4 ms·
You have my attention, what is this recent sudo bug?
by ollybee 6y ago
You have my attention, what is this recent sudo bug?
- float4 6y agohttps://news.ycombinator.com/item?id=25919235 https://news.ycombinator.com/item?id=25919235 As a tip for the future, in case you're interested: you can use hn.algolia.com, search "sudo", time window something like "past month", and you'd have found it.
- vntok 6y agoIt is much more efficient and future-proof to have someone put the exact link as a reply, that way people coming to the thread afterwards can simply click on.
- float4 6y agoI gave the full link, and additionally gave a tip for those who were interested. hn.algolia.com is a great resource and I'm certain not everybody here knows about it.
- jart 6y agoThanks for teaching these men to fish. I thought I was going to need to do all the explaining.
- xwdv 6y agoNot every man needs to fish, we live in a society with specialization. Some people can do the fishing and some can do other things.
- orthecreedence 6y agoWould be nice if everyone knew how to wipe their own ass though.
- TedDoesntTalk 6y agoHow do you know they are men?
- hash9 6y agoThey don't. They're referring to a famous proverb.
- edoceo 6y agoI appreciate when you give me the fish, and also show me how to fish (or even remind me where the fish are).
- rement 6y agoduckduckgo has a !bang for hacker news `sudo !hn` redirects to hn.algolia.com with the thread at the top of the list
- float4 6y agoOh cool, didn't know that!
- passthejoe 6y agohttps://www.beyondtrust.com/blog/entry/understanding-sudo-vulnerability-cve-2021-3156-and-how-privilege-management-for-unix-linux-can-protect-your-enterprise https://www.beyondtrust.com/blog/entry/understanding-sudo-vu...
- tyingq 6y agoDiscussed here: https://news.ycombinator.com/item?id=25919235 https://news.ycombinator.com/item?id=25919235 Though they would have had to also get into the admin server running (probably) WHMCS. The sudo bug would let a hacker take over a server where the customer code ran, but not the main admin server. They would have needed some other weakness to get that. Perhaps aided by owning one of the customer servers.
- samizdis 6y agoI think it's this one, which came to light last month: https://www.linux-magazine.com/Online/News/Decade-Old-Sudo-Flaw-Discovered https://www.linux-magazine.com/Online/News/Decade-Old-Sudo-F... Edited to add: Here's another article about it (you should be able to find quite a few more, too): https://www.theregister.com/2021/01/26/qualys_sudo_bug/ https://www.theregister.com/2021/01/26/qualys_sudo_bug/