CollabVM Wikia/Socket.io: Difference between revisions
import>Dumbassposer106 No edit summary |
import>Mv m Bot: Reverted to revision 3662 by Dartz on May 22 2022 02:14:37 |
||
Line 1: | Line 1: | ||
Originally, CollabVM was run on (shitty) software called Socket.io. Full of vulnerabilities, this was the basis of Dartz' growing site. One infamous guy, Debianguy(Colonial Seizureton or the guest that keeps installing Tiny Core Linux) abused exploits to send a shutdown command directly to qemu command lines. Those same vulnerabilities exist on socket.computer, despite the owner aware of their possible effects on the server. Those vulnerabilities are not to be disclosed, because, if used correctly(or incorrectly) one could overwrite node.js modules that are critical to servers all over the world. Dartz has since sent ways to fix these vulnerabilities, but the lazy-ass dev refuses to put them in use. So here he stands, waiting for someone to pmemsave the whole fucking server | |||
The countdown begins. How long before someone overwrites his socket.computer snapshot with a command to delete the System32 folder at startup or have the hard drive only with junk and no OS? Give it about a few months and it's bound to happen. |
Revision as of 14:52, 28 May 2022
Originally, CollabVM was run on (shitty) software called Socket.io. Full of vulnerabilities, this was the basis of Dartz' growing site. One infamous guy, Debianguy(Colonial Seizureton or the guest that keeps installing Tiny Core Linux) abused exploits to send a shutdown command directly to qemu command lines. Those same vulnerabilities exist on socket.computer, despite the owner aware of their possible effects on the server. Those vulnerabilities are not to be disclosed, because, if used correctly(or incorrectly) one could overwrite node.js modules that are critical to servers all over the world. Dartz has since sent ways to fix these vulnerabilities, but the lazy-ass dev refuses to put them in use. So here he stands, waiting for someone to pmemsave the whole fucking server
The countdown begins. How long before someone overwrites his socket.computer snapshot with a command to delete the System32 folder at startup or have the hard drive only with junk and no OS? Give it about a few months and it's bound to happen.