!PbtOpdWBSRFbEZRLIf:numtide.com

Nix Community Projects

640 Members
Meta discussions related to https://nix-community.org. (For project specific discussions use github issues or projects own matrix channel). Need help from an admin? Open an issue on https://github.com/nix-community/infra/issues163 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
7 Jul 2024
@matthewcroughan:defenestrate.itmatthewcroughanYeah I just saw the version + the config not containing LoginGracePeriod 020:28:19
@matthewcroughan:defenestrate.itmatthewcroughanso maybe it's patched, I didn't look at that20:28:26
@emilazy:matrix.orgemily try nix derivation show $(readlink -f $(which ssh)) 20:29:00
@matthewcroughan:defenestrate.itmatthewcroughanThe server is in a bit of a memory exploded state20:29:27
@matthewcroughan:defenestrate.itmatthewcroughandmesg has logs I see on my scrappy servers when bad memory things happen :D20:29:41
@matthewcroughan:defenestrate.itmatthewcroughan

Looks like the only patches are

      "patches": "/nix/store/isik6ifcjxpw22sfh3kz37galficc78c-locale_archive.patch /nix/store/6id7rg81nbkx9r9pxvax7nssr11xdaas-gss-serv.c.patch?id=a7509603971ce2f3282486a43bb773b1b522af83 /nix/store/ybb4xs45dkngdf3x1xnxqgzn5zmv5alf-dont_create_privsep_path.patch /nix/store/7jbzj9s2wkbznn93ga3aqka6vfx06gjg-ssh-keysign-8.5.patch",

20:30:27
@matthewcroughan:defenestrate.itmatthewcroughan *

Looks like the only patches are

      "patches": "/nix/store/isik6ifcjxpw22sfh3kz37galficc78c-locale_archive.patch /nix/store/6id7rg81nbkx9r9pxvax7nssr11xdaas-gss-serv.c.patch?id=a7509603971ce2f3282486a43bb773b1b522af83 /nix/store/ybb4xs45dkngdf3x1xnxqgzn5zmv5alf-dont_create_privsep_path.patch /nix/store/7jbzj9s2wkbznn93ga3aqka6vfx06gjg-ssh-keysign-8.5.patch",
20:30:30
@matthewcroughan:defenestrate.itmatthewcroughanSo yes, it is in fact vulnerable :D20:31:20
@emilazy:matrix.orgemilythen I guess it's vulnerable20:31:24
@matthewcroughan:defenestrate.itmatthewcroughanShall we do a wordpress and hack it to fix it? 20:31:43
@matthewcroughan:defenestrate.itmatthewcroughanIt'd probably just end up rebooting into the generation with the vulnerability anyway20:32:13
@emilazy:matrix.orgemilygood luck, I don't think anyone has exploited it on a 64-bit system20:32:25
@matthewcroughan:defenestrate.itmatthewcroughanAh right, forgot about that20:32:39

Show newer messages


Back to Room ListRoom Version: 6