There's a critical vulnerability in D-Link NAS devices (CVE-2024-10914: NVD Details) that allows anyone to execute arbitrary commands via an HTTP request.
D-Link won’t fix it, claiming the affected devices are too old—even though some are under 10 years old.
In a technical write-up that provides exploit details, security researcher Netsecfish says that leveraging the vulnerability requires sending "a crafted HTTP GET request to the NAS device with malicious input in the name parameter.”
curl "http://[Target-IP]/cgi-bin/account_mgr.cgi cmd=cgi_user_add&name=%27;<INJECTED_SHELL_COMMAND>;%27"
https://www.circusscientist.com/2022/12/18/ubuntu-snap-update-spoiled-the-world-cup/
Читать полностью…blaurascon/113461106602355243" rel="nofollow">https://critter.cafe/@blaurascon/113461106602355243
Читать полностью…Source: mr_daemon/112079692981422897" rel="nofollow">https://untrusted.website/@mr_daemon/112079692981422897
Читать полностью…Source: https://www.tumblr.com/derinthescarletpescatarian/767127802757677056/why-are-they-built-that-way
Читать полностью…https://www.theverge.com/2024/11/14/24296375/the-onion-infowars-acquisition-alex-jones
Читать полностью…https://www.theverge.com/2024/11/5/24289124/mozilla-foundation-layoffs-advocacy-global-programs
Читать полностью…z80-sans: OpenType font that disassembles Z80 instructions
Source: https://github.com/nevesnunes/z80-sans