Sign in

llstr

@loloster.mastodon.social.ap.brid.gy
13 followers 1 following 102 posts

plagiste herbivore des prairies humides www.mixcloud.com/llstr github.com/loloster [bridged from mastodon.social/@loloster on the fediverse by fed.brid.gy ]

PostsRepliesMedia
Reposted by llstr
Marie Turcan @turcanmarie.bsky.social · 06/10/2026
Un monde parallèle où la préfecture de police parle de « violences » en montrant du serum phy, un foulard, des boules quiès et des paires de lunettes. Lundi dernier, un policier a fracturé la mâchoire d'un adolescent de 14 ans avec un tir de lance-grenade Cougar : www.mediapart.fr/journal/fran...
un tweet de la préfecture de police qui montre le matériel confisqué (lunettes, serum phy et boule quiès) et un message : "Manifester est un droit. La violence ne l’est pas. Avant les rassemblements, les policiers procèdent à des contrôles et saisissent les matériels susceptibles d’être utilisés pour commettre des violences ou des dégradations."
571545997
Reposted by llstr
Hacker Memes @i0null.infosec.exchange.ap.brid.gy · 07/10/2026
every techbro when the ai goes offline
1114
Reposted by llstr
ploum @ploum.mamot.fr.ap.brid.gy · 30/09/2026
— President, the rogue AI has taken control of our nuclear weapons. Armageddon is coming! — We tried everything we could for the last years… Humanity is doomed. Let’s pray. — … — … — Wait… Nothing is happening. The AI has vanished! — We are saved! I wonder who is our saviour! Meanwhile, in a […]
mamot.fr
Original post on mamot.fr
119
Reposted by llstr
bazouzabou @bazouzabou.mstdn.fr.ap.brid.gy · 29/09/2026
"Ils rigolent sur l'augmentation des salaires, ils pleurent pour une vitrine" Paris, 29 septembre 2026. un des meilleur résumé
Ils rigolent sur l'augmentation des salaires, ils pleurent pour une vitrine
029
llstr @loloster.mastodon.social.ap.brid.gy · 06/10/2026
Thin Lizzy, Diddy Levine (Richard Whittaker Mix) www.youtube.com/watch?v=NjDgAZRRP_w
000
llstr @loloster.mastodon.social.ap.brid.gy · 02/10/2026
« Depuis quand on prend aux plus précaires pour laisser les riches en paix ? » www.liberation.fr/economie/social/a…
000
llstr @loloster.mastodon.social.ap.brid.gy · 01/10/2026
« Manuel de survie » lafabrique.fr/manuel-de-survie
lafabrique.fr
000
Reposted by llstr
D. G. Marshall @davidtheeviloverlord.mastodon.social.ap.brid.gy · 24/09/2026
My brother-in-law's laptop stopped working. It's under warranty. So he called #Dell. "Hi! I'm your A.I. assistant. Before I can help you, you have to read me a tiny number from the back of your laptop." He can't read it, he's blind. I read it. The "A.I" has one job. It is very bad at it. I […]
mastodon.social
Original post on mastodon.social
3016
Reposted by llstr
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 23/09/2026
Dan Lorenc at Chainguard posted this statement about #curl on LinkedIn...
We put curl 8.22.0 through an eight-and-a-half-hour automated tree search, about 4,100 tool calls and roughly 190 million tokens of model work (the vast majority cache reads), aimed only at High and Critical outcomes: memory safety on an ASan build across the HTTP/1, HTTP/2, HTTP/3, WebSocket, FTP, IMAP, POP3, SMTP, SMB, LDAP, cookie, and NTLM/Digest/Negotiate parsers under tens of thousands of hostile server responses, plus integrity hunts for TLS verification bypass under an on-path attacker,
STARTTLS and 1implicit-TLS downgrade, cross-handle response confusion, CONNECT tunnel handling, credential leakage through redirects, file writes outside the output directory, and Alt-Svc and HSTS guarantees. Thirty-one lines of attack closed clean with no sanitizer report and no verification
bypass; all that surfaced were three Medium-class edges, one of which the curl team had already fixed on master days before we looked. That outcome is a credit to the project: years of continuous fuzzing, the maintainers' own audits, and a codebase where every server-controlled length is bounded
before use left a persistent automated adversary with nowhere to go. Congratulations to the curl team, and thanks for making our negative result so thoroughly earned.

One note on the token figure: the run log records usage for only about 400 of the turns (18.6 million tokens, 46,500 per turn on average), so the 190 million is that average scaled to the 4,103 tool-call turns.
21614
Reposted by llstr
mx alex tax1a - 2020 (6) @atax1a.infosec.exchange.ap.brid.gy · 18/09/2026
it is safe for a large language model to mix bleach and ammonia in a wet lab, pass it on
014
Reposted by llstr
Claire Billaud :mastodon: @milena-hime.shelter.moe.ap.brid.gy · 17/09/2026
#Writever jour 17 : Base de données La Fédération Intergalactique possédait une immense base de données qui répertoriait tous les systèmes, toutes les planètes et toutes les civilisations, donnant à chacun de ses citoyens une connaissance complète de ce qui les entourait. Une seule planète ne […]
shelter.moe
Original post on shelter.moe
112
llstr @loloster.mastodon.social.ap.brid.gy · 27/06/2026
L’usage de logiciels espions par le renseignement français a plus que doublé en quatre ans www.liberation.fr/societe/police-ju…
000
Reposted by llstr
n1k0 @n1k0.mamot.fr.ap.brid.gy · 23/06/2026
voila faut ça partout
3023
Reposted by llstr
Fritz Adalis @fritzadalis.infosec.exchange.ap.brid.gy · 20/06/2026
So why does Microsoft not make a Copilot for Flight Simulator?
004
Reposted by llstr
Hacker Memes @i0null.infosec.exchange.ap.brid.gy · 17/06/2026
RE: cyberplace.social/@GossiTheDog/1167…
Pun based on tweety bird from Looney Tunes. Tweety on swing in their cage.

Caption: “I forti saw a bweech..i did! i did see a data bweech”
004
Reposted by llstr
Jeff Moss @thedarktangent.defcon.social.ap.brid.gy · 17/06/2026
New #Nginx is out with security fixes, start your upgrades! nginx.org/en/CHANGES #SysAdmin #MastoAdmin
112
Reposted by llstr
raptor @raptor.infosec.exchange.ap.brid.gy · 17/06/2026
A 27-Year-Old Authentication Bypass in #OpenBSD's #PPP Stack blog.argus-systems.ai/blog/openbsd-…
blog.argus-systems.ai
A 27-Year-Old Authentication Bypass in OpenBSD's PPP Stack · Argus Blog
002
llstr @loloster.mastodon.social.ap.brid.gy · 18/06/2026
« Nous sommes dans un monde où la puissance militaire détermine le droit. » Pétrole : «Il n’y aura pas de véritable retour à la normale car l’Iran ne renoncera pas au contrôle du détroit d’Ormuz» […]
mastodon.social
Original post on mastodon.social
000
Reposted by llstr
John Rogers @johnrogers.bsky.social · 12/06/2026
You know in my day, police did the work themselves, carried a drop gun, lied on the stand, planted little baggies of coke, etc. This is just sheer laziness.
1029594
Reposted by llstr
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 11/06/2026
Did you know that in many cultures, it's considered good luck to share your food with a dog? -- the dog
001
llstr @loloster.mastodon.social.ap.brid.gy · 11/06/2026
Le PEIN : « se donner des raisons supplémentaires mais objectives de détester le Ministère de l’Intérieur, nos gouvernants, les technocrates, les startupeurs et bien-sûr son smartphone » lundi.am/Le-portefeuille-d-identite…
lundi.am
Le portefeuille d’identité numérique (PEIN) - Ce projet européen qui rend complotiste
Ce projet européen qui rend complotiste
000
Reposted by llstr
Richard ☠️ Monvoisin @richardmonvoisin.mastodon.social.ap.brid.gy · 03/06/2026
000
Reposted by llstr
Dr. Serge Zaka @sergezaka.bsky.social · 02/06/2026
Comme on le craignait, la canicule de la semaine dernière a provoqué une évapotranspiration inédite pour la période de l’année, se rangeant parmi les plus hautes valeurs jamais observées en France. Résultat : nos réserves hydriques sont déjà mises à mal pour l’été. 1/4
6398199
Reposted by llstr
Tom Stafford @tomstafford.mastodon.online.ap.brid.gy · 02/06/2026
Fedizens! Please send me your favourite meme which shows something important about the #Fediverse I'll go first:
Star wars meme. Empire soldier land to interrogate the retired general. "Mastodon? Really? Man of your talents?". He replies: "It's a peaceful life"

From: https://knowyourmeme.com/memes/its-a-peaceful-life

"It's a Peaceful Life, also known as Really? Man Of Your Talents?, is a reaction image and image macro meme format using a scene from the 2016 film Rogue One: A Star Wars Story in which the character Galen Erso (played by actor Mads Mikkelsen) tells Orson Krennic (Ben Mendelsohn), "It's a peaceful life," after Krennic expresses pitiful shock that Erso is a farmer"
3039211
Reposted by llstr
Xe :verified: @cadey.pony.social.ap.brid.gy · 01/06/2026
"No way to prevent this" say users of only package manager where this regularly happens xeiaso.net/shitposts/no-way-to-prev…
xeiaso.net
"No way to prevent this" say users of only package manager where this regularly happens
Xe Iaso's personal website.
0010
Reposted by llstr
Quixoticgeek @quixoticgeek.v.st.ap.brid.gy · 01/06/2026
Remember. The first pride was a riot.
0215
Reposted by llstr
Tom Gauld @tomgauld.bsky.social · 25/05/2026
My latest books cartoon for @theguardian.com. Many more here: www.theguardian.com/profile/tom-gauld

Panel 1
A small girl and boy are reading on the floor. A father appears at the door and says:
"This is so nice to see! I heard that kids these days weren't reading." 
One of the children says "Ugh, reading? So lame!"

Panel 2
She continues "It's called Booksmaxxing now, Dad!"
He replies as he is leaving "'m just happy you're enjoying it."

Panel 3
The boy says "Booksmaxxing?"
The girl says "I like to mess with him."
121512469
llstr @loloster.mastodon.social.ap.brid.gy · 31/05/2026
« Le seul débouché rentable de l’IA aujourd’hui, ce sont ses applications militaires. » Romaric Godin et Marlène Benquet : «De plus en plus de secteurs de la finance trouvent un intérêt économique à des régimes d’extrême droite» […]
mastodon.social
Original post on mastodon.social
010
Reposted by llstr
Riposte Populaire :antifa: @riposte-pop.piaille.fr.ap.brid.gy · 29/05/2026
Car le meilleur hommage que l’on puisse rendre à notre camarade n’est pas le silence… C’est la poursuite de ses combats. 🔥 Clément. Toujours présent dans nos mémoires. Toujours présent dans nos luttes.🏴‍☠️ 📍 Place de la République, Paris 6 juin 2026 / 12h […] [Original post on piaille.fr]
MARCHE ANTIFASCISTE ET ANTI-IMPERIALISTE

VENEZ MASSIVEMENT REJOINDRE L'APPEL DU 6 JUIN


FACE A LEUR SILENCE, NOTRE RESISTANCE 


Place de la République, Paris
6 juin 2026 / 12h
023
Reposted by llstr
Julianoë @julianoe.mastodon.xyz.ap.brid.gy · 28/05/2026
Vous avez chaud ? Dites vous qu'en 2050 on a 25% de chance de voir les hiver commencer à devenir de plus en plus rigoureux du fait de l'effondrement des courants océaniques marins. 35°C en mai, -25°C en février. Chicago vous passe le bonjour.
202
Reposted by llstr
la_voix @la-voix.mastodon.social.ap.brid.gy · 27/05/2026
#Vidéosurveillance : la vidéosurveillance algorithmique se déploie en #France non seulement dans l’espace public, mais aussi dans les commerces, sans le cadre juridique nécessaire. Des #startups comme #Veesion veesion.io ont lancé une campagne de […] [Original post on mastodon.social]
031
Reposted by llstr
Hacker Memes @i0null.infosec.exchange.ap.brid.gy · 21/05/2026
EVERYONE GETS AN LPE Windows: #BlueHammer (#CVE_2026_33825) #RedSun (#CVE_2026_41091) #UnDefend (#CVE_2026_45498) #WindowsInstaller (#CVE_2026_27910): Linux: #CopyFail (#CVE_2026_31431) #SSHKeysignPwn (#CVE_2026_46333) FreeBSD: #FatGid (#CVE_2026_45250) #ExecveBug (#CVE_2026_7270)
Oprah Meme:
> you get a Windows LPE
> you get a Linux LPE
> you get a FreeBSD LPE
EVERY OS GETS AN LPE
3731
Reposted by llstr
Scary "Grampus" Jerry 👻 @jerry.infosec.exchange.ap.brid.gy · 21/05/2026
There's an RCE vulnerability in nginx, so go patch. There's also another RCE in nginx that hasn't been patched, so commence hand wringing and keep an eye out for the new new patch when it is released.
107
llstr @loloster.mastodon.social.ap.brid.gy · 22/05/2026
RE: mastodon.cloud/@slashdot/1166091823… AI agent ?!
mastodon.cloud
001
llstr @loloster.mastodon.social.ap.brid.gy · 13/05/2026
« So we are the dancing apes » www.youtube.com/watch?v=z8BZd7IBr2Y…
100
Reposted by llstr
Bill @sempf.infosec.exchange.ap.brid.gy · 11/05/2026
Woo. Don't call AI agents "cron jobs" in a meeting of AO bros. They will throw you out the window like on that one web comic meme.
030
Reposted by llstr
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 11/05/2026
#Mythos finds a #curl vulnerability yes, as in singular one. daniel.haxx.se/blog/2026/05/11/myth…
daniel.haxx.se
Mythos finds a curl vulnerability
yes, as in singular _one_. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model _Mythos_ is _dangerously good_ at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead trickle it out to a selected few companies for a while to allow a few good ones(?) to get a head start and fix the most pressing problems first, before the general populace would get their hands on it. The whole world seemed to lose its marbles. Is this the end of the world as we know it? An amazingly successful marketing stunt for sure. ## My (non-) access Part of the deal with _project Glasswing _was that Anthropic also offered access to their latest AI model to “Open Source projects” via Linux Foundation. Linux Foundation let their project Alpha Omega handle this part, and I was contacted by their representatives. As lead developer of curl I was offered access to the magic model and I graciously accepted the offer. Sure, I’d like to see what it can find in curl. I signed the contract for getting access, but then nothing happened. Weeks went past and I was told there was a hiccup somewhere and access was delayed. Eventually, I was instead offered that someone else, who has access to the model, could run a scan and analysis on curl for me using Mythos and send me a report. To me, the distinction isn’t that important. It’s not that I would have a lot of time to explore lots of different prompts and doing deep dive adventures anyway. Getting the tool to generate a first proper scan and analysis would be great, whoever did it. I happily accepted this offer. (I am purposely leaving out the identity of the individual(s) involved in getting the curl analysis done as it is not the point of this blog post.) ## AI scans of curl Before this first Mythos report, we had already scanned curl with several different very capable AI powered tools (I mean _in addition to_ running a number of “normal” static code analyzers all the time, using the pickiest compiler options and doing fuzzing on it for years etc). Primarily AISLE, Zeropath and OpenAI’s Codex Security have been used to scrutinize the code with AI. These tools and the analyses they have done have triggered somewhere between _two and three hundred_ bugfixes merged in curl through-out the recent 8-10 months or so. A bunch of the findings these AI tools reported were confirmed vulnerabilities and have been published as CVEs. Probably a dozen or more. Nowadays we also use tools like GitHub’s Copilot and Augment code to review pull requests, and their remarks and complaints help us to land better code and avoid merging new bugs. I mean, we still merge bugs of course but the PR review bots regularly highlight issues that we fix: our merges would be worse without them. The AI reviews are used _in addition_ to the human reviews. They help us, they don’t replace us. We also see a high volume of high quality security reports flooding in: security researchers now use AI extensively and effectively. Security is a _top_ _priority_ for us in the curl project. We follow every guideline and we do software engineering properly, to reduce the number of flaws in code. Scanning for flaws is just one of many steps to keep this ship safe. You need to search long and hard to find another software project that makes as much or goes further than curl, for software security. Steps involved in keeping curl secure ## May 6, 2026 It was with great anticipation we received the first source code analysis report generated with Mythos. Another chance for us to find areas to improve and bugs to fix. To make an even better curl. This initial scan was made on curl’s git repository and its master branch of a certain recent commit. It counted 178K lines of code analyzed in the src/ and lib/ subdirectories. The analysis details several different approaches and methods it has performed the search, and how it has focused on trying to find which flaws. A fun note in the top of the report says: > curl is one of the most fuzzed and audited C codebases in existence (OSS-Fuzz, Coverity, CodeQL, multiple paid audits). Finding anything in the hot paths (HTTP/1, TLS, URL parsing core) is unlikely. … and it correctly found no problems in those areas. Completely unscientific poll on Mastodon about people’s expectations for Mythos scanning curl ## The size of curl curl is currently 176,000 lines of C code when we exclude blank lines. The source code consists of 660,000 words, which is 12% more words than the entire English edition of the novel War and Piece. On average, every single production source code line of curl has been written (and then rewritten) 4.14 times. We have polished on this. Right now, the existing production code in git master that still remains, has been authored by 573 separate individuals. Over time, a total of 1,465 individuals have so far had their proposed changes merged into curl’s git repository. We have published 188 CVEs for curl up until now. curl is installed in over _twenty million instances_. It runs on over _110 operating systems_ and _28 CPU architectures_. It runs in every smart phone, tablet, car, TV, game console and server on earth. ## Five findings became one The report concluded it found **five** “Confirmed security vulnerabilities”. I think using the term _confirmed_ is a little amusing when the AI says it confidently by itself. Yes, the AI thinks they are confirmed, but the curl security team has a slightly different take. Five issues felt like nothing as we had expected an extensive list. Once my curl security team fellows and I had poked on the this short list for a number of hours and dug into the details, we had trimmed the list down and were left with _one_ confirmed vulnerability. The other four were three false positives (they highlighted shortcomings that are documented in API documentation) and the fourth we deemed “just a bug”. The single confirmed vulnerability is going to end up a _severity low_ CVE planned to get published in sync with our pending next curl release 8.21.0 in late June. The flaw is not going to make anyone grasp for breath. All details of that vulnerability will of course not get public before then, so you need to hold out for details on that. The Mythos report on curl also contained a number of spotted bugs that it concluded were not vulnerabilities, much like any new code analyzer does when you run it on hundreds of thousands of lines of code. All the bugs in the report are being investigated and one bye one we are fixing those that we agree with. All in all about twenty bugs that are described and explained very nicely. Barely any false positives, so I presume they have had a rather high threshold for certainty. curl is certainly getting better thanks to this report, but counted by the volume of issues found, all the previous AI tools we have used have resulted in larger bugfix amounts. This is only natural of course since the first tools we ran had many more and easier bugs to find. As we have fixed issues along the way, finding new ones are slowly becoming harder. Additionally, a bug can be small or big so it’s not always fair to just compare numbers ## Not particularly “dangerous” My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos. Maybe this model is a little bit better, but even if it is, it is not better to a degree that seems to make a significant dent in code analyzing. This is just _one_ source code repository and maybe it is much better on other things. I can only tell and comment on what it found here. ## Still very good But allow me to highlight and reiterate what I have said before: AI powered code analyzers are _significantly_ better at finding security flaws and mistakes in source code than any traditional code analyzers did in the past. All modern AI models are good at this now. Anyone with time and some experimental spirits can find security problems now. The high quality chaos is real. Any project that has not scanned their source code with AI powered tooling will likely find huge number of flaws, bugs and possible vulnerabilities with this new generation of tools. Mythos will, and so will many of the others. Not using AI code analyzers in your project means that you leave adversaries and attackers time and opportunity to find and exploit the flaws you don’t find. ## How AI analyzers differ * They can spot when the comment says something about the code and then conclude that the code does not work as the comment says. * It can check code for platforms and configurations we otherwise cannot run analyzers for * It “knows” details about 3rd party libraries and their APIs so it can detect abuse or bad assumptions. * It “knows” details about protocols curl implements and can question details in the code that seem to violate or contract protocol specifications * They are typically good at summarizing and explaining the flaw, something which can be rather tedious and difficult with old style analyzers. * They can often generate and offer a patch for its found issue (even if the patch usually is not a 100% fix). ## More details from the report **Zero memory-safety vulnerabilities found.** Methodology note: this review is hand-driven analysis using LLM subagents for parallel file reads, with every candidate finding re-verified by direct source inspection in the main session before being recorded. The CVE to variant-hunt mapping was built from curl’s own vuln.json. No automated SAST tooling was used. This outcome is consistent with curl’s status as one of the most heavily fuzzed and audited C codebases. The defensive infrastructure (capped dynbufs everywhere, `curlx_str_number` with explicit max on every numeric parse, `curlx_memdup0` overflow guard, CURL_PRINTF format-string enforcement, per-protocol response-size caps, pingpong 64KB line cap) systematically closes the bug classes that would normally be productive in a codebase this size. Coverage now includes: all minor protocols, all file parsers, all TLS backends’ verify paths, http/1/2/3, ftp full depth, mprintf, x509asn1, doh, all auth mechanisms, content encoding, connection reuse, session cache, CLI tool, platform-specific code, and CI/build supply chain. ## AI finds existing kinds of errors It should be noted that the AI tools find the usual and established kind of errors we already know about. It just finds new instances of them. We have not seen any AI so far report a vulnerability that would somehow be of a novel kind or something totally new. They do not reinvent the field in that way, but they do dig up more issues than any other tools did before. ## More to find These were absolutely not the last bugs to find or report. Just while I was writing the drafts for this blog post we have received more reports from security researchers about suspected problems. The AI tools will improve further and the researchers can find new and different ways to prompt the existing AIs to make them find more. We have not reached the end of this yet. I hope we can keep getting more curl scans done with Mythos and other AIs, over and over until they truly stop finding new problems. ## Credits Thanks to Anthropic and Alpha Omega for providing the model, the tools and doing the scan for us. Thanks also to the individual who did the scan for us. Much appreciated! Top image by Jin Kim from Pixabay Thanks for flying curl. It’s never dull.
7247121
Reposted by llstr
Aram Sinnreich @aram.aoir.social.ap.brid.gy · 10/05/2026
Let's give the absolute worst people on the planet a functionally infinite amount of cash and zero accountability and see what happens
5046
Reposted by llstr
Will Dormann @wdormann.infosec.exchange.ap.brid.gy · 07/05/2026
CopyFail didn't affect Debian 12, and it has been said that this was not intentional, but rather due to an imcomplete backport Interestingly, Debian 12 is also seemingly unaffected by Dirty Frag as well. (But Debian 11 and 13 **are** affected) I'm curious […] [Original post on infosec.exchange]
Debian 12 Dirty Frag failedDebian 11 Dirty Frag successDebian 13 Dirty Frag success
103
Reposted by llstr
Paco Hope @paco.infosec.exchange.ap.brid.gy · 06/05/2026
One of the great things about getting the print version of TheOnion is the ads. Full page mock ads that are just… ouch.
Photo of a full page newspaper ad. It shows a happy, smiling white baby boy holding a small gun that looks like a proportionally shrunk 9mm. The header says “Smith & Wesson Baby Guns” and the tag line says “if you’re gonna bring them into this world, give them a fighting chance.”
0014
Reposted by llstr
Low Quality Facts @lowqualityfacts.mstdn.social.ap.brid.gy · 05/05/2026
Nature is crazy.
Flamingos are white, but often
appear pink because their
feathers are soaked in the
blood of their enemies.
2014
Reposted by llstr
Low Quality Facts @lowqualityfacts.mstdn.social.ap.brid.gy · 06/05/2026
RIP Ted Turner, inventor of the mustache.
"I've invented
a new kind of
facial hair. It's
like a beard,
without all
that chin
bullshit.
"

NEWS NETWORI

-Ted Turner
0216
Reposted by llstr
Daisy Ons Positifs @daisyletourneur.bsky.social · 01/05/2026
Voilà c'est pas dur !
Porte vitrée d'un bar sur laquelle est écrit "fermé le 1er mai pour fêter les droits des travailleuses et des travailleurs arrachés de haute-lutte à la bourgeoisie et au capital.
 fermé aussi le 2 mai aussi parce qu'on est des feignasses"
192802814
Reposted by llstr
Will Dormann @wdormann.infosec.exchange.ap.brid.gy · 01/05/2026
As mentioned earlier in this thread, the `su` corruption route was only one possible strategy to be used by this exploit. Here's another variant of the exploit that doesn't have to rely on such things to achieve its goal. For example, the simple `escalate` […] [Original post on infosec.exchange]

tapioca@fedora:-$ python exploit.py escalate
[*] Copyright (c) 2026, Sndav
[*] This exploit is for educational purposes only
[*] CVE-2026-31431 — Copy Fail
[*] Mode: remove root password via /etc/passwd
[*] Backup: /tmp/.passwd.bak
[*] Before : root:x:0:0:Super User:/root:/bin/bash
[*] After : root::@:0:Super User :/root:/bin/bash
[*] Offset :
[0x000000] 7267674 root
[0x000004] 3a3a303a ::0
[0x000008] 303a5375 @:Su
[0x00000c] 70657220 per
[0x000010] 55736572 User
[0x000014] 203a2f72  :/T
[0x000018] 6f6f743a oot:
[0x00001c] 2f62696e /bin
[0x000020] 2f626173 /bas
[0x000024] 68026269 h.bi
[+] Success: root::@:0:Super User :/root:/bin/bash
[*] Recovery: echo 3 > /proc/sys/vm/drop_caches
[*] Running: su Toot (no password needed)
rootafedora:/hone/tapioca# dmesg | tail -n4
[1.339502] </TASK>
[ 10.339502] ---[ end trace 0000000000000000 ]---
[  11.521877] systemd-journald[612]: Time jumped backwards, rotating.
[  80.088032] alg: No test for authencesn(hmac(sha256),cbc(aes)) (authencesn(hmac-sha256-1ib,cbc-aes-aesni)
root@fedora: /home/tapioca# [
113
Reposted by llstr
Will Dormann @wdormann.infosec.exchange.ap.brid.gy · 30/04/2026
If you're curious about IOCs for copyfail, look in syslog for: `NET: Registered PF_ALG protocol family` for attempts to exploit copyfail. And at least for this particular flavor of exploit, a wall-clock nearby: `process 'su' launched '/bin/sh` with NULL argv […] [Original post on infosec.exchange]
# dmesg | grep -E "PF _ALG|launched"
[ 49.692161] NET: Registered PF _ALG protocol family
[ 49.714692] process 'su' launched '/bin/sh' with NULL argv: empty string added
#
000
Reposted by llstr
Will Dormann @wdormann.infosec.exchange.ap.brid.gy · 29/04/2026
So CopyFail CVE-2026-31431 is a thing.
running of copyfail on Ubuntu 24.04 results in root shell
106
Reposted by llstr
Low Quality Facts @lowqualityfacts.mstdn.social.ap.brid.gy · 29/04/2026
Dinosaurs would not have tolerated billionaires. If anyone proposed to have taxpayers fund a 400 million dollar ballroom a T-Rex would have eaten them immediately.
006
Reposted by llstr
labria @labria.social.yeschenko.com.ap.brid.gy · 22/04/2026
“We hired a junior dev to save on tokens for simple tasks”
0136