CandidDevOps

13.3K posts

CandidDevOps

CandidDevOps

@CandidDevOps

Entrou em Mayıs 2018
918 Seguindo205 Seguidores
Weston Walker
Weston Walker@westonlwalker·
You can detect Copy Fail exploitation with the following auditd rules: -a always,exit -F arch=b64 -S bind -F a2=88 -F key=alg_bind -a always,exit -F arch=b64 -S setsockopt -F a1=279 -F key=alg_setsockopt The exploit binds to this saddr once for each 4 bytes of the shellcode. So, if you see like 30-40 of these, it's probably a bad guy. #DetectionEngineering
Weston Walker tweet media
English
2
24
94
6.9K
Chris Frazier
Chris Frazier@chrisfrazier0·
@N104AP Because it’s just Wireguard? The entire system, even their paid offering is just free tools that you can run yourself…
English
1
0
10
2.3K
Ellie Winters
Ellie Winters@N104AP·
how the fuck is tailscale free for personal use
English
65
24
1.4K
93.3K
CandidDevOps
CandidDevOps@CandidDevOps·
@N104AP You only load their servers for negotiation.
English
0
0
0
888
Lilith Datura
Lilith Datura@LilithDatura·
@theo That Linux zero day seemed like it was played down yesterday and it should not have been
English
2
0
2
278
Theo - t3.gg
Theo - t3.gg@theo·
cPanel, lightning (on PyPi), and intercom-client (on npm) were all pwn’d in the last 24 hours. We also had a brutal Linux zero day go public. I fear this is only the beginning.
English
66
109
1.7K
82.8K
CandidDevOps
CandidDevOps@CandidDevOps·
@GrowlerEnjooyer @ShamashAran It is nontrivial to execute anything on hosts that are properly secured. It's nontrivial when it requires a system to already be compromised.
English
1
0
0
7
TJ Berke
TJ Berke@tpatfeld·
@HeidiBriones What about those of us who identify way more as Gen X but are cut off by like 1 measley year. I am not a millennial 🥺
English
3
0
0
19
Heidi
Heidi@HeidiBriones·
I love when millennials are like "omg, I can't understand Gen Z." Yeah, no shit, that's because we're in a different generation.
English
14
1
46
1.6K
CandidDevOps
CandidDevOps@CandidDevOps·
@GrowlerEnjooyer @ShamashAran An actual example of "trivially exploitable" dumbass: x.com/IntCyberDigest…
International Cyber Digest@IntCyberDigest

🚨 BREAKING: cPanel and WHM, the control panels behind an estimated 70+ million websites, have a critical security flaw that lets anyone become root admin without a password. CVE-2026-41940 affects every supported version. It’s already being exploited in the wild. watchTowr Labs published the full attack today, after the hosting company KnownHost confirmed the bug was already being used to break into a significant chunk of the internet. If you've never heard of cPanel: it's the dashboard that hosting providers and millions of website owners use to manage their servers, domains, email accounts, databases, and SSL certificates. WHM is the admin version that controls the entire server. If someone gets root access to WHM, they get the keys to the kingdom and to every apartment inside it. How the attack works, in plain English: 🔴 Step 1: The attacker sends a deliberately wrong login. cPanel still creates a temporary "you tried to log in" record on disk and gives the attacker a cookie tied to it. 🔴 Step 2: The attacker tweaks the cookie to disable cPanel's password encryption. Normally cPanel encrypts the password field on disk. With one small change to the cookie, cPanel just stores it as plain text instead. 🔴 Step 3: The attacker sends a fake login attempt where the password field secretly contains hidden line breaks. cPanel does not strip these line breaks out, so they get written straight to the session file. Each line break creates a brand new fake record. The attacker uses this to inject lines that say "this user is root" and "this user already authenticated successfully." 🔴 Step 4: The attacker visits one more random page on the site to nudge cPanel into re-reading the file. cPanel then promotes the injected fake lines into its main session memory. 🔴 Step 5: On the next request, cPanel sees a flag that says "this user already passed the password check." cPanel trusts that flag, skips checking the actual password, and lets the attacker in as root. From start to finish, the attack takes a handful of HTTP requests. If you run cPanel or WHM, the patched versions are: 🔴 cPanel/WHM 110.0.x → 11.110.0.97 🔴 cPanel/WHM 118.0.x → 11.118.0.63 🔴 cPanel/WHM 126.0.x → 11.126.0.54 🔴 cPanel/WHM 132.0.x → 11.132.0.29 🔴 cPanel/WHM 134.0.x → 11.134.0.20 🔴 cPanel/WHM 136.0.x → 11.136.0.5 If your version is older than these, assume someone has already broken in and act accordingly. Patch right now, then rotate every password and key the server touched: root passwords, API tokens, SSL private keys, SSH keys, mail passwords, and database passwords.

English
1
0
0
13
CandidDevOps
CandidDevOps@CandidDevOps·
@AnnieEaves You are retarded. You don't have better bread. Your definition of better comes from a country that eats the most fucked up shit imaginable. We eat exactly what we want. Name it, and if I wanted it I'd have it.
English
0
0
0
49
Annie Eaves
Annie Eaves@AnnieEaves·
Love how upset and angry Americans are getting about BREAD. They feel it as a personal insult that Europeans have better bread. I am quite happy to admit that bread in France and others places is far better than UK generally. It didn’t hurt my ego to type that.
English
178
13
896
111.7K
free palestine 🇵🇸
free palestine 🇵🇸@eclairification·
the federal minimum wage is still 7.25. I am 34 and have never made more than 20k/yr, rarely more than 15. it’s really important that i, as a working person oppressed by capitalism, follow news and politics coverage written by people paid 6 figures to live in the culture city.
English
549
46
859
1.7M
Lilac Splint Secondary
@CandidDevOps @HeidiBriones @waitbutwhy I mean it is factually true there will be very likely times you need help from people who are not necessarily at risk themselves. Helping you might put them at risk, do you want help or not? Do you want them to be selfless and help you, or leave you in big danger without help?
English
1
0
0
5
Tim Urban
Tim Urban@waitbutwhy·
Everyone in the world has to take a private vote by pressing a red or blue button. If more than 50% of people press the blue button, everyone survives. If less than 50% of people press the blue button, only people who pressed the red button survive. Which button would you press?
English
5.7K
1.4K
13.7K
26.1M
CandidDevOps
CandidDevOps@CandidDevOps·
@ThatOtherMtnJoe @micsolana I did no such thing. 100% of the liability for 100% of any deaths is equally shared among blue button pressers, and only them.
English
0
0
0
7
Your Average Joe
Your Average Joe@ThatOtherMtnJoe·
@CandidDevOps @micsolana You imperil potentially half the world, many of them children, to maybe protect future unborn. What if all the prenatal doctors picked blue?
English
1
0
0
10
Mike Solana
Mike Solana@micsolana·
interesting how completely the conversation has shifted to kids. initially, most people assumed we were talking about adults, not babies smashing buttons, which kind of breaks the thought experiment. that this is all we’re now discussing implies blues understand they were wrong.
notsoErudite@notsoErudite

Since everyone was very curious my answer, my answer is obviously blue. Gotta save the naive, the kids, the blue lovers, and the principally hope-pilled people. You red button pickers need therapy.

English
513
103
2.5K
127.5K
Lilac Splint Secondary
@CandidDevOps @HeidiBriones @waitbutwhy uh.. yes it is? remember, this as a principle applies to things other than this poll. There *will* be choices where someone could save Your life, like someone needing to open their door to save you from a wolf attack. You'd want them to open that door, risking themselves for you.
English
1
0
0
7
Lilac Splint Secondary
@CandidDevOps @HeidiBriones @waitbutwhy I actually think no people dying here *is* one of the nice things we do get to have! Remember, if it went your way, there would have been lives lost. Suffering and death that did not happen at all because Blue won ^-^
English
1
0
0
8
CandidDevOps
CandidDevOps@CandidDevOps·
@1337_n008 @HazelAppleyard Derp. Beating market return on $1 mil is easy. 27.4 push ups / day. I could handle 100 day for another couple decades..
English
0
0
2
74
Hazel Appleyard
Hazel Appleyard@HazelAppleyard·
$10 per push-up or $1 million?
Hazel Appleyard tweet media
English
928
40
5.6K
2.8M
Dylan Barket
Dylan Barket@DowntownDil·
@HazelAppleyard 287 pushups a day to generate $1,050,000 in a year ($1 Million + 5% interest). That’s 29 pushups per hour, 10 hours a day. Probably would take the $10 per pushup.
English
3
0
121
17.3K
CandidDevOps
CandidDevOps@CandidDevOps·
@poiThePoi No, it's not a problem. I do not in fact *need* the oil fracking to be profitable.
English
1
0
0
52
CandidDevOps
CandidDevOps@CandidDevOps·
@Kokulukiyam @micsolana No, I'm simply demonstrating blue button pressers are retarded. Thank you for making it such an effective endeavor.
English
1
0
0
14
Kokulu Kiyam
Kokulu Kiyam@Kokulukiyam·
@CandidDevOps @micsolana Are you arguing for the test to be only for people that can press buttons, or are you just looking for a gotcha? “This 1 day old newborn can hardly press a button so no kids can participate” is the retarded take here.
English
1
0
0
19