2,279 karma · joined August 11, 2015
Our leading theory is that the Great Firewall inside China is manipulating DNS responses due to blacklisted or blocked keywords. This affects any system that has to pass through the Great Firewall before it reaches the end-user/client. Most of the keywords relate to VPN software, proxies, adult sites, file and text sharing and torrents. This is consistent with the kinds of material that China is known to censor within its borders.
Has anyone tried rendering the current docs with the old theme?
<!--#include file="issue-0001.html" -->
Also, be careful of any moves to supporting dynamic content as Server Side Includes can (sometimes?) lead to code exec even with IncludesNoExec.* sshd(8): OpenSSH 8.5 introduced the LogVerbose keyword. When this option was enabled with a set of patterns that activated logging in code that runs in the low-privilege sandboxed sshd process, the log messages were constructed in such a way that printf(3) format strings could effectively be specified the low-privilege code.
An attacker who had sucessfully exploited the low-privilege
process could use this to escape OpenSSH's sandboxing and attack
the high-privilege process. Exploitation of this weakness is
highly unlikely in practice as the LogVerbose option is not
enabled by default and is typically only used for debugging. No
vulnerabilities in the low-privilege process are currently known
to exist.
Thanks to Ilja Van Sprundel for reporting this bug. We were also unable to control the contents of a file on disk, and bruteforcing process identifiers (PIDs) and file descriptors found no interesting results, eliminating remote LD_PRELOAD exploitation. $ RUBYOPT="-r/usr/lib64/libpcprofile.so" PCPROFILE_OUTPUT="/tmp/testing" ruby /dev/nullSome extra discussion can be found in a Twitter thread[0] from the person who discovered the issues.
[0] https://twitter.com/justinsteven/status/1270113960021209088
[0] https://twitter.com/justinsteven/status/1270113960021209088
[1] https://twitter.com/_markel___/status/1262697756805795841
$ irb
>> puts RUBY_VERSION
2.6.5
>> "ß".chars.size
=> 1
>> "ß".upcase.chars.size
=> 2 --- !ruby/object:Gem::Requirement
requirements:
!ruby/object:Gem::DependencyList
specs:
- !ruby/object:Gem::Source::SpecificFile
spec: &1 !ruby/object:Gem::StubSpecification
loaded_from: "|id 1>&2"
- !ruby/object:Gem::Source::SpecificFile
spec:
[0] https://staaldraad.github.io/post/2019-03-02-universal-rce-r...[0] https://twitter.com/thezedwards/status/1204965655482527744
[0] https://portswigger.net/research/http-desync-attacks-request...
[1] https://old.reddit.com/r/programming/comments/csfj53/sushi_r...
[0] https://www.trustwave.com/en-us/resources/security-resources...