What is Hackers' Pub?

Hackers' Pub is a place for software engineers to share their knowledge and experience with each other. It's also an ActivityPub-enabled social network, so you can follow your favorite hackers in the fediverse and get their latest posts in your feed.

1
1

Plethore of critical MX4200 Wi-Fi router vulnerabilities (that were originally reported to Linksys nearly a year ago!) are still unfixed:

- [SYSS-2025-001] Linksys MX9600/MX4200 - Path Traversal seclists.org/fulldisclosure/20
- [SYSS-2025-002] Linksys MX9600/MX4200 - Missing Authentication for Critical Function seclists.org/fulldisclosure/20
- [SYSS-2025-009] Linksys MX9600/MX4200 - SQL Injection seclists.org/fulldisclosure/20
- [SYSS-2025-010] Linksys MX9600/MX4200 - OS Command Injection seclists.org/fulldisclosure/20
- [SYSS-2025-011] Linksys MX9600/MX4200 - OS Command Injection seclists.org/fulldisclosure/20
- [SYSS-2025-014] Linksys MX4200 - Improper Verification of Source of a Communication Channel
seclists.org/fulldisclosure/20

On first read it might appear that many of these vulnerabilities would only be exploitable by accessing the device non-WAN interface(s) from inside the local network. However, due to the SYSS-2025-014 vulnerability the normally "LAN only RCE" vulnerabilities (SYSS-2025-010 and -011) and SQL injection (SYSS-2025-009) can be performed from the WAN interface (read: the internet). The attacker merely needs to make the connection originate from port 5222 (which is trivial to arrange via local bind before connect).

I recommend retiring the affected devices immediately as the manufacturer clearly has no motivation to fix the issues in a timely manner.

0
0
0

The AI bubble RAM crisis is caused for non-existent problems by non-existent money for a non-existent infrastructure to meet non-existent demand to make non-existent business and will utterly destroy real business based on real demand and real infrastructure built with real money for real problems.

RE: https://bsky.app/profile/did:plc:k6kg5ccozcphfcmp4zyx3s64/post/3meyszsqifs2p

0
1
1
0
0
0
0
0
1
1
0
0
0
1
1
0
0
0
0
0
1

Look at these kittens. One is a perfect little baby who just wants to explore and be loved. One is a little guy with big feelings, who ALSO just wants to be loved, but doesn’t want to make new friends yet. She may be 1/3rd his size (and only a month or so younger) but she’s like 2 months ahead on socialization and confidence.

Little tabby kitten face of a very small ~3 month old kitten  Black ~4-5 month old kitten face with coppery eyes
0
0
1

Right now is the ideal time for people with positions on the left end of the Overton Window to find offices to run for wearing a big blue D.
Anything. School board. State leg. County clerk. Sheriff.

If you want a real Left party in the US, the only serious strategy is to do to the Dems what the Fash have done to the GOP. Be the party. In the US, it really can be that simple.

0
0
0
0
0
0
0
0
0
0
0
0
0

I have clearly heard from a plurality of my audience—a minority, but a substantial plurality nonetheless—that they would like me to write about AI less. This is a desire which I would absolutely prefer to oblige. But I really need AI to meet me halfway here and stop fucking up every single thing about our industry, geopolitics, every hobby related to computers, and the planet

0
0
0
0
0
0
0
1
0
1
0
0
0

here’s a worked example of why nobody believes firefox’s AI kill switch will be anything but a marketing wedge

these showed up in my File menu, displacing the New Private Window item and fucking up my muscle memory, in spite of having browser.ml.enabled set to false. the setting for this is a new nonsensically named option, extensions.ml.enabled. a merry fuck you to the guys who showed up in my replies telling me to just disable the config flag I already disabled months ago.

a screenshot of the mozilla Firefox menu bar on macOS. the file menu is open, showing two new menu items “New AI Window” and “New Classic Window” right above the existing “New Private Window” option, physically displacing it down on the screen. neither of the new menu items has a keyboard shortcut.
0
0
0
1
1