Posts
3020
Following
700
Followers
1548
"I'm interested in all kinds of astronomy."
repeated

So this PoC for CVE-2024-49113 is indeed a thing.
https://www.safebreach.com/blog/ldapnightmare-safebreach-labs-publishes-first-proof-of-concept-exploit-for-cve-2024-49113/

Their writeup is confusingly worded in that it uses both the phrases "victim DC" and "any unpatched Windows Server (not just DCs)", in the same sentence nonetheless.

While the vul can be triggered by any lookup to a malicious LDAP server by any version of Windows, this particular PoC:
- Makes a MS-NRPC Netlogon Remote Protocol to talk to Windows Server, specifically DsrGetDcNameEx2, which gets info about the specified domain.
- Windows Server checks via DNS what LDAP server to talk to to get this info.
- Windows Server talks to the (malicious) LDAP server to service the request.
- The malicious LDAP server sends an unexpected LDAP referral value, causing LSASS.EXE, and subsequently Windows, to fall over.

It's perhaps important to note that CVE-2024-49113 is "just" a DoS, and CVE-2024-49112 is the more juicy RCE one. SafeBreach has indicated that they're still investigating what a full RCE chain might look like.

The fact that SafeBreach called their CVE-2024-49113 exploit "LDAPNightmare" is a bit deceptive, IMO, as CVE-2024-49112 is the thing of nightmares (CVSS 9.8). But hey, whatever gets clicks, amirite?

3
6
0
repeated

Does someone happen to have a copy of the tangara-hw git repo and could push it to Github? The official repo is 502ing right now

https://git.sr.ht/~jacqueline/tangara-hw

0
2
0
repeated
repeated

The back of the laptop will not come off :( :( :( no matter what I do :(

There is a diagram on the Lenovo site. They didn't seem to think this was important to include int he video, the video was just like "use caution". It's also baffling. There are "latches" that have to be "pried up". How do you "pry" a "latch". What does that mean. Does it mean apply force. Latch 3D simply will not unlatch and I can see new little-but-distinct creases forming in the aluminum back of the unit

4
1
0
@mcc Been there! Good know it's not just my English skills preventing me from getting these things open without breaking them!
0
0
0
@neurovagrant @futurebird While completely agree Defender's periodic scans can badly impact systems, esp. with HDD's, just like any other AV. My impression is that vendors put the bar for acceptable disk I/O pretty high assuming SSD's and no other disk-intensive jobs on consumer PC's.
0
0
2
#music #techno
Show content
AI SPACE by Anthony Rother is pretty nerdy:

https://anthonyrother.bandcamp.com/album/ai-space
0
0
0
As gas transfer via UA closed I'm heating the house with Ghidra.
0
0
4
repeated

Project Zero Bot

New Project Zero issue:

Windows Kernel False File Immutability attack on registry hives via the Cloud Filter API

https://project-zero.issues.chromium.org/issues/42451734

CVE-2024-49114
1
1
1
repeated
repeated
repeated

Progress security advisory: WhatsUp Gold Security Bulletin December 2024
@cR0w Progress allegedly published this advisory 12 December 2024, but the page wasn't available from Google search results (thank Gemini AI ✨ for being useless) and Progress doesn't maintain a dedicated security advisories section on their website. Anyway, this page hasn't been updated with new information since 12 December so it's also useless. Here are the three vulnerabilities:

  • CVE-2024-12105 (6.5 medium) authenticated information disclosure via specially crafted HTTP request
  • CVE-2024-12106 (9.4 critical) unauthenticated attacker can configure LDAP settings
  • CVE-2024-12108 (9.6 critical) an attacker can gain access to the WhatsUp Gold server via the public API

No mention of exploitation. Patched in WhatsUp Gold version 24.0.2

0
2
0
repeated

“This button vaporises the finger of anybody who presses it!”

“Why do you always focus on the negative? You critics should talk about the benefits of the Vaporiser2000™. Every press mints $100K USD. That’s an amazing societal benefit.”

“It mints it in the offices of those who make the button! The presser doesn’t get any. They’re using bribes and pressure to force the finger vaporisation onto others!”

“There you go again, focusing on the negative. This is why nobody takes critics seriously”

1
5
0
re: #shaving #influencing
Show content
@acsawdey Not for me unfortunately, my skin can't seem to handle it well :P (even at times when I couldn't give a damn about my looks my very stubborn laziness was overwhelmed by discomfort)
1
0
0
repeated

I think everyone who has an opinion, positive or negative, about LLMs, should read how @simon summed up what’s happened in the space this year. He’s the most credible, most independent, most honest, and most technically fluent person watching the space. https://simonwillison.net/2024/Dec/31/llms-in-2024/

4
8
0
repeated
repeated
Show older