[-] leds@feddit.dk 1 points 1 hour ago

So surprise, the endless legitimate single sign ons on seemingly random websites where users need to enter their password are to blame for this.

93
submitted 3 days ago by leds@feddit.dk to c/piracy@lemmy.dbzer0.com

I dont know who needs to hear this bit qBittorrent has a nasty vulnerability ( and there are some older ones too)

qBittorrent, on all platforms, did not verify any SSL certificates in its DownloadManager class from 2010 until October 2024. If it failed to verify a cert, it simply logged an error and proceeded.

To be exploitable, this bug requires either MITM access or DNS spoofing attacks, but under those conditions (seen regularly in some countries), impacts are severe.

The primary impact is single-click RCE for Windows builds from 2015 onward, when prompted to update python the exe is downloaded from a hardcoded URL, executed, and then deleted afterwards.

The secondary impact for all platforms is the update RSS feed can be poisoned with malicious update URLs which the user will open in their browser if they accept the prompt to update. This is browser hijacking and arbitrary exe delivery to a user who would likely trust whatever URL this software sent them to.

The tertiary impact is this means that an older CVE (CVE-2019-13640 https://www.cvedetails.com/cve/CVE-2019-13640/) which allowed remote command execution via shell metacharacters could have been exploited by (government) attackers conducting either MITM or DNS spoofing attacks at the time, instead of only by the author of the feed.

Full write up is here: https://sharpsec.run/rce-vulnerability-in-qbittorrent/

[-] leds@feddit.dk 49 points 5 days ago

"Who is the current president?"

Yeah that one might be an issue for him..

[-] leds@feddit.dk 1 points 6 days ago

How else would they get in your ear?

[-] leds@feddit.dk 51 points 3 months ago

never voluntarily unlock it anywhere close to the border.

Isn't that defined as 100 mile from the border (including international airports)

20
submitted 3 months ago by leds@feddit.dk to c/foss@beehaw.org

so.. i'm running lineageOS on my phone (a Oneplus 6T) , have been for a very long time. Usually i'm really happy with this but not tonight:

  • Phone suggest a update of OS , just a weekly build. Sure why not, so it does it thing and i reboot, all good.
  • Open a app to listen to some podcast: screen goes black flickers a couple of times showing empty launcher. thankfully power button long press shows shutdown menu (but looks different from normal?) and lets me restart
  • do same thing again , ok looks like latest update broke something
  • update app, same
  • go to settings , updates to try to revert to previous version: no option to install older version , only option is export. weird ok lets try to export old version . Now it lets me install that
  • installation loops , seems it failed
  • try app again, same black screen , hold power button to get boot menu again : now phone says ERASING .. wait what stop no .. (does lineage have a panic wipe my phone key combo i didn't know about?)
  • rebooting , rebooting again
  • welcome setup your phone screen :(
  • remember that my cloud server disk burned last week , no way to restore backups :( :(
[-] leds@feddit.dk 76 points 4 months ago

Remember that Microsoft offers a nicely packaged version of openjdk for download

[-] leds@feddit.dk 46 points 4 months ago

I think your instance is wonderfull ... and you're very nice, too

3
submitted 5 months ago by leds@feddit.dk to c/gardening@lemmy.world

Hi All, my fava beans are being eaten by black ants , no aphids. the ants themselves seem to be sucking the juice out of the leaves, leaving black spots where they have been nibling.

I thought they normally employed aphids to do the hard work for them but maybe they are skipping the middle man. Anyone seen this before?

Other leaves are full of holes but that looks more like snails , dont think the ants are capable of that.

Any good tips for encouraging the ants to move elsewhere ?

[-] leds@feddit.dk 50 points 5 months ago

Of course it is a chlilling discovery, it has been under ice..

[-] leds@feddit.dk 36 points 5 months ago

Got this:

Hello, Dell Technologies takes the privacy and confidentiality of your information seriously. We are currently investigating an incident involving a Dell portal, which contains a database with limited types of customer information related to purchases from Dell. We believe there is not a significant risk to our customers given the type of information involved.

What data was accessed? At this time, our investigation indicates limited types of customer information was accessed, including:

  • Name
  • Physical address
  • Dell hardware and order information, including service tag, item description, date of order and related warranty information
[-] leds@feddit.dk 32 points 6 months ago

OK but what's the cure?

[-] leds@feddit.dk 47 points 9 months ago

But thanks for keeping my phone up to date, it is appreciated ♥

243
DO NOT MERGE (feddit.dk)

Merged

[-] leds@feddit.dk 45 points 10 months ago

Also, Are those screws supposed to be poking out? Doesn't that damage all the squisy bits?

[-] leds@feddit.dk 52 points 1 year ago

Microsoft Edge submits the following data to Microsoft cloud services using a HTTPS connection:

The text of the webpage.

Interesting , this has implications for pages that are not on public internet. Viewing confidential/secret company documents in edge?

view more: next ›

leds

joined 1 year ago