Vulnerability only affects SMB servers using the experimental ksmbd module (Intro'd in Linux 5.15). If your SMB server uses Samba, you're safe. If it uses ksmbd, an attacker with read access could leak your server's memory (similar to Heartbleed). https://t.co/xw7eOlJo8Q
All I want want for Christmas is no coordinated public release of a unauthenticated #RCE#vulnerability impacting a large amount of systems.
But here we go again:
https://t.co/taEQeSL9Ox
#linux CVSS score 10.0
#ZDI-22-1690
⚠️ Censys is tracking a critical vulnerability that has been found in applications using OpenSSL version 3.0.0 and above. Learn more about the potential impact and how to identify vulnerable hosts in our latest blog: https://t.co/57WrK4iEvf
#OpenSSL
The measure of a security team is what they say when you ask them:
What’s currently facing the internet?
How many total systems do you have?
Where is your data?
How many vendors do you have?
Which vendors have what kind of your data?
@GrahamHelton3 We had a finding in the pen test report about TLS v1.1 being allowed.
They checked password length requirements and made recommendations about authentication.
But missing MFA was not a finding.
It is a crazy world out there.
@DebugPrivilege Remove winpcap as the default install option. Upgrade path for old installations ;)
To be fair: I haven’t checked in the last months, but it was such a pain for our admins when we found this… guess we are not alone.
I guess this is why MSRC still don't consider Admin -> Kernel a security boundary.... I guess they prioritized shipped a new shittier UI and forcing TPM requirements over basic security features they've been crowing about for years.
@curi0usJack It is nice concept for conversion scripts, but not for simple renaming.
The rename command is your friend. It works with regular expressions.
rename ‘s/raw$/txt/‘ *.raw
Run it with -n for a dry run
@campuscodi@ConfigMgrDogs Maybe it stores multiple hashes (last character, two last character, …) and the if the last char of my password is entered it goes back one character at a time. But that sounds like you could trace smartscreen. when it performs more steps you know the another char was correct
Asking how to get int #InfoSec is the same thing as asking how to work with cars.
It is not specific enough.
Do you want to design, build, ship, sell, drive, repair, or scrap cars?
If you know what you want it becomes easier to recommend a learning path.