Touching Apache HTTP Server since I was 12.
SQL since I was 15.
I'm also a "SQL expert" and can prove it.
Feel free to tag me with your DevOps/Platform/K8s questions!
AWS/GCP/Azure/DigitalOcean/Hetzner
Python/C#
#kubernetes #kubeadm #devops #platform #k8s
#kubernetes #kubeadm #devops #platform #k8s
#swag #hyderabad #devops #databases #postgres #sql #pgedge #aws #samosas
#swag #hyderabad #devops #databases #postgres #sql #pgedge #aws #samosas
I am back to being on a version that's soon to be unsupported.
I am back to being on a version that's soon to be unsupported.
#ATmosphereConf feedback form is live, let me know what you think!
Read the info at atprotocol.dev/atmosphereco... and please fill out the form to give feedback
#ATmosphereConf
#ATmosphereConf feedback form is live, let me know what you think!
#devbox #nix #nixhub
The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().
It's RCE, not auth bypass, and gated/unreplayable.
Looks like this got caught by chance. Wonder how long it would have taken otherwise.
www.openwall.com/lists/oss-se...
It has everything: malicious upstream, masterful obfuscation, detection due to performance degradation, inclusion in OpenSSH via distro patches for systemd support…
Now I’m curious what it does in RSA_public_decrypt
The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().
It's RCE, not auth bypass, and gated/unreplayable.
if anyone on the team expresses dismay at this, we say "what do you work at google?" and press the button
if anyone on the team expresses dismay at this, we say "what do you work at google?" and press the button