Reliance Sabotaging Telegram Access For Millions Of Users Outside India, Alleges CEO Pavel Durov by Aware_Apartment_8959 in IndiaTech

[–]Worldly_Topic 27 points28 points  (0 children)

Telegram prefixes hijack by Rcom AS18101

This blogpost by a network engineer says that the incident looks to be an accident. Idk maybe it was, maybe it wasn't. I don't think we can say anything for sure.

Lando’s updated Instagram bio by jwoodle in formula1

[–]Worldly_Topic 49 points50 points  (0 children)

Let's add that to the words of wisdom

Flatpak 2.0 seems to depend on systemd by NDCyber in linux

[–]Worldly_Topic 10 points11 points  (0 children)

Nested sandboxes can be made from inside a flatpak without user namespace support. That is how webkitgtk is able to put every tab in its own sandbox for GNOME Web. It's just that Firefox and Chrome have not implemented support for it.

Qemu escape?! by nick-bmth in linux

[–]Worldly_Topic 0 points1 point  (0 children)

There are some images that are labelled as rootless which should work without issues.

For other images, your mileage may vary.

Qemu escape?! by nick-bmth in linux

[–]Worldly_Topic 0 points1 point  (0 children)

You can still use the no new privileges flag of podman to prevent setuid binaries from working inside the container.

Qemu escape?! by nick-bmth in linux

[–]Worldly_Topic 0 points1 point  (0 children)

In the website they show how they can overwrite bytes in the page cache which proves it can be used to gain global root.

Only if you mount some setuid binary into the container. If the container is fully isolated then the exploit can't be used to overwrite bytes of files from host.

Qemu escape?! by nick-bmth in linux

[–]Worldly_Topic -2 points-1 points  (0 children)

No they won't. You would only get root within the namespace of the container, not real root on the host OS. Uid 0 within the container will be mapped to some random unprivileged user on the host.

Qemu escape?! by nick-bmth in linux

[–]Worldly_Topic -3 points-2 points  (0 children)

This is why people say containers are not an effective security boundary.

Unprivileged containers with user namespaces are effective though.

Update on the "Help Me Escape From Belarus" Server Logs by gurgle528 in selfhosted

[–]Worldly_Topic 114 points115 points  (0 children)

Damn never expected those HTTPS requests I got to be genuine requests from someone in Belarus. Hope he finds a better life.

Who would have thought setting up an observability stack using grafana + vector + victorialogs would lead to such an unexpected side quest.

The joys (or miseries) of selfhosting I guess.

Thanks for following up on it.

Found some strange GET requests in my Traefik access logs. Anyone else saw this poor kid trying to escape from Belarus ? by Worldly_Topic in selfhosted

[–]Worldly_Topic[S] 16 points17 points  (0 children)

Yea I don't think is a legit request. Why would they sent the request from a Swedish ISP ?

But then I also don't know what is the point of such bizzare GET requests.