Unless you deliberately set out to compile a minimalistic custom kernel, less than half of them. Problem is, you may not be able to easily tell which half.
Leave ssh root access open with no password. Attackers will try to escalate privileges as their default strategy, when that fails they'll add your IP to their unhackable blacklist.
I think you might be able to deactivate this one by turning off XFRM support in a custom-configured kernel, at the cost of losing some types of tunneling. Not going to actually test that, though.
17 Comments
cypherpunks@lemmy.ml · 57 pts · 109d
Runecrush376@lemmy.world · 7 pts · 109d
😂😂😂
inari@piefed.zip · 20 pts · 108d
Good news. One fewer zero-day.
fatur0000new@lemmy.ml · 15 pts · 109d
If this is quickly solved, there is nothing to worry about
Sorry if my english is bad
Azzu@lemmy.dbzer0.com · 8 pts · 108d
It is already solved. The dirtyfrag patch fixes it already.
neon_nova@lemmy.dbzer0.com · 5 pts · 109d
Only think you forgot was punctuation marks at the ends of your sentences.
pastermil@sh.itjust.works · 14 pts · 109d
This simply means the person isn't finished talking.
Goingdown@sopuli.xyz · 14 pts · 108d
Same workaround works here as with dirty frag. Just disable those kernel modules.
Tenderizer78@lemmy.ml · 6 pts · 108d
Maybe the solution is to just, delete a bunch of kernel modules.
How many of them are actually important anyway?
nyan@sh.itjust.works · 2 pts · 108d
Unless you deliberately set out to compile a minimalistic custom kernel, less than half of them. Problem is, you may not be able to easily tell which half.
AstroLightz@lemmy.world · 13 pts · 108d
I'm sure removing the root user will prevent all escalation exploits. Can't get root if there is no root!
/j
racoon@lemmy.ml · 2 pts · 107d
wickedrando@lemmy.ml · 7 pts · 109d
apparmor ftw
Cantaloupe@lemmy.fedioasis.cc · 7 pts · 107d
Ah shit, here we go again.
Infernal_pizza@lemmy.dbzer0.com · 6 pts · 108d
At this point we might as well just run everything as root anyway
ranzispa@mander.xyz · 9 pts · 108d
Leave ssh root access open with no password. Attackers will try to escalate privileges as their default strategy, when that fails they'll add your IP to their unhackable blacklist.
nyan@sh.itjust.works · 3 pts · 109d
I think you might be able to deactivate this one by turning off XFRM support in a custom-configured kernel, at the cost of losing some types of tunneling. Not going to actually test that, though.
altphoto@lemmy.today · 2 pts · 108d
Scarry! Uoi guys on windows better stay away...ohhh privilege!