QSI's "6 Degrees of Kevin Bacon's Quantum Sammich" aka Red Hat Intel: post #60 โ€” TG.ME

โœจQuantum Stellar Initiative (QSI)โœจThe "Next RedHat" Quantum Vegetarian Bacon Sammich Edition Social Media Bridges Post 5 of 8 Unlike Khazarians who invent a problem to sell a solution, White Hat ๐Ÿ˜ ๐Ÿ” ๐Ÿ” ๐Ÿ” ๐Ÿ” ๐Ÿ” ๐Ÿ” ๐Ÿ” ๐Ÿ”  ๐Ÿ˜ sees a problem and creates a free, open source solution for all ๐Ÿซถ April 2023:โ€ฆ
The "Next RedHat"
Quantum Vegetarian Bacon Sammich Edition
Social Media Bridges
Post 6 of 8


Sneakysneaks ๐Ÿฅท
๐Ÿ” ๐Ÿ” ๐Ÿ” ๐Ÿ” ๐Ÿ” ๐Ÿ” ๐Ÿ” ๐Ÿ”  ๐Ÿฅท

Just like how Ledger Nano claimed they have NO BACKDOOR for hackers, they (like Mastodon) decided to open their FRONTDOOR to the white hats instead
๐Ÿ˜๐Ÿ˜๐Ÿ˜


In 2023, the Mozilla Foundation contracted Cure53 to perform penetration testing on Mastodon's software, in preparation to bridge Mastodon with Mozilla's community. The testing "discovered" "several vulnerabilities", most notably one called "TootRoot" which would have enabled arbitrary code execution and another that would have enabled cross-site scripting attacks through oEmbed cards

Arbitrary Code Execution (ACE): an attacker's ability to run any commands or code of the attacker's choice on a target machine or in a target process. ACE vulnerability is a security flaw in software or hardware that would allow arbitrary code execution to hijack any or all Mastodon nodes/servers

Cross-Site Scripting (XSS): security vulnerability that can be found in some web applications. XSS attacks enable attackers to inject client-side scripts into web pages viewed by other users and may be used by attackers to bypass access controls

oEmbed: an open source form that enables embedding content from a website into another page. For example, Twitter uses it to embed tweets into blog posts. Squarespace, WordPress, Drupal, and LinkedIn all happen to embed content using oEmbed


โœ‹โœ‹โœ‹โœ‹โœ‹โœ‹โœ‹โœ‹โœ‹
While these vulnerabilities were supposedly "patched" in July 2023, we know that this patch was actually a test to prepare Mastodon's servers to eventually allow "white hat hackers" to hijack all of their nodes/servers in order to push specific content to individual users in 2024 Social Media Bridges as well as block nefarious servers and users
๐Ÿ˜ˆ๐Ÿ˜ˆ๐Ÿ˜ˆ
โœ‹โœ‹โœ‹โœ‹โœ‹โœ‹โœ‹โœ‹โœ‹


https://arstechnica.com/security/2023/07/mastodon-fixes-critical-tootroot-vulnerability-allowing-node-hijacking/


For example, in September 2023, the following bugs were discovered:

- Attackers can spoof domains they do not own

- By crafting specific input, attackers can inject arbitrary data into HTTP requests issued by Mastodon, which can be used to perform confused deputy attacks if the server configuration includes ALLOWED_PRIVATE_ADDRESSES to allow access to local exploitable services

- Under certain conditions, attackers can abuse the translation feature to bypass the server-side HTML sanitization, allowing unescaped HTML to execute in the browser. The impact is limited thanks to Mastodon's strict Content Security Policy, blocking inline scripts, etc. However a CSP bypass or loophole could be exploited to execute malicious XSS

https://github.com/mastodon/mastodon/security/advisories/GHSA-2693-xr3m-jhqr


โ˜•๏ธโ˜•๏ธโ˜•๏ธโ˜•๏ธโ˜•๏ธโ˜•๏ธโ˜•๏ธโ˜•๏ธโ˜•๏ธโ˜•๏ธ
So WHOSE private addresses are being allowed?
๐Ÿ˜ฌ and WHAT specific inputs are being crafted? ๐Ÿ˜ฌ๐Ÿ˜ฌ and WHAT certain conditions are being met to execute "malicious XSS" that they just patched 2 months earlier? ๐Ÿ˜ฌ๐Ÿ˜ฌ๐Ÿ˜ฌ
โ˜•๏ธโ˜•๏ธโ˜•๏ธโ˜•๏ธโ˜•๏ธโ˜•๏ธโ˜•๏ธโ˜•๏ธโ˜•๏ธโ˜•๏ธ


๐Ÿ“ฑ QSI Channel
๐Ÿ“ฑ Stellar & QFS Training App
Ars Technica
Mastodon fixes critical โ€œTootRootโ€ vulnerability allowing node hijacking
Most critical of the bugs allowed attackers to root federated instances.
โค13๐Ÿ”ฅ4๐Ÿ‘3
November 22, 2023 795 8