Post B5pOhwGgY5zsXAgN60 by domi@donotsta.re
 (DIR) More posts by domi@donotsta.re
 (DIR) Post #B5pO4BA3l12N8ncm2a by lnl@screaminginsi.de
       0 likes, 0 repeats
       
       Disclosure: in some cases, a Linux user can use doas to edit files in /etc/periodic/15min, allowing to execute code as root. I haven't reported this to cron because maintainer's e-mail address was so long I didn't want to type it.lauren@hayasaka ~ $ doas python3 ./turbohack.pylauren@hayasaka ~ $ tail -n2 /tmp/out.txt[+] Executing: whoamiroot
       
 (DIR) Post #B5pOdjogtx7Il3aLMe by domi@donotsta.re
       0 likes, 0 repeats
       
       @lnl it’s true, someone has used this vulnerability to create so-called “linucks merrors” on one of our servers.PoC: https://alpine.sakamoto.pl/ - the consequences are crazy, perhaps not fully understood yet. beware!!RE: https://screaminginsi.de/@lnl/statuses/01KQFTJ4K5226XSXZK7AEBJHPS
       
 (DIR) Post #B5pOhwGgY5zsXAgN60 by domi@donotsta.re
       0 likes, 0 repeats
       
       @lnl patch by upgrading to systemd timers