@tanavit@toot.aquilenet.fr @MonniauxD@social.sciences.re "Command & Control": ce sont le ou les serveurs utilisés par les attaquants pour communiquer avec les systèmes compromis.
Remote
0
Followers
0
Following
4
Posts
Joined November 05, 2022
blog:
Posts
Open post
And here we go for the 2nd blog post about a vulnerability in Mastodon. It details how HTTP signatures can be bypassed because of an innocuous bug, and how it can lead to the spoofing of Mastodon instances depending on their domain name. Don't worry, infosec.exchange wasn't vulnerable ;)
https://scumjr.github.io/2023/11/07/usurping-mastodon-instances-cve-2023-42451/
28
2
20
0
Open post
Replying to
@chaos@infosec.exchange
The first blog post details a SSRF vuln in Mastodon, which leads to arbitrary code execution. No need to freak out, the vulnerability doesn't exist in prod in default configuration, and affected versions are limited to pre-releases.
https://scumjr.github.io/2023/10/12/from-ssrf-to-rce-on-mastodon-cve-2023-42450/
0
0
2
0
Remote instance
infosec.exchange
Open on original server