GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    feld (feld@friedcheese.us)'s status on Thursday, 16-Jan-2025 03:20:48 JST feld feld
    everyone is overreacting to CVEs like usual

    if you're doing rsync over SSH, they'd have to have compromised the server key to not trigger the fingerprint/impersonation warning

    If the server is compromised by an attacker, you have much larger problems.

    Secure both ends. Use a secure network transport that can't be MITM'd. These problems don't matter then.

    RT: https://mastodon.social/users/nixCraft/statuses/113833699519818054
    In conversation about 4 months ago from friedcheese.us permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: files.mastodon.social
      nixCraft 🐧 (@nixCraft@mastodon.social)
      from nixCraft 🐧
      Attached: 1 image The rsync utility in Linux, *BSD, and Unix-like systems are vulnerable to multiple security issues, including arbitrary code execution, arbitrary file upload, information disclosure, and privilege escalation. Hence, you must patch the system ASAP https://www.cyberciti.biz/linux-news/cve-2024-12084-rsyn-security-urgent-update-needed-on-unix-bsd-systems/ #infosec #security #linux #unix
    • ✙ dcc :pedomustdie: :phear_slackware: likes this.
    • Embed this notice
      Fish of Rage (sun@shitposter.world)'s status on Thursday, 16-Jan-2025 03:21:50 JST Fish of Rage Fish of Rage
      in reply to
      @feld sometimes I forget people use rsyncd
      In conversation about 4 months ago permalink
    • Embed this notice
      feld (feld@friedcheese.us)'s status on Thursday, 16-Jan-2025 03:22:43 JST feld feld
      in reply to
      • Fish of Rage
      @sun the performance over ssh is ass, so it's fine to use rsyncd --just require a VPN
      In conversation about 4 months ago permalink
      Fish of Rage likes this.
    • Embed this notice
      JoshuaSlocum (joshuaslocum@poa.st)'s status on Thursday, 16-Jan-2025 05:07:10 JST JoshuaSlocum JoshuaSlocum
      in reply to
      @feld i only rsync to locally attached USB 1.1 hard drives i've scrounged from dumpsters
      i am invincible
      In conversation about 4 months ago permalink
      feld likes this.
    • Embed this notice
      gentoobro (gentoobro@shitpost.cloud)'s status on Saturday, 18-Jan-2025 13:34:44 JST gentoobro gentoobro
      in reply to

      CVE's almost never matter. It's always something like "An attacker with root permissions and physical access to the machine might be able to recover your Facebook password in only 12 hours with this new speculative execution attack!."

      In conversation about 4 months ago permalink
      ✙ dcc :pedomustdie: :phear_slackware: likes this.
    • Embed this notice
      feld (feld@friedcheese.us)'s status on Saturday, 18-Jan-2025 15:05:02 JST feld feld
      in reply to
      • gentoobro
      @gentoobro And some kid with an infosec certificate and zero years experience is losing his mind
      In conversation about 4 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.