Earlier quoted context omitted.
Possibly Playstation as well.
Also Netgate's devices running PFSense.
FatGid: FreeBSD 14.x kernel local privilege escalation
21–30 of 46 posts
Re: FatGid: FreeBSD 14.x kernel local privilege escalation
#22Earlier quoted context omitted.
Why not? This weird complaint has been happening since ~2010 and it has never made any sense. You are strictly better off with the website than without it. When it was vulnerability researchers getting all peevish about the status competition they were running, I at least understood where the complaint was coming from, but even among practitioners, branded vulnerabilities are so much the norm at this point that there…
> You are strictly better off with the website than without it. Why? This is a better resource in every way: https://cgit.freebsd.org/src/commit/?id=000d5b52c19ff3858a6f... It details the actual problem instead of showing off tired stack exploit tricks.
Case in point: what's "tired" about the stack exploitation techniques they're using here?
And, while you're not right, even stipulating that you were, what would that matter? How is anyone better off with less explanation of a vulnerability?
Re: FatGid: FreeBSD 14.x kernel local privilege escalation
#23Earlier quoted context omitted.
It's a wall of text about a kernel stack overflow. I'm not sure where the "Elton John" part is. Is it... that they used an accent color?
Maybe the researcher was wearing windshield-wiper spectacles when he discovered the vulnerability. I don't understand why you're being so defensive about this.
These complaints aren't about what's better or worse for the user community; they're about people trying to put vulnerability researchers in their place.
Re: FatGid: FreeBSD 14.x kernel local privilege escalation
#24Earlier quoted context omitted.
Alas, TrueNAS actually switched to Linux a couple of years ago.
FreeBSD was the reason I chose TrueNAS Core. Unfortunately, you are right, TrueNAS Scale (Linux) is where they are focusing all their attention. At this point I will not purchase additional TrueNAS equipment as I feel I was "rug pulled." I get that they are going after more of the Docker container/app market, but I just want a solid ZFS w/excellent networking NAS device. Linux is close to this ideal, but it isn't as…
I mean that is the whole point of a NAS OS. It gives you a GUI and you don't have to worry about the rest.
Re: FatGid: FreeBSD 14.x kernel local privilege escalation
#25Re: FatGid: FreeBSD 14.x kernel local privilege escalation
#26Why does this need to be a whole ass website
Re: FatGid: FreeBSD 14.x kernel local privilege escalation
#27Earlier quoted context omitted.
Maybe the researcher was wearing windshield-wiper spectacles when he discovered the vulnerability. I don't understand why you're being so defensive about this.
Because it's a tiresome, tropey, and ultimately invalid complaint. Look downthread at the person who said the FreeBSD commit log was better than this page, despite being inscrutable to security practitioners who don't work in the kernel and not saying a word about proven exploit vectors. These complaints aren't about what's better or worse for the user community; they're about people trying to put vulnerability resea…
Re: FatGid: FreeBSD 14.x kernel local privilege escalation
#28Earlier quoted context omitted.
Because it's a tiresome, tropey, and ultimately invalid complaint. Look downthread at the person who said the FreeBSD commit log was better than this page, despite being inscrutable to security practitioners who don't work in the kernel and not saying a word about proven exploit vectors. These complaints aren't about what's better or worse for the user community; they're about people trying to put vulnerability resea…
While I believe whimsical names will always be silly, I do concede that commit log is effectively useless to 99% of eyeballs.
Re: FatGid: FreeBSD 14.x kernel local privilege escalation
#29Earlier quoted context omitted.
Why not? This weird complaint has been happening since ~2010 and it has never made any sense. You are strictly better off with the website than without it. When it was vulnerability researchers getting all peevish about the status competition they were running, I at least understood where the complaint was coming from, but even among practitioners, branded vulnerabilities are so much the norm at this point that there…
> You are strictly better off with the website than without it. Why? This is a better resource in every way: https://cgit.freebsd.org/src/commit/?id=000d5b52c19ff3858a6f... It details the actual problem instead of showing off tired stack exploit tricks.
git log -S suggests 4cd93df95e697942adf0ff038fc8f357cbb07cf9, which looks more likely: https://cgit.freebsd.org/src/commit/?id=4cd93df95e697942adf0... - though not to say you don't want the later commit too. I'm sure you do.
Re: FatGid: FreeBSD 14.x kernel local privilege escalation
#30Earlier quoted context omitted.
You're not going to get anywhere in the security sector unless you gain notoriety i.e. are noticed. This appears to come from dressing up like Elton John in a feather suit and hiring a marketing team.
It's a wall of text about a kernel stack overflow. I'm not sure where the "Elton John" part is. Is it... that they used an accent color?