Post B7j729kO3R2Rej8Q5I by 0h00000000@ioc.exchange
 (DIR) More posts by 0h00000000@ioc.exchange
 (DIR) Post #B7itFnLOkLCcs03W3U by mntmn@mastodon.social
       0 likes, 0 repeats
       
       ffmpeg remote code execution vuln https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/
       
 (DIR) Post #B7iwwMUwjc05vIVjrk by multisn8@donotsta.re
       0 likes, 0 repeats
       
       @mntmn Important caveat: ASLR was disabled for this demonstration. Our exploit requires hardcoded addresses for system() and the OOB command string, which means it works deterministically only with ASLR disabled (setarch x86_64 -R). In a default Linux configuration with ASLR enabled, the addresses are randomized on every execution, and the exploit does not land.phew. still worrisome, but not all that bad
       
 (DIR) Post #B7iwy3bzvN1vvZcLw0 by mntmn@mastodon.social
       0 likes, 0 repeats
       
       @multisn8 uff uff
       
 (DIR) Post #B7j729kO3R2Rej8Q5I by 0h00000000@ioc.exchange
       0 likes, 0 repeats
       
       @mntmn Reminds me of working a Fortune 100 co in 2000 and people were emailing around *EXE* files of meme videos before the word meme had been coined and 3 years before H.264 was invented. I wonder how many backdoors were installed by that EXE file... "Combo No. 5 - based on Mambo No. 5"https://www.youtube.com/watch?v=Ptqpq1dsDNw