Discussion
Loading...

#Tag

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
jomo
@jomo@mstdn.io  ·  activity timestamp 4 days ago

FYI: The sudo-rs bug of leaking passwords on timeout is a general problem of line buffered stdin streams.

The `read` builtin suffers from the same problem.

https://github.com/trifectatechfoundation/sudo-rs/security/advisories/GHSA-c978-wq47-pvvw

#sudors #sudo_rs #bash #CVE_2025_64170 #infosec

GitHub

Partial password reveal when password timeout occurs

### Summary When typing partial passwords but not pressing return for a long time, a password timeout can occur. When this happens, the keys pressed are replayed onto the console. ### Example ...
Your browser does not support the video tag.
GIF
GIF
Video of a shell showing the command `read -t 5 -s password || echo timed out`. After 5 seconds, "timed out" is printed and the previously invisible "s3cr3t!" is printed after the prompt string on the next line.
Video of a shell showing the command `read -t 5 -s password || echo timed out`. After 5 seconds, "timed out" is printed and the previously invisible "s3cr3t!" is printed after the prompt string on the next line.
  • Copy link
  • Flag this post
  • Block
jbz
@jbz@indieweb.social  ·  activity timestamp 4 days ago

RIIR was written on the cross

https://lists.debian.org/debian-security-announce/2025/msg00218.html

#sudors #opensource

[SECURITY] [DSA 6052-1] rust-sudo-rs security update

  • Copy link
  • Flag this post
  • Block
jbz
@jbz@indieweb.social  ·  activity timestamp 2 months ago

🦀 sudo-rs Is Now The Default sudo Of Ubuntu 25.10 - Phoronix

https://www.phoronix.com/news/Ubuntu--Now-Default-sudo-rs

#sudors #ubuntu #rust

jmcunx
@jmcunx@mastodon.sdf.org replied  ·  activity timestamp 2 months ago
@jbz

Good work and nice, but were issues fixed and complexities made simpler.

Personality I think they should have made doas the default 😊 And if they wanted to, once people get use to it, convert it to rust.

#sudors #ubuntu #rust #openbsd

  • Copy link
  • Flag this comment
  • Block
jbz
@jbz@indieweb.social  ·  activity timestamp 2 months ago

🦀 sudo-rs Is Now The Default sudo Of Ubuntu 25.10 - Phoronix

https://www.phoronix.com/news/Ubuntu--Now-Default-sudo-rs

#sudors #ubuntu #rust

  • Copy link
  • Flag this post
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login