leds

joined 1 year ago
 

I dont know who needs to hear this bit qBittorrent has a nasty vulnerability ( and there are some older ones too)

qBittorrent, on all platforms, did not verify any SSL certificates in its DownloadManager class from 2010 until October 2024. If it failed to verify a cert, it simply logged an error and proceeded.

To be exploitable, this bug requires either MITM access or DNS spoofing attacks, but under those conditions (seen regularly in some countries), impacts are severe.

The primary impact is single-click RCE for Windows builds from 2015 onward, when prompted to update python the exe is downloaded from a hardcoded URL, executed, and then deleted afterwards.

The secondary impact for all platforms is the update RSS feed can be poisoned with malicious update URLs which the user will open in their browser if they accept the prompt to update. This is browser hijacking and arbitrary exe delivery to a user who would likely trust whatever URL this software sent them to.

The tertiary impact is this means that an older CVE (CVE-2019-13640 https://www.cvedetails.com/cve/CVE-2019-13640/) which allowed remote command execution via shell metacharacters could have been exploited by (government) attackers conducting either MITM or DNS spoofing attacks at the time, instead of only by the author of the feed.

Full write up is here: https://sharpsec.run/rce-vulnerability-in-qbittorrent/

[–] [email protected] 21 points 1 month ago (1 children)

AI seems perfect for renewables load balancing. Got extra power to burn because it is windy at night? Train your models

[–] [email protected] 1 points 1 month ago

I feel like phone on pile should at least be yellow

[–] [email protected] 26 points 1 month ago

Not a lawyer but that does look like a very acceptable URL doesn't it? I mean has all the normal URL dots and slashes so I'd say accept

[–] [email protected] 17 points 1 month ago* (last edited 1 month ago)

Telegram has been supplying US government with data on its users

https://www.404media.co/telegram-confirms-it-gave-u-s-user-data-to-the-cops/

[–] [email protected] 1 points 1 month ago (1 children)

Also relevant:

[–] [email protected] 2 points 1 month ago

Seems like a good use for android app pinning, I think that locks the phone to that app until unlocked

[–] [email protected] 6 points 1 month ago (1 children)
[–] [email protected] 17 points 1 month ago (1 children)
[–] [email protected] 1 points 2 months ago (1 children)

Spotify might as well be doing this themselves already to avoid having to pay all those annoying artist

[–] [email protected] 8 points 2 months ago (1 children)

Nazis unfortunately (disclaimer not a swede)

[–] [email protected] 3 points 2 months ago

In that case probably not for everyday use then , or just use sand. But I'd think that there is also some chemical action that makes it very effective against tea and coffee stains

[–] [email protected] 1 points 2 months ago (2 children)

Just baking soda works

 

Merged

view more: next ›