journalctl -u micro
https://depthfirst.com/nginx-rift
Red Hot Cyber
Fragnesia: arriva un terzo bug LPE in Linux che mette a rischio i sistemi
La vulnerabilità Fragnesia colpisce il kernel Linux, consentendo agli utenti malintenzionati di ottenere i privilegi di root. Scopri di più su come proteggerti
😭1
Il rasoio di Occam ha quasi sempre ragione.
Il dispositivo continua a disconnettersi?
Indovinate la causa...la scheda di rete
Puntualmente leschede realtek USB che siano per wifi o ethernet su Linux fanno davvero piangere.
Il dispositivo continua a disconnettersi?
Indovinate la causa
Puntualmente le
Installato PiHole dopo tanto tempo che mi dicevo di farlo, un'ora in tutto.
• configurato docker compose, passwd custom, domini custom
• disabilitata la funzione dns dell'istanza dnsmasq nativa
(che agisce comunque da dhcp, nel caso docker morisse)
• aggiunto una blocklist custom con letteralmente tutto
https://github.com/hagezi/dns-blocklists#ultimate
• testato con domini consentiti e bloccati
• configurato docker compose, passwd custom, domini custom
• disabilitata la funzione dns dell'istanza dnsmasq nativa
(che agisce comunque da dhcp, nel caso docker morisse)
• aggiunto una blocklist custom con letteralmente tutto
https://github.com/hagezi/dns-blocklists#ultimate
• testato con domini consentiti e bloccati
GitHub
GitHub - hagezi/dns-blocklists: DNS-Blocklists: For a better internet - keep the internet clean!
DNS-Blocklists: For a better internet - keep the internet clean! - hagezi/dns-blocklists
Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux. The file name transformers.pyz appears deliberately chosen to mimic the widely used Hugging Face Transformers library and blend into ML/dev environments.
The main payload is a credential stealer, but it also includes country-aware logic; it avoids Russian-language environments and contains a geo fenced destructive branch that has 1-in-6 chance of executing rm -rf / when the system appears to be in Israel or Iran.
To mitigate this threat: isolate affected Linux hosts, block 83[.]142[.]209[.]194, hunt for /tmp/transformers.pyz, pgmonitor[.]py, and pgsql-monitor.service, and rotate exposed credentials.
FixupX
Microsoft Threat Intelligence (@MsftSecIntel)
Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage…
🔥1
Forwarded from Gianmarco Gargiulo Mastodon Bridge
You REALLY should remove the tracking codes from Youtube links now.
They started showing a popup about who sent the link and offering a (maybe new) DM feature, potentially revealing your personal account name to anyone who opens the link.
They started showing a popup about who sent the link and offering a (maybe new) DM feature, potentially revealing your personal account name to anyone who opens the link.
Forwarded from Gianmarco Gargiulo Mastodon Bridge
you can anonymize the link by removing the part of the link after the “?”
(at least for youtube currently, this can be different on other platforms and may also change in the future)
(at least for youtube currently, this can be different on other platforms and may also change in the future)
Forwarded from /g/ Library
YouTube
I was laid off by Atlassian
00:00 Intro
00:58 Interview process
04:16 Starting at Atlassian
04:35 Building an Open Service Broker
07:43 Diagram of OSB architecture
09:56 Picking a proxy technology - Envoy
11:36 Envoy XDS Control Plane
14:33 AWS Infrastructure
17:45 Creating the machine…
00:58 Interview process
04:16 Starting at Atlassian
04:35 Building an Open Service Broker
07:43 Diagram of OSB architecture
09:56 Picking a proxy technology - Envoy
11:36 Envoy XDS Control Plane
14:33 AWS Infrastructure
17:45 Creating the machine…
SELF HOSTED SWEDISH FOSS DISCORD ALTERNATIVE?
https://fluxer.app/
https://github.com/fluxerapp/fluxer
È in super early-development, non aspettatevi nulla.
Se vedete dei piani a pagamento, riferiscono solo alla loro istanza pubblica
https://fluxer.app/
https://github.com/fluxerapp/fluxer
È in super early-development, non aspettatevi nulla.
Se vedete dei piani a pagamento, riferiscono solo alla loro istanza pubblica
Fluxer
Fluxer - A chat app that puts you first
Free and open source chat for friends, groups, and communities, with text, voice, video, screen sharing, and self-hosting.
🔥1
journalctl -u micro
Voi conoscete questa distro? Idee? https://bazzite.gg/ • rpm-based • snapshot readonly avviabili ad ogni aggiornamento • secureboot • luks • driver aggiuntivi preinstallati • kde (oppure gnome) • waydroid ecc
Distro molto interessante che combina CachyOS con l'atomicità di Bazzite / Fedora
• Fedora Atomic Core (RPM os-tree)
• Cosmic Desktop
• Rust CLI toolkit (vabbè)
• CachyOS LTO kernel, scx schedulers, optimized I/O
• ed altro
https://origami.wf/
• Fedora Atomic Core (RPM os-tree)
• Cosmic Desktop
• Rust CLI toolkit (vabbè)
• CachyOS LTO kernel, scx schedulers, optimized I/O
• ed altro
https://origami.wf/
origami.wf
Origami Linux
Next‑generation Fedora Atomic based distro with Cosmic desktop.
A lavoro sto facendo un servizio in php multiprocesso. Devo gestire
Puntualmente il servizio non riceve il segnale. Cos'ho sbagliato?
Provo a mettere il comando di avvio nel composefile in forma exec (con un array) così non si crea una shell, il servizio avrà pid 1 ricevendo così direttamente i segnali ...niente
Provo a usare il flag
Provo a impostare gli handler a mano bypassando ReactPHP ...niente
Controllo la maschera dei segnali gestiti ...tutto ok
Poi mi sono rotto il cazzo ed ho usato
SIGTERM per chiudere tutto in modo pulito. Sto usando docker.Puntualmente il servizio non riceve il segnale. Cos'ho sbagliato?
Provo a mettere il comando di avvio nel composefile in forma exec (con un array) così non si crea una shell, il servizio avrà pid 1 ricevendo così direttamente i segnali ...niente
Provo a usare il flag
init che internamente usa tini come gestore processi ...nienteProvo a impostare gli handler a mano bypassando ReactPHP ...niente
Controllo la maschera dei segnali gestiti ...tutto ok
$ grep SigCgt /proc/PID/status
SigCgt: 0000000004004a07
Poi mi sono rotto il cazzo ed ho usato
strace ...insomma il segnale lo riceveva, ma non quello giusto: SIGWINCH ...perché l'immagine base del container docker è apache, che imposta un STOPSIGNAL custom nel dockerfile.Media is too big
VIEW IN TELEGRAM
source
AIPAC (American Israel Public Affairs Committee) è una delle lobby politiche più influenti degli Stati Uniti. Fondata nel 1951, lavora per rafforzare i rapporti tra USA e Israele e sostiene politiche considerate favorevoli allo Stato israeliano.
Negli anni è diventata una delle organizzazioni più potenti di Washington, con forte influenza sul Congresso americano attraverso attività di lobbying, campagne politiche e relazioni istituzionali.
I critici di AIPAC sostengono che dovrebbe registrarsi sotto il FARA (Foreign Agents Registration Act), la legge americana che regola chi opera polit...
Forwarded from Gianmarco Gargiulo Mastodon Bridge
#Google publishes exploit code threatening millions of #Chromium users
https://arstechnica.com/security/2026/05/google-publishes-exploit-code-threatening-millions-of-chromium-users/
#Chrome #cybersecurity
https://arstechnica.com/security/2026/05/google-publishes-exploit-code-threatening-millions-of-chromium-users/
#Chrome #cybersecurity
Ars Technica
Google publishes exploit code threatening millions of Chromium users
Google publishes exploit code before patch, reported 42 months earlier, is fixed.
Forwarded from Gianmarco Gargiulo Mastodon Bridge
This is what peak I/O shield looks like.
VGA, DVI, DisplayPort, or HDMI? Yes.
Analog 7.1 or optical audio? Yes.
PS/2, USB2 or USB3? Yes.
eSATA? Yes. Two.
Bonus RS232 with a 3D printed bracket on the side~
(From an old home server I just shut down after many years ^^)
VGA, DVI, DisplayPort, or HDMI? Yes.
Analog 7.1 or optical audio? Yes.
PS/2, USB2 or USB3? Yes.
eSATA? Yes. Two.
Bonus RS232 with a 3D printed bracket on the side~
(From an old home server I just shut down after many years ^^)
❤1
Forwarded from Gianmarco Gargiulo Mastodon Bridge
APKPure is distributing a malicious copy of Telegram Article URL: https://xcancel.com/EricParker/status/2058411298195661221 Comments URL: https://news.ycombinator.com/item?id=48255605 Points: 1 # C...
Origin | Interest | Match
Origin | Interest | Match
Tentando disperatamente di far andare l'LSP Intelephense via ssh, puntualmente continua a crashare.
Ho provato di nuovo
Però dopo tanto tempo ho notato che crasha con troppa precisione, sempre 3 secondi sia senza che con
Guardo... c'è un timer DI 3 SECONDI che controlla se il processo padre passato via messaggi esiste ancora (internamente esegue
Trucco: passare pid 0, così la syscall avrà sempre successo — l'LSP non muore più.
Ore spese nette: >16
Ho provato di nuovo
strace, a loggare stdin/stdout dei messaggi jsonrpc, niente.Però dopo tanto tempo ho notato che crasha con troppa precisione, sempre 3 secondi sia senza che con
strace (che normalmente rallenta di molto i processi).Guardo... c'è un timer DI 3 SECONDI che controlla se il processo padre passato via messaggi esiste ancora (internamente esegue
kill) altrimenti muore. Peccato che in un ambiente remoto i pid siano completamente diversi.Trucco: passare pid 0, così la syscall avrà sempre successo — l'LSP non muore più.
Ore spese nette: >16
🤯2👍1