Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
averi
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
averi
5mo ago
There's a specific reason why the exploit targets a setuid binary, if you poison it in memory it will be executed with the permissions of the user owning it, in this case root, meaning a setuid(0) + spawning a new shell will effectivel
2.
▲
by
averi
5mo ago
You can work with the idea of a DNS whitelist, as in you pass a list of allowed DNS entries via your .gitlab-ci.yml (or separate config) resolution happens and those entries (IPs) are stored in a list, any other IP not present in that list
3.
▲
by
averi
5mo ago
Nowhere in the article is mentioned user namespaces completely mitigate the vulnerability, page cache corruption still happens but not being able to obtain root in the target host increases the attack vector to more than just a one liner in
4.
▲
CVE-2026-31431: Copy Fail vs. rootless containers
(dragonsreach.it)
205 points
by
averi
5mo ago
|
123 comments
5.
▲
Help the GNOME Foundation Defend the GNOME Trademark Against Groupon
(gnome.org)
25 points
by
averi
12y ago
|
2 comments
6.
▲
The Future is Cloudy
(dragonsreach.it)
2 points
by
averi
14y ago
|
0 comments
7.
▲
My favorite Wordpress Plugins
(dragonsreach.it)
2 points
by
averi
14y ago
|
0 comments
8.
▲
The Linux's perception of my neighbours
(dragonsreach.it)
2 points
by
averi
14y ago
|
0 comments