🕵️ SicherheitslückenCVE-2024-33668 | Zammad up to 6.2.x Upload Cache excessive authentication(17.09.2026 um 02:15 Uhr)
🕵️ SicherheitslückenCVE-2024-33668 | Zammad up to 6.2.x Upload Cache excessive authentication(17.09.2026 um 02:15 Uhr)
📰 IT Security Nachrichten 🕛 vor 8 Jahren 2 Min Lesezeit SECURITY-FEED
0

What would increase trust in hash-codes and public keys found on the internet: a sha256 hash for an internet-published file, published outside internet also

↗ Quelle (reddit.com)
🔬 IoC Intelligence (1 Indikatoren erkannt)
964ee9592e219a93759a26909e38a0e49201c52d6779d4597ef1c3152c54fe36
🗣️ Stimme:


SSL certificates, gpg and others are great, but current ways to use public keys for encryption and signing lack something that could be helped with little bit of separate from internet communication.

SSL certificate's secret key, the part that has to be kept hidden, might have been stolen in secret. Or worse, the organization itself might be crooked and deliver altered files to some percentage of downloaders or specific downloaders.

First time delivery of a public key over the internet is vulnerable.

SSL certificates have expiration dates. And for good reason.

This is mostly for when installing an OS, like a Linux distro, from an ISO file, to be used for years. Or when taking public keys for use. Single home users usually would not use this monthly, but maybe once per year.

There would be monthly hash and key file for many different open source projects, published on many sites. Then on some worldwide physical magazine or newspaper printed on paper and sold in streets, on it's classified ad section, a small ad containing the sha256 or sha512 code, the master-hash for the hash and key file.

This would not replace anything, just be extra and in addition to existing methods.

Also, as a possible extra, a monthly ceremony of video reading of the master-hash by various people, even on the internet, would increase trust.

Users of the hash and key file could be: Top 100 Linux distros, FreeBSD, OpenBSD, firefox, google, bitcoin, litecoin and other cryptocurrencies, some big repository of public keys, microsoft, apple...

.

This is output from sha256sum, a program in every Linux distro. Is it in mac and windows too? Reading this out loud takes a minute:

964ee9592e219a93759a26909e38a0e49201c52d6779d4597ef1c3152c54fe36


submitted by [comments]
Vollständiges Original-Advisory
Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf reddit.com.
↗ Original-Artikel auf reddit.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
3 Quellen
CVE-2020-20212 | MikroTik RouterOS 6.44.5 /nova/bin/console null pointer dereference
2 Quellen
CVE-2017-17537 | MikroTik RouterBOARD 6.39.2/6.40.5 TCP Service 53 input validation (EDB-43200 / ID 860320)
2 Quellen
CVE-2023-27169 | Xpand IT Write-Back Manager 2.3.1 hash predictable salt (EUVD-2023-30949)