损害 OpenWrt 供应链(🔥 得分:3 小时内 154+)
https://readhacker.news/s/6jeDY
https://readhacker.news/s/6jeDY
GMO Flatt Security Research
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection
Introduction
Hello, I’m RyotaK (@ryotkak
), a security engineer at Flatt Security Inc.
A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt
on my router.1 After accessing the LuCI, which is the web interface of OpenWrt…
Hello, I’m RyotaK (@ryotkak
), a security engineer at Flatt Security Inc.
A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt
on my router.1 After accessing the LuCI, which is the web interface of OpenWrt…
PostgreSQL 高可用性解决方案 – 第 1 部分:Jepsen 测试和 Patroni(❄️ 分数:1 周内 150+)...
https://readhacker.news/s/6iQAT
https://readhacker.news/s/6iQAT
除非我的手机可以成为一台 PC,否则我不想继续为额外的性能付费(得分:152+ in 1...
https://readhacker.news/s/6jd9N
https://readhacker.news/s/6jd9N
Android Authority
Unless my phone can be a PC too, I don't want to keep paying for extra performance
I've been using this year's fastest smartphones but I'm yet to find a use case that requires all this extra performance.
“Hetzner 决定取消我们的帐户并终止所有服务器。”
https://readhacker.news/s/6jfm9
https://readhacker.news/s/6jfm9
Mastodon
Kiwix (@kiwix@mastodon.social)
Attached: 1 image
So last week (on Sunday 1 December at 00:00), our server host canceled its service without warning.
TL;DR: we do not recommend using @Hetzner_Online@social.cologne 's service
Everyone else: a short 🧵
So last week (on Sunday 1 December at 00:00), our server host canceled its service without warning.
TL;DR: we do not recommend using @Hetzner_Online@social.cologne 's service
Everyone else: a short 🧵
Chuck E. Cheese 的电子动画乐队退出(❄️ 得分:6 天内 151+)
https://readhacker.news/s/6iU8y
https://readhacker.news/s/6iU8y
IEEE Spectrum
Chuck E. Cheese’s Animatronics Band Bows Out
By the end of this year, Chuck E. Cheese will retire the animatronics at all but 5 locations. Yes, the curtain is closing on Mr. Munch and his Make Believe Band. It took almost 50 years, but video screens have finally won out.
Curl_inet_ntop 和 Inet_ntop4 中的缓冲区溢出风险(得分:15 小时内 151+)
https://readhacker.news/s/6je5M
https://readhacker.news/s/6je5M
HackerOne
curl disclosed on HackerOne: Buffer Overflow Risk in Curl_inet_ntop...
*Curl is a software that I love and is an important tool for the world. *
*If my report doesn't align, I apologize for that.*
The `Curl_inet_ntop` function is designed to convert IP addresses from...
*If my report doesn't align, I apologize for that.*
The `Curl_inet_ntop` function is designed to convert IP addresses from...
全球近一半的青少年无法理解阅读(❄️ 分数:5 天 150+)
https://readhacker.news/s/6iY6C
https://readhacker.news/s/6iY6C
Our World in Data
Nearly half of teenagers globally cannot read with comprehension
The chart shows the share of children at the end of lower-secondary school age — aged 12 to 15 — who meet the minimum proficiency set by UNESCO in reading comprehension. This means they can connect the main ideas across various texts, understand the author’s…