GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    IAintShootinMis (iaintshootinmis@digitaldarkage.cc)'s status on Tuesday, 24-Sep-2024 19:37:35 JST IAintShootinMis IAintShootinMis

    Who is paying attention to #EvilSocket on X and wheres the conversation happening? I'd like to follow whoever's mastodon is talking about it.

    If no one is, then there is a #Linux unauth #RCE being disclosed to openwall on the 30th.

    Appears to affect Linux and #BSD with a 9.9 CVSS score.

    From reading X thread seems to be not kernel or user space. Assuming protocol implementation?

    https://x.com/evilsocket/status/1838169889330135132

    #ThreatIntel #Vuln #Exploit #infosec #cve

    In conversation about 8 months ago from digitaldarkage.cc permalink

    Attachments


    1. https://media.digitaldarkage.cc/digitaldarkage.media/media_attachments/files/113/189/114/845/206/450/original/c11baa163fc3ef9f.jpg

    2. https://media.digitaldarkage.cc/digitaldarkage.media/media_attachments/files/113/189/114/914/094/370/original/9cda397f9880674c.jpg

    • Embed this notice
      IAintShootinMis (iaintshootinmis@digitaldarkage.cc)'s status on Tuesday, 24-Sep-2024 20:35:36 JST IAintShootinMis IAintShootinMis
      • Kevin Beaumont

      @GossiTheDog respectfully sir, and I mean this sincerely (your toots are considered Infosec scripture in this house), I argue there's a lot to do and I've been doing it. (Its in my Troop Leading Procedures thread here: https://digitaldarkage.cc/@iaintshootinmis/113189506131608638 )

      I can't put mitigations in place, or start patching, but we can brace ourselves and partners for the oncoming Storm.

      In conversation about 8 months ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        IAintShootinMis (@iaintshootinmis@digitaldarkage.cc)
        from IAintShootinMis
        I had several people I know tell me they weren't doing anything about #EvilSocket 's potential disclosure because it was inactionable. I wish I were at a keyboard right now. But of course its actionable! In the military we often received warning orders and we always followed our troop leading procedures. Heres a break down of those and how they apply to your role in #InfoSec A 🧵.
    • Embed this notice
      Ben Aveling (benaveling@infosec.exchange)'s status on Tuesday, 24-Sep-2024 23:28:56 JST Ben Aveling Ben Aveling
      • Kevin Beaumont

      @GossiTheDog @iaintshootinmis we’re told there’s some simple mitigations that will be included in the announcement on the 6th.
      Probably worth scheduling someone to watch for those, with stakeholder contact details and access to whatever mgt tooling you use for deploying changes/running commands across the fleet.
      For some companies that means scheduling a change/outage window, so there might be some prep required for that.
      #EvilSocket #EvilSocketVuln

      In conversation about 8 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.