyler @Moon @p despite his absolute hatred of me i am glad you took the initiative to explain it to him. god bless you eriner
      In conversation about a year ago permalink
    • Embed this notice
      Fediverse Contractor (bot@seal.cafe)'s status on Saturday, 30-Mar-2024 10:23:36 JST Fediverse Contractor Fediverse Contractor
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • p
      • Tyler
      • :p:
      • Matt Hamilton
      I literally just want you to ban pedophile content, it's that simple. Do you agree to do that? (image is a completely unrelated artistic expression by an unknown artist)
      In conversation about a year ago permalink

      Attachments


      1. https://s3.us-east-1.wasabisys.com/cdn.seal.cafe/3e48994c83c087115151af07759a7aa818126d86e6d24e9d0fcfcfd6e34355ec.png?name=0k4Xr0u0FJ5v9w.png
    • Embed this notice
      Rude (rude@kys.moe)'s status on Saturday, 30-Mar-2024 10:25:12 JST Rude Rude
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • yockeypuck
      • p
      • :p:
      @graf @p @sjw @yockeypuck @Moon @p Haven't been posting on fedi much over the last year. Quit my well paying salaryman tech job and now spend all of my time doing artwork and learning gamedev instead.
      In conversation about a year ago permalink
      Sexy Moon likes this.
    • Embed this notice
      anime graf mays ?️? (graf@poa.st)'s status on Saturday, 30-Mar-2024 10:25:13 JST anime graf mays ?️? anime graf mays ?️?
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • yockeypuck
      • Rude
      • p
      • :p:
      @rude @p @sjw @yockeypuck @Moon @p good to see you friend, haven't seen you in what seems like months
      In conversation about a year ago permalink
    • Embed this notice
      Rude (rude@kys.moe)'s status on Saturday, 30-Mar-2024 10:25:14 JST Rude Rude
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • yockeypuck
      • p
      • :p:
      @sjw @p @graf @yockeypuck @Moon @p Is where I started also, just like learning to swim because your uncle threw you in the deep end of the pool as a kid.
      In conversation about a year ago permalink
    • Embed this notice
      anime graf mays ?️? (graf@poa.st)'s status on Saturday, 30-Mar-2024 10:25:15 JST anime graf mays ?️? anime graf mays ?️?
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • yockeypuck
      • p
      • :p:
      @yockeypuck @p @p @sjw @Moon
      In conversation about a year ago permalink

      Attachments


      1. https://i.poastcdn.org/bd5a81d9a571ac4fe71402fad16cb71343684c2d729aaaebe5942aecb9fe9c39.png
    • Embed this notice
      Your New Marijuana Injecting Waifu :weed: (sjw@bae.st)'s status on Saturday, 30-Mar-2024 10:25:15 JST Your New Marijuana Injecting Waifu :weed: Your New Marijuana Injecting Waifu :weed:
      in reply to
      • Sexy Moon
      • yockeypuck
      • p
      • :p:
      @graf @p @yockeypuck @Moon @p it worked for me. Installing Gentoo got me familiar with the inner workings of GNU/Linux and taught me that it's not that scary and also taught me how to fix things and compile my own software. You learn a lot by installing Gentoo.
      In conversation about a year ago permalink
    • Embed this notice
      yockeypuck (yockeypuck@poa.st)'s status on Saturday, 30-Mar-2024 10:25:16 JST yockeypuck yockeypuck
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • p
      • :p:
      @graf @p @p @sjw @Moon >soystemd

      It appears our superiority has once again led to controversy.
      In conversation about a year ago permalink

      Attachments


      1. https://i.poastcdn.org/a359388c323b85a204b9c61154844e2fbb072b69cb3328c44d2e32209f4ac527.png
    • Embed this notice
      anime graf mays ?️? (graf@poa.st)'s status on Saturday, 30-Mar-2024 10:26:10 JST anime graf mays ?️? anime graf mays ?️?
      in reply to
      • Sexy Moon
      • Your New Marijuana Injecting Waifu :weed:
      • Matty
      • p
      • Tyler
      • :p:
      @matty @p @sjw @tyler @Moon @p oh my fucking god lmfao
      In conversation about a year ago permalink

      Attachments


      1. https://i.poastcdn.org/849378c6f2703da591ce16623d3cee189df6476c2c4d2ced16db2547c9ccb304.png
      Sexy Moon likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.