this post was submitted on 23 Sep 2024
39 points (95.3% liked)
Cybersecurity
5754 readers
67 users here now
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
- Be respectful. Everyone should feel welcome here.
- No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
- No Ads / Spamming.
- No pornography.
Community Rules
- Idk, keep it semi-professional?
- Nothing illegal. We're all ethical here.
- Rules will be added/redefined as necessary.
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]
Notable mention to [email protected]
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
So this would probably be SSH related right? Otherwise what would all Linux systems have in common?
My bet is on Systemd.
That’s not all GNU/Linux though. Either the OP doesn’t understand a very common container OS, Alpine, doesn’t use systemd (also Void Linux and others outside the container space) or it’s something else.
Oh that would be baaaad
And unsurprising
How would this be unsurprising? Is systemd known for this kind of thing or something?
https://pwnies.com/systemd-bugs/
Not all Linux's have SSH enabled, especially out of the box.
They have some other posts about IPv6 parsing (also not universal), but that doesnt sound like an "easy" RCE.
If it were SSH though, wouldn't that ALSO include a wider blast radius than just Linux systems?
Like OpenSSH is used all over the damn place, unless I guess there's something specific about the issue that limits it to Linux hosts for some reason?
He claims the blast radius is bigger, not just Linux. He also claims to be in talks with Apple. So the educated guess would still be openssh