Take a look at my answer there. It was my fault apparently.
TL;DR: I set the image channel icon to /etc/paswd and forgot about it, people saw a suspicious call and panicked, sorry.
@infosec.pub
WannaCry targeted hospitals, businesses and similar machines.
WannaCry targeted everything with SMB exposed, blindly.
Also, you should read more about security through obscurity, the fact that "no one will target you because you are a low-value target" is a false sense of security.
Perhaps images, video, font etc. rendering could be compromised?
Yes, it already happen in the past. Also the Wi-Fi and Bluetooth stack got exploited, like multiple kernel drivers.
But it shouldn't be a matter of "in the past was X exploited?" but more on having a correct security posture.
Honestly if you are arguing about wasting a "perfectly working phone" you should blame it on the vendor, especially Android devices vendors have this let's say "defect" of dropping the support after 4/5 years.
Also not going to talk about custom ROMs (with the super rare exclusion of some) managed by god knows who, without any security team behind.
Since even the NFC and Cellular Network stack got vulnerabilities the only way you would consider an old phone "safe" to use is just turning it into the equivalent of a local ARM server.
Also pretty fun seeing the replies in the original post talking about how Google Play store shouldn't have malware on it.
Playing around with the SecureFlag platform, pretty interesting IMHO. Also want to start a new language to stick with, I am pretty undecided between Zig (but is not memory safe by design) elixir (functional programming still isn't my thing) and nim (can't handle any more language with indentation-based codeblocks).
Any suggestion is welcome, I will use them to build mostly security tools.
There is no such thing as ā100%ā malware detection especially if you are talking about signature based AV. On windows I just use the built-it security features. On OSX there is blockblock that checks any unknown binary on the system against VirusTotal, but still we are talking about Signatures. What I would suggest is going into an IDS like CrowStrike falcon, but is usually sold to enterprises and itās pricy.
I believe the risk of running outdated software is super inflated and mediatic, 99% of people would be absolutely fine running a version of Android from 3 years ago or Windows 8.
That's the same thing people running windows XP on internet were thinking in 2017.
Then WannaCry arrived and they got their data encrypted :)
Report quality (less FP) compared to semgrep, snyk and sonarcloud but a killer feature for me is that you get the call paths so you can see when and how a vulnerable dependency is called. Pretty useful on big codebases.
thanks for using Leebra!
go to feed...