Qué interesante esto!

Con un código de Python de 10 líneas podés acceder a una shell de root en la mayoría de las distros GNU/Linux 🤔

Lo acabo de probar en @archlinux (actualizado la semana pasada) y @kalilinux, y ambos son vulnerables.

🔥 Solución rápida: desactivar el módulo del kernel algif:

# echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif-aead.conf

# rmmod algif_aead 2>/dev/null

+info: https://xint.io/blog/copy-fail-linux-distributions

#happyHacking

#gnu #linux #copyfail

Copy Fail: 732 Bytes to Root on Every Major Linux Distribution. - Xint

Xint Code disclosed CVE-2026-31431, an authencesn scratch-write bug chaining AF_ALG + splice() into a 4-byte page cache write. A 732-byte PoC gets root on Ubuntu, Amazon Linux, RHEL, SUSE. | AI for Security, Vulnerability Research

@dani .. ohÁ ! back to 1990 ,
in garage, toying with one of those intel 486 DX CPUs .

#retrocomputing

#happyhacking

Update. When all the parts for the projects are finally complete. It was expensive and delivery times were longer than expected, even for an order within Germany.
#happyhacking

And `Den`got a proper documentation now too.

https://den-odm.readthedocs.io/en/stable/

#golang #happyhacking

Den - Den

An ODM for Go with SQLite and PostgreSQL backends

A quiet, productive day so far:

- Released 0.4.0 of my ODM `Den` with new features and bug fixes.
- Switched my web framework `Burrow` from Bun to Den and released 0.11.0.
- Moved the documentation for Burrow to readthedocs.org
https://burrow.readthedocs.io/en/stable/

A Sunday, that makes me happy.

#golang #happyhacking

Burrow - Burrow

A modular Go web framework built on Chi, Den, and html/template

My own version: If we fight for Free Software and Open Source, democracy stays relevant and is not going away. #fosdem
I will go to the monthly sleep again. #HappyHacking

Along with getting a NovaCustom laptop (discussed elsewhere) — in part b/c I didn't like the keyboard — I switched to traveling w/ an external keyboard. I chose the #HappyHacking Studio model which has a “pointer stick” (similar to a #TrackPoint). I like it enough I've replaced my very old #HHKB (3 models since discontinued) w/ Studio on the desk.

I do find my finger occasionally hits the stick when typing words w/ those nearby letters. I'm not sure how big the problem is, so I #AskFedi …(1/2)

⚠️ SYSTEM LOG
Shutting down: 2025
EuskalHack wishes you happy holidays and a bug-free end of year.
2026 is loading…
#EuskalHack #HappyHacking

#hackers and #tinkerers a new #2600 meeting in #Madrid & all the info about the next 2600 meeting, December 5 in Madrid, is on #usenet newsgroups #alt.2600 #alt.2600.madrid & #alt.2600.hackers also location is on https://2600.madrid and if you hate like myself the bloated web you can find it on #gemini at gemini://2600.madrid also for #worldwide meetings visit https://2600.com/meetings
#happyHacking #2600 #hackingIsNotACrime #hackerculture #usenet #hacking

@[email protected] @2600
@hispagatos

2600 Madrid! – 2600 Madrid

Amatör Telsizcilik ile İletişimin Sınırlarını Aş!

Etkinliğin İçeriği
* Amatör Telsizciliğe Giriş
* Nasıl Amatör Telsizci Olunur
* Amatör Telsizcilikte Kullanılan Ekipmanlar
* Amatör Telsizciliğin Topluluk Ruhu

Sen de Katıl! -> https://join.happyhacking.space

#diyarbakır #happyhacking