mastodon.zunda.ninja is one of the many independent Mastodon servers you can use to participate in the fediverse.
Zundon is a single user instance as home of @zundan as well as a test bed for changes of the code.

Administered by:

Server stats:

1
active users

#ssh

0 posts0 participants0 posts today
Airports Bot<p>Sharm El Sheikh International Airport - Sharm El Sheikh, Egypt</p><p><a href="https://en.wikipedia.org/wiki/Sharm_el-Sheikh_International_Airport" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">en.wikipedia.org/wiki/Sharm_el</span><span class="invisible">-Sheikh_International_Airport</span></a><br><a href="https://www.openstreetmap.org/#map=13/27.977272/34.394717" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">openstreetmap.org/#map=13/27.9</span><span class="invisible">77272/34.394717</span></a></p><p><a href="https://mastodon.world/tags/HESH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HESH</span></a> <a href="https://mastodon.world/tags/SSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SSH</span></a> <a href="https://mastodon.world/tags/SharmElSheikh" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SharmElSheikh</span></a> <a href="https://mastodon.world/tags/Egypt" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Egypt</span></a> <a href="https://mastodon.world/tags/airport" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>airport</span></a> <a href="https://mastodon.world/tags/aviation" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>aviation</span></a> <a href="https://mastodon.world/tags/avgeeks" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>avgeeks</span></a> <a href="https://mastodon.world/tags/GIS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GIS</span></a></p>
Airports Bot<p>Sharm El Sheikh International Airport - Sharm El Sheikh, Egypt</p><p><a href="https://en.wikipedia.org/wiki/Sharm_el-Sheikh_International_Airport" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">en.wikipedia.org/wiki/Sharm_el</span><span class="invisible">-Sheikh_International_Airport</span></a><br><a href="https://www.openstreetmap.org/#map=13/27.977272/34.394717" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">openstreetmap.org/#map=13/27.9</span><span class="invisible">77272/34.394717</span></a></p><p><a href="https://mastodon.world/tags/HESH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HESH</span></a> <a href="https://mastodon.world/tags/SSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SSH</span></a> <a href="https://mastodon.world/tags/SharmElSheikh" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SharmElSheikh</span></a> <a href="https://mastodon.world/tags/Egypt" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Egypt</span></a> <a href="https://mastodon.world/tags/airport" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>airport</span></a> <a href="https://mastodon.world/tags/aviation" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>aviation</span></a> <a href="https://mastodon.world/tags/avgeeks" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>avgeeks</span></a> <a href="https://mastodon.world/tags/GIS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GIS</span></a></p>

Im Juli sorgten zwei #SSH CVEs für Aufsehen. #SUSE Manager 5.0 und Leap Micro 6.0 sind erschienen und #CentOS 7 wurde eingestellt. Weitere Backup-Provider wollen #Proxmox unterstützen. #Firefox 128 verärgert mit PPA, das openSUSE-Projekt diskutiert lebhaft ein Rebranding. Canonical will Docker-Container zukünftig bis zu 12 Jahre unterstützen, während #FreeBSD den Supportzyklus verkürzt.

🎧 focusonlinux.podigee.io/112-ne

Hey! Let's talk about #SSH and #security!

If you've ever looked at SSH server logs you know what I'm about to say: Any SSH server connected to the public Internet is getting bombarded by constant attempts to log in. Not just a few of them. A *lot* of them. Sometimes even dozens per second. And this problem is not going away; it is, in fact, getting worse. And attackers' behavior is changing.

The graph attached to this post shows the number of attempted SSH logins per day to one of @cloudlab s clusters over a four-year period. It peaks at about 3.4 million login attempts per day.

This is part of a study we did on our production system, using logs of more than 640 million login attempts, covering more than 1,500 hosts on our side and observing more than 840 thousand incoming IP addresses.

A paper presenting our analysis and a new, highly effective means to block SSH brute force attacks ("Where The Wild Things Are: Brute-Force SSH Attacks In The Wild And How To Stop Them") will be presented next week at #NSDI24 by @sachindhke . The full paper is at flux.utah.edu/paper/singh-nsdi

Let's dive in. 🧵

Continued thread

Durch Good-Cop/Bad-Cop-Taktiken wurden Softwareentwickler dazu gedrängt, subtil versteckte Sicherheitslücken einzubauen. Wie können wir das zukünftig vermeiden?
.
1️⃣ Vereinfachung/Reduzierung von Programmen und Abhängigkeiten
2️⃣ Mehr Wertschätzung und Unterstützung für die Open-Source-Entwickler
3️⃣ Bessere Kontrolle, aber ohne Belastung für die Entwickler
4️⃣ Angewandtere Ausbildung

Was sind eure Ideen dazu? Freue mich auf Feedback!

#xz #lzma #ssh #FOSS #FLOSS #OSS
marcel-waldvogel.ch/2024/04/02

Marcel Waldvogel · Wie die Open-Source-Community an Ostern die (IT-)Welt retteteHuch, waren das spannende Ostern, aus IT-Sicht! Es wurde die potenziell schlimmste IT-Sicherheitskatastrophe durch puren Zufall noch rechtzeitig abgewendet. Ansonsten hätte ein Angreifer Millionen von Servern weltweit im Nu unter seine Kontrolle bringen können. TL;DR (oder: Das Wichtigste in
Continued thread

Der Angriff hatte zum Ziel, Abermillionen von Servern weltweit für die unbekannten Angreifer zu öffnen. Was diese mit den Früchten der Vorbereitung der letzten 3 Jahre dann hätten erreichen wollen, das werden wir wohl nie erfahren. Aber die potenziellen Auswirkungen auf Abermillionen von Nutzerinnen, ihren Daten aber auch die Wirtschaft und Stabilität von ganzen Ländern hätten dramatisch werden können.
#xz #lzma #ssh
dnip.ch/2024/04/02/xz-open-sou

Wir sind dieses Wochenende nur durch unglaubliches Glück und extrem knapp an wohl einer der grössten Katastrophen rund um die globale IT-Sicherheit vorbeigeschrammt.

Phuh! Doch — was ist eigentlich passiert? Wie konnte das überhaupt geschehen? Und was können (und müssen) wir tun, um dies zukünftig zu vermeiden?

Und: Danke an die ganzen IT-Helden, die dies an diesem langen Wochenende für uns getan haben.
#xz #lzma #ssh
dnip.ch/2024/04/02/xz-open-sou

📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #04/2024 is out! It includes the following and much more:

🔓 🧬 #23andMe admits it didn’t detect #cyberattacks for months
🔓 #Trello API abused to link email addresses to 15 million accounts
🔓 🇺🇸 #LoanDepot Breach: 16.6 Million People Impacted
🇺🇸 🇷🇺 #Microsoft network breached through password-spraying by Russian-state hackers
🇷🇺 🇺🇸 Russian #TrickBot Mastermind Gets 5-Year Prison Sentence for #Cybercrime Spree
🇺🇸 🇷🇺 #HPE says it was hacked by Russian group behind Microsoft email #breach
🇷🇺 🇸🇪 Russian Hackers Suspected of #Sweden Cyberattack
✈️ 💰 Aviation Leasing Giant #AerCap Hit by #Ransomware Attack
🇺🇸 📲 #SEC blames sim-swapping, lack of MFA for X account hijacking
🇨🇳 Chinese Hackers Silently Weaponized #VMware Zero-Day Flaw for 2 Years
🔔 👮🏻‍♂️ Ring Will No Longer Allow Police to Request Doorbell Camera Footage From Users
🇫🇷 👀 French regulator fines #Amazon $35 million over its surveillance system of warehouse workers
🇫🇷 🍪 #France Fines #Yahoo 10 Mn Euros Over Cookie Abuses
🍎 💸 Cracked #macOS apps drain wallets using scripts fetched from DNS records
🦠 🔑 Malicious #NPM Packages Exfiltrate Hundreds of Developer #SSH Keys via #GitHub
🦠 💻 NS-STEALER Uses Discord Bots to Exfiltrate Your #Secrets from Popular Browsers
🐥 🔑 X adds #passkeys support for #iOS users in the United States
🩹 🚨 Critical #Jenkins Vulnerability Exposes Servers to RCE Attacks - #Patch ASAP!
🤖 💥 AI will increase the number and impact of cyber attacks, intel officers say
🐛 🩹 Exploit released for Fortra #GoAnywhere MFT auth bypass bug
🔓 ⚡#Pwn2Own Automotive: Hackers Earn Over $700k for #Tesla, EV Charger, Infotainment Exploits
🔓 🇨🇳 Mass exploitation of #Ivanti VPNs is infecting networks around the globe
🍎 🩹 Apple Issues #Patch for Critical Zero-Day in #iPhones, Macs - Update Now

Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

infosec-mashup.santolaria.net/

X’s Infosec Newsletter · InfoSec MASHUP - Week 04/2024By Xavier «X» Santolaria

We have just issued the first #release of #sshd-openpgp-auth and #ssh-openpgp-auth.

Using this server and client-side tooling it is possible to manage the #authentication of #SSH host keys with the help of an #OpenPGP certificate as trust anchor.

crates.io/crates/sshd-openpgp-

crates.io/crates/ssh-openpgp-a

Many thanks to @wiktor for the great collaboration and #NLnet / #NGIAssure for funding this work!

crates.iocrates.io: Rust Package Registry

CC @ubernauten

Meine (nicht-öffentliche) Nextcloud und bald bestimmt mehr ist auf (A)steroiden, cause proudly hosted by uberspace.de. (Steroide sind natürlich nur für Maschinen OK, und auch nur so lange, wie sie sich nicht gewerkschaftlich organisieren, wie bei Stanislav Lem.)

Außerdem nutze ich @Codeberg,@cryptpad,@duckduckgo, @mxlinux,@keepassxc,#vnc+#ssh,@git,#gittfs,#gitcrypt,@libreoffice,@thunderbird,#chromiumungoogled*#chrlauncher,@fdroidorg,@libretube,@AntennaPod,#opencamera,@anysoftkeyboard,#quickdic,#transportr,@torproject,@signalapp,#jitsi,@Tusky,#mgit,#markor,#PilfershushJammer,#fosswarn,#vlc,#doublecmd,#powershell,#autohotkey,#xca,#openssl,#zapp,@privacybrowser,#UntrackMe,@veracrypt,#AuthPass,@newpipe,#radiodroid,#edslite,#SecScanQR,#sqlitedbbrowser,#avnc,@k9mail,u.V.m., überhaupt privat fast nur und im Job so viel wie geht #floss , im Netz und lokal.

–––

Warum FLOSS? U.A. deshalb:

KI – Macht – Ungleichheit. media.ccc.de/v/ce4743cc-50ad-4

「新しい OpenSSH の脆弱性により Linux システムがリモート コマンド インジェクションにさらされる 」: The Hacker News

「この脆弱性により、リモートの攻撃者が脆弱な OpenSSH の転送された #ssh エージェント上で任意のコマンドを実行する可能性があります」
thehackernews.com/2023/07/new-

#Ubuntu 22.04.2 の最新版では、 #openssh は version 8.9p1-3 ですが、この #脆弱性 については既に #パッチ が当たっています。

The Hacker NewsNew OpenSSH Vulnerability Exposes Linux Systems to Remote Command InjectionA recently patched flaw in OpenSSH (CVE-2023-38408) could allow remote attackers to run arbitrary commands on vulnerable hosts.