https://www.cve.org/CVERecord?id=CVE-2024-29937
> RCE in OpenBSD NFS server
Imagine the damage it would do if anyone actually used the meme OS in production.
Tip Your Landlord Shirt $21.68 |
DMT Has Friends For Me Shirt $21.68 |
Tip Your Landlord Shirt $21.68 |
What is RCE?
Remote
Comething
Exploit
Remote code execution.
Thanks, FBI.
Rectal Cavern Enjoyer
Did they publish anything other than an easily faked youtube video?
That is a teaser trailer, and I also thought it was hilariously bad.
I wouldnt be surprised if theyre for real, but I also wouldn't be surprised if they are full of shit. People claim to do stuff all the time, and openBSD is pretty battle tested. Time will tell what the real story is.
>teaser trailer for a rce
Heartbleed was a massive fricking mistake.
>https://t2.fi/schedule/2024/#speech5
>https://www.signedness.org/misc/
I'm assuming this only works over a local network if it does work. NFS is weird in general lol, prolly they are on to something. Doesn't make sense to me it would affect OpenBSD and not most linux distros though.
>Doesn't make sense to me it would affect OpenBSD and not most linux distros though.
Aren't they completely separate implementations?
Linux has a more battle tested and audited implementation of NFS, considering how much more people use it.
Only two remote holes in the default install, in a heck of a long time!
>heartbleed
>holey for over a decade.
It isn't by chance.
Umm sweaty NFS is not enabled by default in the default install so it doesn't count :^)
Daily reminder that OpenBSD approach to security is is just implement a bunch of esoteric meme mitigations without any kind of threat model behind.
Any shit Linux box with MAC like AppArmor, SELinux or TOMOYO are way more secure.
NFS is brain damage. It's never used in production apart from some neckbeard's "homelab". This is a nothingburger.
?feature=shared
What's this terminal? Looks cool
Cool-retro-term
Why is the security scene so clownish that looks like they are characters in a show about hackers written by people that don't understand computers?
If you could rock that look at your day job wouldn't you jump at the chance?
RED ALERT
DEPLOY THE jerking off MONKEYS
THIS IS NOT A DRILL
Fake and gay.
freebsd won