home.social

#pixelsmash — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pixelsmash, aggregated by home.social.

fetched live
  1. dont panic people. aslr is there to protect you, ffmpeg exploit only works without aslr. aslr is enabled by default on modern systems!

    to check on linux:
    cat /proc/sys/kernel/randomize_va_space

    should be 2 (OK)
    #ffmpeg #PixelSmash
  2. dont panic people. aslr is there to protect you, ffmpeg exploit only works without aslr. aslr is enabled by default on modern systems!

    to check on linux:
    cat /proc/sys/kernel/randomize_va_space

    should be 2 (OK)
    #ffmpeg #PixelSmash
  3. dont panic people. aslr is there to protect you, ffmpeg exploit only works without aslr. aslr is enabled by default on modern systems!

    to check on linux:
    cat /proc/sys/kernel/randomize_va_space

    should be 2 (OK)
    #ffmpeg #PixelSmash
  4. "If you provide a network-based service and explicitly disable standard security measures, people can remotely hack into your system!"

    "If you post the location of your spare key online, people from all over the country can come and rob your house!"

    #ffmpeg #PixelSmash #ASLR

  5. "If you provide a network-based service and explicitly disable standard security measures, people can remotely hack into your system!"

    "If you post the location of your spare key online, people from all over the country can come and rob your house!"

    #ffmpeg #PixelSmash #ASLR

  6. "If you provide a network-based service and explicitly disable standard security measures, people can remotely hack into your system!"

    "If you post the location of your spare key online, people from all over the country can come and rob your house!"

    #ffmpeg #PixelSmash #ASLR

  7. "If you provide a network-based service and explicitly disable standard security measures, people can remotely hack into your system!"

    "If you post the location of your spare key online, people from all over the country can come and rob your house!"

    #ffmpeg #PixelSmash #ASLR

  8. "If you provide a network-based service and explicitly disable standard security measures, people can remotely hack into your system!"

    "If you post the location of your spare key online, people from all over the country can come and rob your house!"

    #ffmpeg #PixelSmash #ASLR

  9. 🚨 ‼️ Pixelfed + Loops Admins PSA ⚠️

    You need to update ffmpeg to v8.1.2+ ASAP.

    We made a guide for Ubuntu ⬇️

    gist.github.com/dansup/460039b

    Please boost for visibility, this also affects other fediverse software, and this guide may help those admins too.

    See jfrog.com/blog/pixelsmash-crit for more details about the vulnerability.

    #ffmpeg #pixelsmash

  10. 🚨 ‼️ Pixelfed + Loops Admins PSA ⚠️

    You need to update ffmpeg to v8.1.2+ ASAP.

    We made a guide for Ubuntu ⬇️

    gist.github.com/dansup/460039b

    Please boost for visibility, this also affects other fediverse software, and this guide may help those admins too.

    See jfrog.com/blog/pixelsmash-crit for more details about the vulnerability.

    #ffmpeg #pixelsmash

  11. 🚨 ‼️ Pixelfed + Loops Admins PSA ⚠️

    You need to update ffmpeg to v8.1.2+ ASAP.

    We made a guide for Ubuntu ⬇️

    gist.github.com/dansup/460039b

    Please boost for visibility, this also affects other fediverse software, and this guide may help those admins too.

    See jfrog.com/blog/pixelsmash-crit for more details about the vulnerability.

    #ffmpeg #pixelsmash

  12. 🚨 ‼️ Pixelfed + Loops Admins PSA ⚠️

    You need to update ffmpeg to v8.1.2+ ASAP.

    We made a guide for Ubuntu ⬇️

    gist.github.com/dansup/460039b

    Please boost for visibility, this also affects other fediverse software, and this guide may help those admins too.

    See jfrog.com/blog/pixelsmash-crit for more details about the vulnerability.

    #ffmpeg #pixelsmash

  13. 🚨 ‼️ Pixelfed + Loops Admins PSA ⚠️

    You need to update ffmpeg to v8.1.2+ ASAP.

    We made a guide for Ubuntu ⬇️

    gist.github.com/dansup/460039b

    Please boost for visibility, this also affects other fediverse software, and this guide may help those admins too.

    See jfrog.com/blog/pixelsmash-crit for more details about the vulnerability.

    #ffmpeg #pixelsmash

  14. I feel like this is an under-reported limitation to that ffmpeg "PixelSmash" vulnerability: Their proof-of-concept exploit only works with ASLR disabled. Which, on any modern system, really shouldn't be the case.

    jfrog.com/blog/pixelsmash-crit

    #ffmpeg #PixelSmash #ASLR

  15. I feel like this is an under-reported limitation to that ffmpeg "PixelSmash" vulnerability: Their proof-of-concept exploit only works with ASLR disabled. Which, on any modern system, really shouldn't be the case.

    jfrog.com/blog/pixelsmash-crit

    #ffmpeg #PixelSmash #ASLR

  16. I feel like this is an under-reported limitation to that ffmpeg "PixelSmash" vulnerability: Their proof-of-concept exploit only works with ASLR disabled. Which, on any modern system, really shouldn't be the case.

    jfrog.com/blog/pixelsmash-crit

    #ffmpeg #PixelSmash #ASLR

  17. I feel like this is an under-reported limitation to that ffmpeg "PixelSmash" vulnerability: Their proof-of-concept exploit only works with ASLR disabled. Which, on any modern system, really shouldn't be the case.

    jfrog.com/blog/pixelsmash-crit

    #ffmpeg #PixelSmash #ASLR

  18. I feel like this is an under-reported limitation to that ffmpeg "PixelSmash" vulnerability: Their proof-of-concept exploit only works with ASLR disabled. Which, on any modern system, really shouldn't be the case.

    jfrog.com/blog/pixelsmash-crit

    #ffmpeg #PixelSmash #ASLR

  19. I find it weird calling the recent FFmpeg security vulnerability a RCE [1]. Where is that remote coming from?
    Yes sure, some web applications use FFmpeg and passes untrusted files to it. *Those* have a RCE.
    Setting the CVSS attack vector to "network" seems overinflating.

    By that standard any software that somebody built a webapp around is "network" facing.

    And let's not even talk about setting attack complexity to "low" but admitting that it only works with ASLR disabled.

    [1] jfrog.com/blog/pixelsmash-crit

    #FFmpeg #vulnerability #infosec #PixelSmash

  20. I find it weird calling the recent FFmpeg security vulnerability a RCE [1]. Where is that remote coming from?
    Yes sure, some web applications use FFmpeg and passes untrusted files to it. *Those* have a RCE.
    Setting the CVSS attack vector to "network" seems overinflating.

    By that standard any software that somebody built a webapp around is "network" facing.

    And let's not even talk about setting attack complexity to "low" but admitting that it only works with ASLR disabled.

    [1] jfrog.com/blog/pixelsmash-crit

    #FFmpeg #vulnerability #infosec #PixelSmash

  21. I find it weird calling the recent FFmpeg security vulnerability a RCE [1]. Where is that remote coming from?
    Yes sure, some web applications use FFmpeg and passes untrusted files to it. *Those* have a RCE.
    Setting the CVSS attack vector to "network" seems overinflating.

    By that standard any software that somebody built a webapp around is "network" facing.

    And let's not even talk about setting attack complexity to "low" but admitting that it only works with ASLR disabled.

    [1] jfrog.com/blog/pixelsmash-crit

    #FFmpeg #vulnerability #infosec #PixelSmash

  22. I find it weird calling the recent FFmpeg security vulnerability a RCE [1]. Where is that remote coming from?
    Yes sure, some web applications use FFmpeg and passes untrusted files to it. *Those* have a RCE.
    Setting the CVSS attack vector to "network" seems overinflating.

    By that standard any software that somebody built a webapp around is "network" facing.

    And let's not even talk about setting attack complexity to "low" but admitting that it only works with ASLR disabled.

    [1] jfrog.com/blog/pixelsmash-crit

    #FFmpeg #vulnerability #infosec #PixelSmash

  23. I find it weird calling the recent FFmpeg security vulnerability a RCE [1]. Where is that remote coming from?
    Yes sure, some web applications use FFmpeg and passes untrusted files to it. *Those* have a RCE.
    Setting the CVSS attack vector to "network" seems overinflating.

    By that standard any software that somebody built a webapp around is "network" facing.

    And let's not even talk about setting attack complexity to "low" but admitting that it only works with ASLR disabled.

    [1] jfrog.com/blog/pixelsmash-crit

    #FFmpeg #vulnerability #infosec #PixelSmash