Cybersecurity

8775 readers
82 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
 
 

Symlink bug in Gogs lets attacker commit a repo with a symlink pointing to a system file, and then Gogs will access the file under its own permissions I guess. Not good. Gogs should only run as an untrusted user though anyway.

Article doesn't say whether Gitea or Forgejo (both Gogs descendants) have the same bug.

Gogs, Gitea, and Forgejo are all Git forges (like Gitlab, basically a self-hosted Github-like web app) for those not familiar.

20
21
22
23
24
25
view more: next ›