検索

2.7までのGNU inetutilsに含まれるtelnetdに、細工した環境変数を送信するだけで認証を回避して特権ユーザーでのログインが可能な脆弱性が発見されらしい。CVE-2026-24061。いまどきtelnetdをThe Internetに露出している人はそうそういないはずとはいえ、なかなか興味深いので調べてみたところ。telnetdがexecv()で呼び出す/usr/bin/loginのコマンドラインオプションをうまく使うことでそういうことができてしまうようで、正直興奮した。 https://www.safebreach.com/blog/safebreach-labs-root-cause-analysis-and-poc-exploit-for-cve-2026-24061/ #CVE #GNU #inetutils #login #telnetd #サイバーセキュリティ #セキュリティ #情報セキュリティ #脆弱性
返信 0 · Renote 1
Okay, let me do a better #introduction now that there's a bajillion more people here. I'm a former hacker, worked in #infosec, still into #programming and #electronics, currently more interested in #nature, both being in it and studying it. #philosophy #pragmatism #science #physics #chemistry #biology #geography #astronomy #mathematics #algebra #geometry #analysis #politics #anarchism #economics #socialism #language #english #svenska #português #deutsch #hacking #foss #gnu #linux #gnome #c
返信 0 · Renote 0
I configured WKD for trop.in domain, now you can get my gpg key using simple command: gpg --locate-keys andrew@trop.in Some mail clients will do it automagically. More information on WKD and how to configure it here: https://www.uriports.com/blog/setting-up-openpgp-web-key-directory/ https://keys.openpgp.org/about/usage#wkd-as-a-service Kudos to @[email protected] and @[email protected] for the comments, links, articles and all the help. #gnu #gnupg #gpg #pgp #wkd
返信 0 · Renote 0