GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    feld (feld@friedcheese.us)'s status on Thursday, 16-Jan-2025 03:20:48 JSTfeldfeld
    everyone is overreacting to CVEs like usual

    if you're doing rsync over SSH, they'd have to have compromised the server key to not trigger the fingerprint/impersonation warning

    If the server is compromised by an attacker, you have much larger problems.

    Secure both ends. Use a secure network transport that can't be MITM'd. These problems don't matter then.

    RT: https://mastodon.social/users/nixCraft/statuses/113833699519818054
    In conversationabout 4 months ago from friedcheese.uspermalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: files.mastodon.social
      nixCraft 🐧 (@nixCraft@mastodon.social)
      from nixCraft 🐧
      Attached: 1 image The rsync utility in Linux, *BSD, and Unix-like systems are vulnerable to multiple security issues, including arbitrary code execution, arbitrary file upload, information disclosure, and privilege escalation. Hence, you must patch the system ASAP https://www.cyberciti.biz/linux-news/cve-2024-12084-rsyn-security-urgent-update-needed-on-unix-bsd-systems/ #infosec #security #linux #unix
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.