Solar Designer

14.4K posts

Solar Designer

Solar Designer

@solardiz

@Openwall founder, @oss_security maintainer, @lkrg_org co-author, @CtrlIQ Linux security engineer. RTs don't imply agreement with points of view.

Katılım Ağustos 2012
1.4K Takip Edilen13.2K Takipçiler
Solar Designer retweetledi
CIQ
CIQ@CtrlIQ·
The CIQ portal is live: access, evaluate, and deploy CIQ products on your own terms. From registration to your first download in under 10 minutes. Personal Use, Free, Developer and Trial licenses are available today, alongside a full product catalog including RLC Pro, RLC Pro Hardened, RLC Pro AI, RLC+, CIQ Bridge, Fuzzball, Ascender Pro, and Warewulf Pro. Start where you are. Scale when you're ready: bit.ly/4bRs2Jc #RLCPro #RockyLinux #Linux #OpenSource #EnterpriseLinux #CIQ
CIQ tweet media
English
0
2
3
373
Solar Designer retweetledi
Open Source Security mailing list
CVE-2026-3888: snap-confine + systemd-tmpfiles = root openwall.com/lists/oss-secu… as discovered by @Qualys Case study: Ubuntu Desktop 24.04 - Analysis - Exploitation Case study: Ubuntu Desktop 25.10 - Overview - Exploitation A quick note on the uutils coreutils (the rust-coreutils)
English
1
4
19
2.3K
Solar Designer retweetledi
Open Source Security mailing list
10+ CVEs in GStreamer openwall.com/lists/oss-secu… a dependency of the tracker-extract package, which GNOME uses to automatically parse metadata in new files. Among other things, this service indexes all files in the user's home directory without any user interaction.
English
0
6
13
3.3K
Solar Designer retweetledi
Open Source Security mailing list
CVE-2005-0488: Some telnet clients still leak environment variables openwall.com/lists/oss-secu… Vulnerable: GNU Inetutils 2.7.33 (Debian, Ubuntu, Termux, ...), FreeBSD 16.0-CURRENT, NetBSD 11.0-RC2, Solaris 11.4. By-design partial leakage: OpenBSD 7.8. Abuse via telnet:// URI scheme.
English
0
1
5
1.6K
Solar Designer retweetledi
Open Source Security mailing list
AppArmor vulnerabilities openwall.com/lists/oss-secu… Confused deputy - Removing, loading a profile - Bypassing Ubuntu's user-namespace restrictions AppArmor+Sudo+Postfix = root Kernel - Uncontrolled recursion - Out-of-bounds read - Use-after-free - Double-free x.com/qualys/status/…
Qualys@qualys

Qualys Threat Research Unit (TRU) discovered CrackArmor: 9 AppArmor flaws impacting 12M+ Linux systems since 2017. These enable root access & container breakouts. Patch your kernels now! Details: bit.ly/4s2c3O4 #Linux #Cybersecurity #CrackArmor"

English
1
5
10
2.8K
Solar Designer retweetledi
Open Source Security mailing list
CVE-2026-3497: OpenSSH GSSAPI Key Exchange patch issue openwall.com/lists/oss-secu… Many Linux distros carry this patch on top of OpenSSH. Affects servers with "GSSAPIKeyExchange yes". Triggered by single tiny crafted SSH packet, no authentication or credentials needed. Impact varies.
English
0
1
6
1.2K
Solar Designer retweetledi
Openwall
Openwall@Openwall·
passwdqc 2.1.0 is out, adding built-in common passwords list. We effectively include top 100k of HIBPv8 overlap with RockYou, optimized and compressed to under 200 KB embedded in program binary. None of JtR password.lst 1.8 million are accepted by default. openwall.com/lists/announce…
Openwall@Openwall

passwdqc 2.0.3 releases for Unix-like and Windows systems are out, with many minor additions and changes. Leaked password filter files updated to HIBP v8, encoding the 847+ million unique passwords (from billions of accounts) in a 3.5 GB file. openwall.com/lists/announce…

English
0
5
17
2.2K
Solar Designer retweetledi
Open Source Security mailing list
Open Source Security mailing list@oss_security·
Telnetd Vulnerability Report openwall.com/lists/oss-secu… Rediscoveries in InetUtils beyond last month's froot. Incomplete fix of CVE-1999-0073, where the CVE description's example was LD_LIBRARY_PATH, but new LPE PoCs use CREDENTIALS_DIRECTORY and GCONV_PATH. Avoided in Linux NetKit?
English
0
2
5
853
Solar Designer retweetledi
Open Source Security mailing list
Open Source Security mailing list@oss_security·
OpenSC, ghostscript, cgif issues from the recent Anthropic disclosure openwall.com/lists/oss-secu… Anthropic say they found 500+ vulnerabilities and list 3 of them. These 3 don’t appear to have CVEs and 2 don’t appear in releases. Maintainers may not agree with the significance.
English
0
2
4
1.1K
Solar Designer retweetledi
Open Source Security mailing list
Open Source Security mailing list@oss_security·
As blogged by @trailofbits, two popular AES libraries, aes-js and pyaes, “helpfully” provide a default IV in their AES-CTR API, leading to a large number of key/IV reuse bugs. These bugs potentially affect thousands of downstreams. openwall.com/lists/oss-secu… x.com/trailofbits/st…
Trail of Bits@trailofbits

Two AES libraries ship a default IV that guarantees key reuse. 700K+ repos depend on aes-js alone. A developer flagged the problem years ago, but it was never fixed. 🧵

English
1
4
13
3.4K
Brad Spengler
Brad Spengler@spendergrsec·
but not when you can't even see what you should be able to connect to (especially so when the same id can be reused by local mode containers).
English
1
0
1
251
Solar Designer retweetledi
Lexfo
Lexfo@LexfoSecurite·
Introducing sshimpanzee, a reverse shell made by @TitouanLazard based on openssh's sshd. It supports DNS, ICMP and HTTP encapsulation as well as SOCKS and HTTP Proxies : blog.lexfo.fr/sshimpanzee.ht…
English
0
38
97
17.7K
Solar Designer retweetledi
Open Source Security mailing list
Open Source Security mailing list@oss_security·
zlib security audit by @7aSecurity openwall.com/lists/oss-secu… 10 issues, 1 High "Heap Buffer Overflow via Legacy gzprintf Implementation", which "seems to require that zlib was built with -DNO_vsnprintf -DNO_snprintf, targeting a system lacking snprintf." x.com/7aSecurity/sta…
7ASecurity@7aSecurity

📢New 7ASecurity public #securityaudit report 🔒@zlib strengthened through a whitebox security audit by 7ASecurity. 10 findings. 100% fixed. What was uncovered? Read & share your feedback! 🔗7asecurity.com/blog/2026/02/z… #CyberSecurity #opensource #zlib #appsec #infosec

English
0
4
7
1.6K
Solar Designer retweetledi
Open Source Security mailing list
Open Source Security mailing list@oss_security·
CVE-2026-25646: libpng: Heap buffer overflow openwall.com/lists/oss-secu… in png_set_quantize when called with no histogram and a palette larger than twice the requested maximum number of colors. Images that trigger this vulnerability are valid per the PNG specification. Fix in 1.6.55
English
0
8
30
3.9K
Solar Designer retweetledi
Open Source Security mailing list
CVE-2026-23906: Apache Druid: Authentication Bypass via LDAP Anonymous Bind openwall.com/lists/oss-secu… by providing an existing username with an empty password. Immediate Mitigation: Disable anonymous bind on your LDAP server. Resolution: Upgrade to version 36.0.0 or later.
English
0
1
7
1K
Solar Designer retweetledi
Open Source Security mailing list
On patch vs. commit messages openwall.com/lists/oss-secu… PSA: Did you know that it’s unsafe to put code diffs into your commit messages? Such diffs will be applied by patch(1) and git-am(1) as part of the code change! This is how a sleep(1) made it into i3 4.25-2 in Debian unstable.
English
0
2
11
1.4K
Solar Designer retweetledi
Open Source Security mailing list
"systemd vsock sshd" kernel patch fix openwall.com/lists/oss-secu… Every address family in Linux needs to implement its own namespace handling. In 2007, all existing address families got a check to only allow the initial network namespace. AF_VSOCK is newer and never got this check.
English
1
2
9
1.3K