Post B5nPHYVJzX0OwMal16 by zvava@bbs.619.hu
(DIR) More posts by zvava@bbs.619.hu
(DIR) Post #B5nPHYVJzX0OwMal16 by zvava@bbs.619.hu
1 likes, 0 repeats
oh funfree root/privilege escalation on every linux distribution since 2017 with just a little python script⇒ copy.fail
(DIR) Post #B5nQjyk28RlENOafFw by lanodan@queer.hacktivis.me
1 likes, 0 repeats
@mia @zvava Also doesn't for me but there's a gigantic pile of reasons why it wouldn't.- My gentoo machines end up with: OSError: [Errno 97] Address family not supported by protocol- My Alpine machines end up with: PermissionError: [Errno 13] Permission denied: '/bin/su'
(DIR) Post #B5nRYqU8al65XRPVMe by lanodan@queer.hacktivis.me
0 likes, 0 repeats
@mia @zvava Reported to them in the off chance it'll cool their "Run everywhere, all linux are vulnerable!" bullshit.https://github.com/theori-io/copy-fail-CVE-2026-31431/issues/3https://github.com/theori-io/copy-fail-CVE-2026-31431/issues/4
(DIR) Post #B5nUBeGKAZj4pea0ES by hsza@social.tudbut.de
0 likes, 0 repeats
@lanodan @zvava @mia they do need to get some cool. their site reads like llm slop, and yep indeed they claim the vuln was found by a slop machineSlopcurity ✨
(DIR) Post #B5nUBeUVJr4JXdDKKm by lanodan@queer.hacktivis.me
0 likes, 0 repeats
@hsza @zvava @mia Well security researchers have been doing this overhyping of security vulns pretty much forever, like any kind of "We found a vuln against all linux!!!" is basically guaranteed bullshit at this point.
(DIR) Post #B5nUCbCT2YhJcmEFua by tudbut@social.tudbut.de
1 likes, 0 repeats
@hsza @lanodan @mia @zvava also fun: website says “Targets /usr/bin/su by default; pass another setuid binary as argv[1].”, but there is no such thing. argv[1] is never read in the actual code and passing anything there does nothing.
(DIR) Post #B5nUPMdQVLGEDRvSFc by mia@shrimptest.0x0.st
1 likes, 0 repeats
@lanodan @zvava @hsza oftentimes they use this to advertise their services or those of their employers. just part of the hustle at this point
(DIR) Post #B5nUZwZBlZeeYGzKim by lanodan@queer.hacktivis.me
0 likes, 0 repeats
@mia @zvava @hsza Makes sense, after all non-commercial distros seem like a pain to exploit in comparison to commercial ones with a ton of random garbage being setuid-root/file-caps or running as root.
(DIR) Post #B5nWRkQFEajMTk1Zc8 by hsza@social.tudbut.de
0 likes, 0 repeats
@tudbut @lanodan @mia @zvava Slopcurity!!I do expect that whole website has been hallucinated by some “agent” so obvious nonsense like that checks out
(DIR) Post #B5nWRkrXb6Z5qOnNA0 by lanodan@queer.hacktivis.me
0 likes, 0 repeats
@hsza @zvava @mia @tudbut Well the CVE does exists and has been patched, and been reproduced on Kali Linux (always this toy distro, lol): https://github.com/theori-io/copy-fail-CVE-2026-31431/issues/2
(DIR) Post #B5nWRlEaDQzqzrZm4m by tudbut@social.tudbut.de
0 likes, 0 repeats
@lanodan @zvava @mia @hsza i dont at all doubt it works on some distros but “ITS ALL OF LINUX” is some nonsense
(DIR) Post #B5nWRlPvXG4RZ2spl2 by hsza@social.tudbut.de
0 likes, 0 repeats
@tudbut @lanodan @mia @zvava works on my linux. probably gonna see about recompiling the latest 6.18 lts or something (not going up to 7+ since those newest versions are intensely vibe coded; backported patches are gonna be slop too, but i have only so many options at this point)
(DIR) Post #B5nWRlcKn7zmBWgk64 by tudbut@social.tudbut.de
0 likes, 0 repeats
@hsza @lanodan @mia @zvava ah i just saw im actually on 7.0.0 already so its probably patched for me. oh well.not going up to 7+ since those newest versions are intensely vibe codedlooks like i might be reverting my last system update :/
(DIR) Post #B5nWRlrZsSBkwnourA by hsza@social.tudbut.de
0 likes, 0 repeats
@tudbut @lanodan @mia @zvava ah, you don’t read phoronix do youthe linux kernel’s ensloppification has been rapidly accelerating lately and 7.0 is my personal “no nuh uh ill have none of that” point
(DIR) Post #B5nWRm7stpETlNRwH2 by mia@shrimptest.0x0.st
0 likes, 0 repeats
@hsza @zvava @lanodan @tudbut i hate the AI cult and am currently suspending one of my services because of it but even i think you need to touch grass ngl
(DIR) Post #B5nWRmR1keXqikPE6y by tudbut@social.tudbut.de
0 likes, 0 repeats
@mia @hsza @zvava @lanodan if “you” also refers to me: i touch a lot of grass actually, its why i dont consider updates necessary or even worth my time. ive long since stopped doing them on all systems except my nixos one (because thats one where i can revert them with ease), though maybe now thatll also include the nixos one
(DIR) Post #B5nWRmksYqQNiJh53Q by mia@shrimptest.0x0.st
0 likes, 0 repeats
@tudbut @zvava @lanodan @hsza idk to me it’s like doing the laundry or something, so i upgrade stuff pretty frequently. tumbleweed never really broke anything for me. my desktop still has the same install from 2009 and i just kept migrating it to new hardware over time
(DIR) Post #B5nWRmzPgo3CROUgi0 by lanodan@queer.hacktivis.me
0 likes, 0 repeats
@mia @tudbut @zvava @hsza Both of which are extremely personal ways of putting it, so please untag.
(DIR) Post #B5ncjtu3K6Fqov0Qqm by hsza@social.tudbut.de
0 likes, 0 repeats
@lanodan @mia @zvava does appear real tho, their python file does give me a root shellit is unfathomably stupid how most software in year of our miku 2026 runs completely unsandboxed and this can just Happen if you double click the wrong thing. security being not properly designed for by mainstream OS developers thus ending up as this active cat and mouse game
(DIR) Post #B5ncju9IPQRpaC8bbs by mia@shrimptest.0x0.st
0 likes, 0 repeats
@hsza @zvava @lanodan sandboxing is mostly a hack for systems that were not designed with security in mindsuid executables should not exist in the first place
(DIR) Post #B5ncjuQJOA3iQy6C8G by mirabilos@toot.mirbsd.org
0 likes, 0 repeats
@lanodan @hsza @mia @zvava how do you 'sudo' or 'su' without suid executables?
(DIR) Post #B5ncjucMfLhT2Ljov2 by mia@shrimptest.0x0.st
0 likes, 0 repeats
@mirabilos @zvava @lanodan @hsza you can launch them from a privileged process that takes care of sanitizing the environment and setting up restrictions/sandboxing. e.g. systemd’s run0 does that
(DIR) Post #B5ncjuolvDcnepXjG4 by mirabilos@toot.mirbsd.org
0 likes, 0 repeats
@zvava @mia @lanodan @hsza but what when you cannot? For example when chrooting into an installed system from a live CD? Even ssh’ing in can get less secure from that as the ssh process that handles the user session is privdropped…
(DIR) Post #B5ncowIHrT1bgQkBwO by lanodan@queer.hacktivis.me
0 likes, 0 repeats
@mirabilos @hsza @mia @zvava So far the way I've seen is to connect to a privileged daemon, quite like with an sshd but on sockets (at least I hope, let's not replace suid with MITM-ability…).
(DIR) Post #B5ncowgkOWaguIBj4C by mirabilos@toot.mirbsd.org
0 likes, 0 repeats
@zvava @hsza @lanodan @mia assumes sockets work and you have a writable filesystem for them depending on the impl
(DIR) Post #B5nd9VMdBJ5AF7aAE4 by mia@shrimptest.0x0.st
0 likes, 0 repeats
@mirabilos @zvava @lanodan @hsza i don’t see how i can’t do that there. chroot changes the root dir of the process and has no influence on privileges otherwise
(DIR) Post #B5nd9VVqd2SGhhtWam by mirabilos@toot.mirbsd.org
0 likes, 0 repeats
@zvava @mia @lanodan @hsza but the stuff in the chroot cannot contact a daemon
(DIR) Post #B5ndo9beyqRadTzkW0 by mia@shrimptest.0x0.st
0 likes, 0 repeats
@mirabilos @zvava @lanodan @hsza yes it can if you have that running in the same env. i don’t see the problem.
(DIR) Post #B5ndo9tNuwcdWSHu8u by mia@shrimptest.0x0.st
0 likes, 0 repeats
@zvava @lanodan @mirabilos @hsza for systemd-based distros you’d use systemd-nspawn anyway
(DIR) Post #B5ndoA4NG5Pe4XQgGu by mirabilos@toot.mirbsd.org
0 likes, 0 repeats
@mia @zvava @lanodan @hsza I don’t systemd
(DIR) Post #B5ne5urgWmSQ80xaqm by mia@shrimptest.0x0.st
0 likes, 0 repeats
@mirabilos @zvava @lanodan @hsza it’s an example. there’s no reason it has to be systemd. just saying that namespaces exist and we have tools to run things from a system root in a container-like env that are easier to use than manually setting up /proc /sys /dev and running chroot
(DIR) Post #B5ne5v1xuYgGdtlnsG by mirabilos@toot.mirbsd.org
0 likes, 0 repeats
@mia @zvava @lanodan @hsza I have a script for the latter.