Copy Fail
copy.fail
Copy Fail
1–10 of 545 posts
Re: Copy Fail
#2Is there a readable version of the exploit readily available by any chance? Gotta admit that I failed binary-zip-interpretation-with-naked-eye class twice
Re: Copy Fail
#3What is the rationale behind naming
CVEs and individual domains? Marketing?
Re: Copy Fail
#4What is the rationale behind naming CVEs and individual domains? Marketing?
It makes sure people don't forget about the vulnerabilities, at least
Re: Copy Fail
#5What is the rationale behind naming CVEs and individual domains? Marketing?
Same reason they name storms, numbers scare normies
Re: Copy Fail
#6Is there a readable version of the exploit readily available by any chance? Gotta admit that I failed binary-zip-interpretation-with-naked-eye class twice
The binary "zip" isn't the exploit, it's the shellcode. The exploit is the rest, which changes the code of a SUID executable (su).
Re: Copy Fail
#7What is the rationale behind naming CVEs and individual domains? Marketing?
Probably to some extent it is marketing, but generally it has to do with significant bug finds to get the message out to the people who need to apply patches and/or be informed. Heartbleed, Log4Shell, etc.
Very few CVE’s get names dedicated to them like this, because usually when they do - it is very serious, as in this case.
Re: Copy Fail
#8Is this fixed in any stable release kernel yet?
Re: Copy Fail
#9This looks like an extraordinary find at first glance.
Does this mean you can go from a basic web shell from a shared hosting account to root? I can see how that could wreak havoc really quickly.
Re: Copy Fail
#10If this is verified, this is a very big deal. Root access on any shared computer. Additionally do we know what kernel versions and stable versions have the patch?