When Root Meets Immutable: OpenBSD Chflags vs. Log Tampering
https://rsadowski.de/posts/2025/openbsd-immutable-system-logs/
Critical Sudo Vulnerabilities Let Local Users Gain Root Access on Linux, Impacting Major Distros
Cybersecurity researchers have disclosed two security flaws in the Sudo command-line utility for Linux and Unix-like operating systems that could enable local attackers to escalate their privileges to root on susceptible machines.
https://thehackernews.com/2025/07/critical-sudo-vulnerabilities-let-local.html
So... my back is feeling it so many brambles' roots to dig and they are so looooong
They are like cables! Kind of amazing in a way.
I reckon by next week, I can plant few seedlings in there.
#gardening #nature #growth #growingfood #root
A critical Linux vulnerability (CVE-2025-32463) in Sudo lets any local unprivileged user gain root via the --chroot (-R) option
Affects default configs on Ubuntu, Fedora & others — no Sudo rules needed
Fix: Update to Sudo 1.9.17p1+ (no workarounds)
CVSS: 9.8 (Critical)
Highlights persistent risks in open-source privilege handling
https://cybersecuritynews.com/linux-sudo-chroot-vulnerability/
#Linux #Sudo #FOSS #CyberSecurity #InfoSec #OpenSource #Vulnerability #Root #Exploit #SysAdmin #DevSecOps #Tech @TechNews
#Root-Zugriff für alle:
#Kritische #Sudo-Lücke gefährdet unzählige #Linux-Systeme
#Forscher haben eine gefährliche #Sicherheitslücke im #Kommandozeilentool #Sudo entdeckt. Angreifer können mit wenig Aufwand Root-Rechte erlangen.
Die #Sicherheitslücke besteht laut Blogbeitrag der #Forscher seit der im Juni 2023 veröffentlichten #Sudo-Version 1.9.14 – und damit seit rund zwei Jahren. Ursache ist wohl ein Fehler in der #Chroot- #Implementierung.
@JessTheUnstill @bohwaz @punkfairie @ajsadauskas @tomiahonen @fuchsiii Exactly...
Coincidentially, that's why #Android (and #iOS) doesn't let users have #root access because billions of devices owned by mostly "#TechIlliterates" that hardly get #SecurityUpdates would be an even bigger risk if they didn't boot a locked-down #ROM image, thus only allowing for #malware in user-privilegued userspace!
Cuz having a mobile OS that shoves everything through #Tor and only allows #userspace-Apps in the form modern web technologies would be a big #security and #privacy gain.
In case USA provides even more surprises, can Europe run our own root name servers as an alternative to root-servers.net
, since .net
zone is operated by VeriSign, and .org
(hosting root hints) by Public Internet Registry, which are both US entities?
Correction: root hints are on .net
domain too, IANA only links to actual file.
@ai6yr @briankrebs OFC this targets #TechIlliterates and the only effective means here are:
Through parent's trust life
gave haven, wich I gladly
returned, when they aged
(My parents lived together till the age of 90 and 95 and both deceased within 6 weeks)
#MastoPrompt
#root
#dailyhaikuprompt
#shell
Bob Marley - Live Santa Barbara 1979
Killer strategy boardgame Root's new Steam expansion has made me aware that Root exists as a PC game - https://www.rockpapershotgun.com/killer-strategy-boardgame-roots-steam-expansion-has-made-me-aware-that-root-exists-as-a-pc-game #Strategy #Fantasy #Root #PC
Hi #Fediverse, let's start our journey here with our #introduction. We are #Turris project by #CZNIC. We develop and produce #opensource #wifi #router with focus on #security running #Linux distribution based on #OpenWrt. Of course, we provide automatic #updates and #root accounts. We have a #network of #honeypots running on our devices and create a dynamic #firewall based on the data.
We talked about anger, fear, hate, and love during this morning’s Wednesday Ayem Attunement.
This is a dark day for many people. Let’s take a (profanity-laced) look at how love works.
https://www.instagram.com/reel/DCCLZIsRe6k/?igsh=bTU5dTUyNDY5aHFw
I was relatively quiet yesterday because I spent pretty much all day playing #boardgames with local choom @ety and a bunch of (hopefully) new friends from the local Board Games Consortium here. Around 10 hours of gaming madness yesterday!
We played things like #SpaceBase, #CthulusVault, #Root, #Anomia, #TuringMachine, #Guilliotine, and several other games of which I can't recall the names at the moment. I won one, lost most of the rest. But it was fun, fun, fun!
My personal crowning achievement was finally being able to play Cyberpunk #GangsOfNightCity with actual people (and a full complement at that)! According to the rules, the game maxes out at 5 players (which kind of sucks, considering there are 3 additional gangs and 2 Nomad clans with the Badlands expansion), but we played the tutorial mission to get everyone familiar with the mechanics and that still took like 3 hours. But I learned a lot about game having a "full boat" of players. I know what I'm going to do different next time, for sure!
The one thing I forgot to do was take pictures of GONC in it's full, in-progress glory!
So much fun, and I'm looking forward to doing it again soonish. Thanks for the invite, @ety !