TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Fedora and Ubuntu 0-days show that hacking desktop Linux is now a thing

20 点作者 Liuser超过 8 年前

6 条评论

234dd57d2c8db超过 8 年前
Neat. Some steps that I take on my desktop linux on machines like my work machine that mitigate this attack:<p>- always run your browser in a restricted firejail. this prevents browser exploits from reading your ssh keys. It also makes it much harder to pivot to a root shell or maintain a persistent backdoor because the filesystem is deleted upon jail exit.<p>- don&#x27;t install multimedia applications on sensitive machines. My default install is ubuntu server with i3-wm,vim,git and other dev tools. No mplayer, no vlc, no multimedia. I listen to music on my phone if I want to jam out. The work computer is for work.<p>- use snapshotted VMs for interacting with sketchy files such as word docs, xlsx, mp3s, etc.<p>- default deny rules in iptables to block inbound connections<p>- static arp entry for the default route to prevent MITM on lan if possible. I do this on my work machine where the network is well known.
评论 #13191247 未加载
anonbanker超过 8 年前
So, this is exploitable if you&#x27;re running an SNES SPC backend in gstreamer, on a linux workstation.<p>That&#x27;s a big stretch, and a lot of hype for this &quot;0-day&quot;. How many people are going to be realistically affected by this? Why is arstechnica making such hype about it?<p>Yes, it&#x27;s novel that someone&#x27;s been able to break out of gstreamer&#x27;s sandbox using unimplemented (or poorly-implemented) 65816 opcodes, but that&#x27;s about as far as it goes.<p>Thankfully, my Calculate (Gentoo) Linux KDE desktop with a VLC backend is completely unaffected by this &quot;0-day&quot;, and everything on my network is safe.
评论 #13189673 未加载
评论 #13189668 未加载
aiur3la超过 8 年前
&gt; While Evans&#x27; attacks won&#x27;t work on most Linux servers, they will reliably compromise most desktop versions of Linux...<p>Nope, patched already in debian and ubuntu.
ryanlol超过 8 年前
So it wasn&#x27;t a thing before? But the couple of exploits developed by this guy made it a thing.<p>How come it wasn&#x27;t made a thing by similar exploits developed by others in the past decades?<p>Ars writes the strangest things sometimes.
finchisko超过 8 年前
Can properly setup apparmour&#x2F;selinux profile help migitate this vulnearibility?
nameless912超过 8 年前
This is good for linux!<p>Right?
评论 #13189678 未加载