What is Hackers' Pub?

Hackers' Pub is a place for software engineers to share their knowledge and experience with each other. It's also an ActivityPub-enabled social network, so you can follow your favorite hackers in the fediverse and get their latest posts in your feed.

Telnet is a remote login protocol that became obsolete in 1995 when SSH became available because SSH offers transport encryption while telnet does not.

Those who kept a telnetd running for whatever reason (and did not hide it behind a firewall) have had a root backdoor for the last ten years.

GNU InetUtils Security Advisory: remote authentication by-pass in telnet

The telnetd server invokes /usr/bin/login (normally running as root) passing the value of the USER environment variable received from the client as the last parameter.

If the client supply a carefully crafted USER environment value being the string "-f root", and passes the telnet(1) -a or --login parameter to send this USER environment to the server, the client will be automatically logged in as root bypassing normal authentication processes.

This happens because the telnetd server do not sanitize the USER environment variable before passing it on to login(1), and login(1) uses the -f parameter to by-pass normal authentication.

Severity: High

Vulnerable versions: GNU InetUtils since version 1.9.3 up to and including version 2.7.

History

The bug was introduced in the following commit made on 2015 March 19 […]

Recommendation

Do not run a telnetd server at all. Restrict network access to the telnet port to trusted clients.

Source (including exploit code not reproduced here): lists.gnu.org/archive/html/bug

0
1
1
0
0
0
0
0

Hello, meine Firma hat mir nach 11 Jahren gekündigt. Jetzt such ich nach einem neuen Job als Software Entwickler. Ich geh auch gern ins Büro solangs in Nürnberg und Umgebung ist aber genau so gern mach ichs auch Remote.
CPP, Python, Go, Delphi sind so Späße die ich kann. Generell auch Datenbanken, Docker, CI/CD, ein bisschen Netwerk, Server, alles was man als Nerd halt so macht.
Wenn ihr was habt oder was wisst haut mich gern an und auch gern

0
0
0

Telnet is a remote login protocol that became obsolete in 1995 when SSH became available because SSH offers transport encryption while telnet does not.

Those who kept a telnetd running for whatever reason (and did not hide it behind a firewall) have had a root backdoor for the last ten years.

GNU InetUtils Security Advisory: remote authentication by-pass in telnet

The telnetd server invokes /usr/bin/login (normally running as root) passing the value of the USER environment variable received from the client as the last parameter.

If the client supply a carefully crafted USER environment value being the string "-f root", and passes the telnet(1) -a or --login parameter to send this USER environment to the server, the client will be automatically logged in as root bypassing normal authentication processes.

This happens because the telnetd server do not sanitize the USER environment variable before passing it on to login(1), and login(1) uses the -f parameter to by-pass normal authentication.

Severity: High

Vulnerable versions: GNU InetUtils since version 1.9.3 up to and including version 2.7.

History

The bug was introduced in the following commit made on 2015 March 19 […]

Recommendation

Do not run a telnetd server at all. Restrict network access to the telnet port to trusted clients.

Source (including exploit code not reproduced here): lists.gnu.org/archive/html/bug

0
0

Whelp, one of my remote hosts got hacked. 😱 I’m sure this makes me look like an idiot, but here’s a post on what happened, anyway.

amxmln.com/blog/2026/that-time

Lesson learned, I hope I can move on and not be paralysed by paranoia. 😅

0
1
0
0
0

RE: social.vivaldi.net/@sesivany/1

Oooooooh.

It just hit me.

Wikipedia was born in the US. That's why there is the Wikimedia Foundation which controls the project, keeps everything inside its infrastructure, and is the single point of contact for the project.

OpenStreetMap was born in Europe. By the words of Jiří, our DNA is different: we provide the data and do the absolute minimum, allowing hundreds of companies flourish on our data. E.g. there are no official routers or search engines.

0
0
0
0
들뢰즈의 마르코프 체인에 대한 이야기는 잘 모르겠지만
영상 매체라면 A장면이 B장면 C장면에 모두 영향을 준다는 의미가 아닐까?
A 장면에서 영향을 안받은 것 같은 B,C장면이 나오더라도 마르코프 체인 통계 안에서 구성된다는 이야기 아닐까?
라고 빨래 널면서 생각해 봅니다.
0
0
0
0

Aus aktuellem Anlass:

When they kick at your front door
How you gonna come?
With your hands on your head
Or on the trigger of your gun

When the law break in
How you gonna go?
Shot down on the pavement
Or waiting in death row

The Clash - Guns of Brixton
youtu.be/gVVqUuNG1ZI

0
0
1

In the early days of personal computing CPU bugs were so rare as to be newsworthy. The infamous Pentium FDIV bug is remembered by many, and even earlier CPUs had their own issues (the 6502 comes to mind). Nowadays they've become so common that I encounter them routinely while triaging crash reports sent from Firefox users. Given the nature of CPUs you might wonder how these bugs arise, how they manifest and what can and can't be done about them. 🧵 1/31

0
0
3
1
0
0
0
1

We need legislation on sideloading ASAP. Yesterday, I learned the hard way that I’m not allowed to use my own personal, paid developer certificate to sign IPAs I want to install on my own personal device. Wow. 😬

An email from Apple, notifying me of the account termination.
0
0
0
0
0
0
1
0

트럼프 정부에 韓정부 제지 요청한 쿠팡측, 한미통상분쟁 노리나 www.yna.co.kr/view/AKR2026... 쿠팡 투자자들이 이재명 대통령과 민주당에 대해 '친중 성향'까지 거론 쿠팡 투자자들은 USTR에 한국산 제품에 대한 관세 부과, 미국 내에서 한국의 서비스 제공 제한, 재발 방지 대책 마련 등을 청원했다.

트럼프 정부에 韓정부 제지 요청한 쿠팡측, 한미통상분쟁...

0
1

The joys of modern email: "Has Microsoft decided to put all of our email on hold or are they having a global M365 inbound SMTP email incident?"

(For about the last hour and a half, if it's an incident someone is having a bad day.)

0

Hey Washington, there's a profoundly bad law making its way through the state level.

This law, will require ALL 3d printers to send copies of the files you print directly to the government to be check against a database of "banned shapes".

Literally turning your 3d printer into spyware. And if you don't voluntarily turn your printer into a spy, you will be a class C Felon.

This law affects ALL CNC machines, not just 3dps.

youtube.com/watch?v=kS-9ISzMhB

0
0
0
0
0
0
0
1
1
1

A woman who I follow on the fediverse just had to delete a post due to sexual harassment.

Men if you want more diversity on the Fediverse you need to speak up and call in your peers. You need to educate them and if they persist ban them. Make it clear they aren't welcome.

Otherwise you're making it clear we aren't welcome.

It shouldn't just be us doing the work

dotart.blog/cobbles/the-silence

0
0
0
0
0
0

of all the coding I do, I never want to [redacted self violence] more than when I'm doing CSS.

does anyone know of any good guides/courses for debugging it/having better mental models for working with it?

I need to read every layout all the way through, and I have wizard zines pocket guide.

0

老害にならず、イキりもせず、適切に知識と常識をアップデートして、年齢でマウントを取らず、歳下だからとタメ口を使わず、異性の後輩をちゃん付け呼びせず、若い世代のグループに首を突っ込まず、自慢話も武勇伝も語らず、ありがとうとごめんなさいが言えるおじさんに私はなりたい。
2

0
0
0

For the last decade, the has been funding , , , , and many other Open Source projects you know and love through its programme.

But now that programme is ending and they are thinking about its successor.

They want to hear from you on what it should look like: Share your feedback to make sure the Commission keep funding amazing Open Source projects!
[JM]

ec.europa.eu/info/law/better-r

The NGI logo
0
0
0

Ghostty is getting an updated AI policy. AI assisted PRs are now only allowed for accepted issues. Drive-by AI-written PRs will be closed without question. Bad AI drivers will be banned from all future contributions. If you're going to use AI, you better be good. github.com/ghostty-org/ghostty

0
0
0