Skip Navigation
4 exploits, 1 bug: exploiting CVE-2024-20017 4 different ways
blog.coffinsec.com 4 exploits, 1 bug: exploiting CVE-2024-20017 4 different ways

a post going over 4 exploits for CVE-2024-20017, a remotely exploitable buffer overflow in a component of the MediaTek MT7622 SDK.

0
Lemmy Development Update 2024-09-20
  • This is sso support as the client. So you could use any backend that supports the oauth backend (I assume, didn't look at it yet).

    So you could use a forgejo instance, immediately making your git hosting instance a social platform, if you wanted.
    Or use something as self hostable like hydra.

    Or you can use the social platforms that already exist such as Google or Microsoft. Allowing faster onboarding to joining the fediverse. While allowing the issues that come with user creation to be passed onto a bigger player who already does verification. All of these features are up for your instance to decide on.
    The best part, if you don't agree with what your instance decides on, you can migrate to one that has a policy that coincides with your values.

    Hope that gives you an idea behind why this feature is warranted.

  • Are we falling behind Lemmy.World again?
  • Possibly, as it's one generic endpoint, but it also blocked a few other things people in the fediverse created, which are mighty helpful in diagnosis of these and other issues.

    So using some AI model or whatever CF uses is probably not going to be the best thing for us as it classified a POST request as a crawler?? ๐Ÿคท

    I'd have to whitelist every regular endpoint as well and then it gets messy as CF only gives you so much control as a free user.

    So, for the moment I've blocked the most annoying ones based on UserAgent.

  • Are we falling behind Lemmy.World again?
  • We enabled the CloudFlare AI bots and Crawlers mode around 0:00 UTC (20/Sept).

    This was because we had a huge number of AI scrapers that were attempting to scan the whole lemmyverse.

    It successfully blocked them... While also blocking federation ๐Ÿ˜ด

    I've disabled the block. Within the next hour we should see federation traffic come through.

    Sorry for the unfortunate delay in new posts!

    Tiff

  • latchset/clevis: Automated Encryption Framework
    github.com GitHub - latchset/clevis: Automated Encryption Framework

    Automated Encryption Framework. Contribute to latchset/clevis development by creating an account on GitHub.

    GitHub - latchset/clevis: Automated Encryption Framework

    to be paired with tang

    0
    'Big, massive deterrent': Social media companies could face fines for allowing kids under 14 on their platforms
    www.abc.net.au 'Big, massive deterrent': Social media companies could face fines for allowing kids under 14 on their platforms

    Social media giants would be forced to ban children under the age of 14 from their platforms or face hefty penalties, under proposed laws in South Australia that could be replicated in other states.

    'Big, massive deterrent': Social media companies could face fines for allowing kids under 14 on their platforms

    Highly relevant to us (as admins)

    22
    broadcast-box: A broadcast, in a box.
    github.com GitHub - Glimesh/broadcast-box: A broadcast, in a box.

    A broadcast, in a box. . Contribute to Glimesh/broadcast-box development by creating an account on GitHub.

    GitHub - Glimesh/broadcast-box: A broadcast, in a box.

    Not so much a sploit but an easy way to do broadcasting!

    0
    no power, no internet, but still have coffee (and a battery pack)
  • I can neither confirm or deny for the safety of my pigeons.

  • Hacking a Virtual Power Plant
    rya.nc Hacking a Virtual Power Plant

    I recently had solar panels and a battery storage system from GivEnergy installed at my house. A major selling point for me was that they have a local network API which can be used to monitor andโ€ฆ

    Hacking a Virtual Power Plant
    0
    test post with new patch with backported fixes
  • I"M A MOD LOOK AT ME

  • Tony Hawk's Pro Strcpy
    icode4.coffee Tony Hawk's Pro Strcpy

    Tony Hawk's Pro Strcpy: A game save and RCE exploit for the Tony Hawk game series that can be used to hack Xbox, Playstation 2, Gamecube, and Xbox 360 consoles.

    Tony Hawk's Pro Strcpy
    0
    Secure Boot is completely broken on 200+ models from 5 big device makers
    arstechnica.com Secure Boot is completely broken on 200+ models from 5 big device makers

    Keys were labeled "DO NOT TRUST." Nearly 500 device models use them anyway.

    Secure Boot is completely broken on 200+ models from 5 big device makers

    An article from July, but I bet you haven't updated your bios! Or you left it open on purpose?

    3
    Technical Details on July 19, 2024 Outage | CrowdStrike
  • Yeah that's why I included the other "main posts"... Their technical details really didn't say anything technical

  • Technical Details on July 19, 2024 Outage | CrowdStrike
    www.crowdstrike.com Technical Details on July 19, 2024 Outage | CrowdStrike

    Learn more about the July 19, 2024 CrowdStrike outage and the technical details related to it.

    Technical Details on July 19, 2024 Outage | CrowdStrike

    The update that broke half of all enterprise servers. One of the official remediation steps is to "Reboot as many as 15 times"

    Read more: https://community.intel.com/t5/Intel-vPro-Platform/Remediate-CrowdStrike-Falcon-update-issue-on-Windows-systems/m-p/1616593/thread-id/11795

    • https://old.reddit.com/r/crowdstrike/comments/1e6vmkf/bsod_error_in_latest_crowdstrike_update/
    • https://repost.aws/en/knowledge-center/ec2-instance-crowdstrike-agent
    • https://azure.status.microsoft/en-gb/status
    3
    unRAID v7!
  • Ah. I see you too enjoy the debian approach

  • [Bug] Crossposts do not work
  • This should be fixed as we rolled out 0.19.5 today

  • Mozilla Welcomes Anonym: Privacy Preserving Digital Advertising | The Mozilla Blog
  • Oh I was wrong, after further reading this looks to be a lot better than what I was thinking.

    I must have been thinking about another methodology of attempted privacy over a dataset.

  • Mozilla Welcomes Anonym: Privacy Preserving Digital Advertising | The Mozilla Blog
  • Before I start reading, if this has anything to do with differential privacy, I'm going to be disappointed.

  • Is it okay to post images to Reddthat directly, or is better to use an image hoster like catbox.moe?
  • Yes, you can upload images to Reddthat when posting, commenting, etc.

    We have a CDN In front and aggressively cache all of the images.

    3rd party images are fetched to generate a thumbnail, and to cache the image. The problem with this is, catbox can be slow at times and if that happens when you post it can't generate them.
    Some clients also only open the direct links instead of showing the cached image, resulting in images not loading, or taking forever to load.

    I say if you are posting on Reddthat, I'm happy for people to use the features provided by Reddthat. So upload here, if you so wish.

    Just remember that the images you upload are linked to your account.

  • Lemmy v0.19.4 Release - Image Proxying and Federation improvements
  • A faster db. Just the regular performance benefits, https://www.postgresql.org/about/news/postgresql-16-released-2715/

    Also, Lemmy is built against v16 (now) so at some point it will eventually no longer JustWork

  • Lemmy v0.19.4 Release - Image Proxying and Federation improvements
  • The script will be useless to you, besides for referencing what to do.

    Export, remove pg15, install pg16, import. I think you can streamline with both installed at once as they correctly version. You could also use the in place upgrade. Aptly named: pg_upgradeclusters

    But updating to 0.19.4, you do not need to go to pg16... but... you should, because of the benefits!

  • [Solved] [Bug] Clicking on suggested title for a link doesn't add the title
  • This should be fixed now. After a re-deploy of 0.19.4 (as they repushed it ~6h after the initial tag)

  • [Solved] [Bug] Emoji button not working
  • We re-deployed 0.19.4 which had fixes. The emoji popup now shows up (for me on mobile)

  • Hacking Millions of Modems (and Investigating Who Hacked My Modem)
    samcurry.net Hacking Millions of Modems (and Investigating Who Hacked My Modem)

    Two years ago, something very strange happened to me while working from my home network. I was exploiting a blind XXE vulnerability that required an external HTTP server to smuggle out files, so I spun up an AWS box and ran a simple Python webserver to receive the traffic from the vulnerable server.

    Hacking Millions of Modems (and Investigating Who Hacked My Modem)

    Unbelievable...

    3
    Post 2 via default ui

    Every language is allowed here? Did you know that

    0
    posters are back

    Double posts are bad mmmhmmm k

    0
    ticoombs Tiff @reddthat.com

    Self Proclaimed Internet user and Administrator of Reddthat

    Posts 99
    Comments 166
    Moderates