Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Oh.

Oh.

Scheduled Pinned Locked Moved Uncategorized
18 Posts 8 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • cr0w@infosec.exchangeC cr0w@infosec.exchange

    Oh.

    myF5

    favicon

    (my.f5.com)

    huronbikes@cyberplace.socialH This user is from outside of this forum
    huronbikes@cyberplace.socialH This user is from outside of this forum
    huronbikes@cyberplace.social
    wrote last edited by
    #2

    @cR0w "the bigger the BIG-IP, the bigger the CVE!" as the old saying goes

    cr0w@infosec.exchangeC fritzadalis@infosec.exchangeF 2 Replies Last reply
    0
    • huronbikes@cyberplace.socialH huronbikes@cyberplace.social

      @cR0w "the bigger the BIG-IP, the bigger the CVE!" as the old saying goes

      cr0w@infosec.exchangeC This user is from outside of this forum
      cr0w@infosec.exchangeC This user is from outside of this forum
      cr0w@infosec.exchange
      wrote last edited by
      #3

      @huronbikes Yeah but that NGINX vuln...

      huronbikes@cyberplace.socialH 1 Reply Last reply
      0
      • cr0w@infosec.exchangeC cr0w@infosec.exchange

        @huronbikes Yeah but that NGINX vuln...

        huronbikes@cyberplace.socialH This user is from outside of this forum
        huronbikes@cyberplace.socialH This user is from outside of this forum
        huronbikes@cyberplace.social
        wrote last edited by
        #4

        @cR0w oh that's just a little oopsie-doodle that can *adjusts glasses* crash the server or lead to RCE.

        huronbikes@cyberplace.socialH 2 Replies Last reply
        0
        • huronbikes@cyberplace.socialH huronbikes@cyberplace.social

          @cR0w oh that's just a little oopsie-doodle that can *adjusts glasses* crash the server or lead to RCE.

          huronbikes@cyberplace.socialH This user is from outside of this forum
          huronbikes@cyberplace.socialH This user is from outside of this forum
          huronbikes@cyberplace.social
          wrote last edited by
          #5

          @cR0w "that's 6-7 skibbidi bad", as nobody's kids say.

          cr0w@infosec.exchangeC 1 Reply Last reply
          0
          • huronbikes@cyberplace.socialH huronbikes@cyberplace.social

            @cR0w "that's 6-7 skibbidi bad", as nobody's kids say.

            cr0w@infosec.exchangeC This user is from outside of this forum
            cr0w@infosec.exchangeC This user is from outside of this forum
            cr0w@infosec.exchange
            wrote last edited by
            #6

            @huronbikes IDK, I might need @catsalad to confirm that verbiage.

            1 Reply Last reply
            0
            • huronbikes@cyberplace.socialH huronbikes@cyberplace.social

              @cR0w oh that's just a little oopsie-doodle that can *adjusts glasses* crash the server or lead to RCE.

              huronbikes@cyberplace.socialH This user is from outside of this forum
              huronbikes@cyberplace.socialH This user is from outside of this forum
              huronbikes@cyberplace.social
              wrote last edited by
              #7

              @cR0w https://github.com/nginx/nginx/commit/524977e7c534e87e5b55739fa74601c9f1102686 is the commit that addresses the nginx rewrite vuln. It's funny, I was looking for a much more involved piece of code that would address it but looks like it's an issue with properly resetting the state of a custom arg parser.

              cr0w@infosec.exchangeC 1 Reply Last reply
              0
              • huronbikes@cyberplace.socialH huronbikes@cyberplace.social

                @cR0w https://github.com/nginx/nginx/commit/524977e7c534e87e5b55739fa74601c9f1102686 is the commit that addresses the nginx rewrite vuln. It's funny, I was looking for a much more involved piece of code that would address it but looks like it's an issue with properly resetting the state of a custom arg parser.

                cr0w@infosec.exchangeC This user is from outside of this forum
                cr0w@infosec.exchangeC This user is from outside of this forum
                cr0w@infosec.exchange
                wrote last edited by
                #8

                @huronbikes It's funny how in software, such small things can be catte-strophic.

                Link Preview Image
                huronbikes@cyberplace.socialH 1 Reply Last reply
                0
                • cr0w@infosec.exchangeC cr0w@infosec.exchange

                  @huronbikes It's funny how in software, such small things can be catte-strophic.

                  Link Preview Image
                  huronbikes@cyberplace.socialH This user is from outside of this forum
                  huronbikes@cyberplace.socialH This user is from outside of this forum
                  huronbikes@cyberplace.social
                  wrote last edited by
                  #9

                  @cR0w well, it's fine, it's not like NginX is used very much, for everything, all over. Also not like this affected the Kubernetes NginX ingress controller... very much...

                  bws@social.linux.pizzaB 1 Reply Last reply
                  0
                  • huronbikes@cyberplace.socialH huronbikes@cyberplace.social

                    @cR0w well, it's fine, it's not like NginX is used very much, for everything, all over. Also not like this affected the Kubernetes NginX ingress controller... very much...

                    bws@social.linux.pizzaB This user is from outside of this forum
                    bws@social.linux.pizzaB This user is from outside of this forum
                    bws@social.linux.pizza
                    wrote last edited by
                    #10

                    @huronbikes @cR0w you mean the ingress controller which is EOL anyway? ๐Ÿ˜‰

                    huronbikes@cyberplace.socialH 1 Reply Last reply
                    0
                    • bws@social.linux.pizzaB bws@social.linux.pizza

                      @huronbikes @cR0w you mean the ingress controller which is EOL anyway? ๐Ÿ˜‰

                      huronbikes@cyberplace.socialH This user is from outside of this forum
                      huronbikes@cyberplace.socialH This user is from outside of this forum
                      huronbikes@cyberplace.social
                      wrote last edited by
                      #11

                      @bws @cR0w EOL works so well certain former employers are definitely not using Windows Server 2012 in 2026. For critical business functionality. Very often.

                      tomsellers@infosec.exchangeT nosirrahsec@infosec.exchangeN 2 Replies Last reply
                      0
                      • huronbikes@cyberplace.socialH huronbikes@cyberplace.social

                        @bws @cR0w EOL works so well certain former employers are definitely not using Windows Server 2012 in 2026. For critical business functionality. Very often.

                        tomsellers@infosec.exchangeT This user is from outside of this forum
                        tomsellers@infosec.exchangeT This user is from outside of this forum
                        tomsellers@infosec.exchange
                        wrote last edited by
                        #12

                        @huronbikes @bws @cR0w

                        I actually came here to make a joke about that because there are TWO similarly named controllers:

                        • Ingress NGINX Controller: deprecated, owned by the K8s project
                        • NGINX Ingress Controller: still alive, owned by F5
                        huronbikes@cyberplace.socialH rootwyrm@weird.autosR 2 Replies Last reply
                        0
                        • tomsellers@infosec.exchangeT tomsellers@infosec.exchange

                          @huronbikes @bws @cR0w

                          I actually came here to make a joke about that because there are TWO similarly named controllers:

                          • Ingress NGINX Controller: deprecated, owned by the K8s project
                          • NGINX Ingress Controller: still alive, owned by F5
                          huronbikes@cyberplace.socialH This user is from outside of this forum
                          huronbikes@cyberplace.socialH This user is from outside of this forum
                          huronbikes@cyberplace.social
                          wrote last edited by
                          #13

                          @TomSellers @bws @cR0w that second one is definitely part of the advisory. Fun will be had by all.

                          1 Reply Last reply
                          0
                          • tomsellers@infosec.exchangeT tomsellers@infosec.exchange

                            @huronbikes @bws @cR0w

                            I actually came here to make a joke about that because there are TWO similarly named controllers:

                            • Ingress NGINX Controller: deprecated, owned by the K8s project
                            • NGINX Ingress Controller: still alive, owned by F5
                            rootwyrm@weird.autosR This user is from outside of this forum
                            rootwyrm@weird.autosR This user is from outside of this forum
                            rootwyrm@weird.autos
                            wrote last edited by
                            #14

                            @TomSellers @huronbikes @bws @cR0w don't forget the dozens of OTHER 'nginx controllers' offered various places.

                            1 Reply Last reply
                            0
                            • cr0w@infosec.exchangeC cr0w@infosec.exchange

                              Oh.

                              myF5

                              favicon

                              (my.f5.com)

                              eruonna@lgbtqia.spaceE This user is from outside of this forum
                              eruonna@lgbtqia.spaceE This user is from outside of this forum
                              eruonna@lgbtqia.space
                              wrote last edited by
                              #15

                              @cR0w maybe I should be happy they laid me off last year

                              cr0w@infosec.exchangeC 1 Reply Last reply
                              0
                              • eruonna@lgbtqia.spaceE eruonna@lgbtqia.space

                                @cR0w maybe I should be happy they laid me off last year

                                cr0w@infosec.exchangeC This user is from outside of this forum
                                cr0w@infosec.exchangeC This user is from outside of this forum
                                cr0w@infosec.exchange
                                wrote last edited by
                                #16

                                @eruonna Oof, IDK about that but I get it.

                                1 Reply Last reply
                                0
                                • huronbikes@cyberplace.socialH huronbikes@cyberplace.social

                                  @bws @cR0w EOL works so well certain former employers are definitely not using Windows Server 2012 in 2026. For critical business functionality. Very often.

                                  nosirrahsec@infosec.exchangeN This user is from outside of this forum
                                  nosirrahsec@infosec.exchangeN This user is from outside of this forum
                                  nosirrahsec@infosec.exchange
                                  wrote last edited by
                                  #17

                                  @huronbikes @bws @cR0w I've definitely never seen a Server 2012 in production.

                                  Nope.

                                  That would be CRAZY since it's EOL.

                                  1 Reply Last reply
                                  0
                                  • huronbikes@cyberplace.socialH huronbikes@cyberplace.social

                                    @cR0w "the bigger the BIG-IP, the bigger the CVE!" as the old saying goes

                                    fritzadalis@infosec.exchangeF This user is from outside of this forum
                                    fritzadalis@infosec.exchangeF This user is from outside of this forum
                                    fritzadalis@infosec.exchange
                                    wrote last edited by
                                    #18

                                    @huronbikes @cR0w @cR0w
                                    Isn't Big Ip that one Peter Gabriel song?

                                    1 Reply Last reply
                                    1
                                    0
                                    Reply
                                    • Reply as topic
                                    Log in to reply
                                    • Oldest to Newest
                                    • Newest to Oldest
                                    • Most Votes


                                    • Login

                                    • Login or register to search.
                                    • First post
                                      Last post
                                    0
                                    • Categories
                                    • Recent
                                    • Tags
                                    • Popular
                                    • World
                                    • Users
                                    • Groups