GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    niconiconi (niconiconi@mk.absturztau.be)'s status on Tuesday, 20-Aug-2024 19:34:16 JSTniconiconiniconiconi
    • Haelwenn /элвэн/ :triskell:

    When I was installing my first mail server years ago, I saw mbox and thought, "Seriously? Who still uses this ancient format from the original Unix..." and changed that to Maildir without thinking. When reviewing old news today, TIL I unconsciously hardened my server from that infamous 2020 OpenSMTPD root exploit. :blobcatlul: Turned out the ancient mbox format also made it difficult to drop privileges... Also, @lanodan@queer.hacktivis.me, hi. https://poolp.org/posts/2020-01-30/opensmtpd-advisory-dissected/

    In conversationTuesday, 20-Aug-2024 19:34:16 JST from mk.absturztau.bepermalink

    Attachments


    1. https://misskey-taube.s3.eu-central-1.wasabisys.com/files/20617ed8-bf67-4124-b967-d323bfd57792.webp

    2. https://misskey-taube.s3.eu-central-1.wasabisys.com/files/defc51ce-fab8-43f3-893a-615e7f8155c2.webp
    3. Domain not in remote thumbnail source whitelist: poolp.org
      OpenSMTPD advisory dissected
      TL;DR: - Qualys released an advisory for a bad, bad vulnerability - an MTA is a very bad software to have a vulnerability in - hole was plugged but that's not enough, similar bugs should be mitigated in the future - article discusses what could have prevented escalation despite the bug What happened ?
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.