What is Nostr?
feld /
npub1c5t…h8gn
2025-01-15 18:20:44

feld on Nostr: everyone is overreacting to CVEs like usual if you're doing rsync over SSH, they'd ...

everyone is overreacting to CVEs like usual

if you're doing rsync over SSH, they'd have to have compromised the server key to not trigger the fingerprint/impersonation warning

If the server is compromised by an attacker, you have much larger problems.

Secure both ends. Use a secure network transport that can't be MITM'd. These problems don't matter then.

The rsync utility in Linux, *BSD, and Unix-like systems are vulnerable to multiple security issues, including arbitrary code execution, arbitrary file upload, information disclosure, and privilege escalation. Hence, you must patch the system ASAP https://www.cyberciti.biz/linux-news/cve-2024-12084-rsyn-security-urgent-update-needed-on-unix-bsd-systems/

#infosec #security #linux #unix

Author Public Key
npub1c5tlngqj4f9f3lkxnu2swe98pem78ss6xf380ldh3rlrm595zrustfh8gn