Hi folks, today I found around the corner a huge XTerm code injection.
DECRQSS Device Control Request Status String "DCS $ q" simply echoes
(responds with) invalid commands.
Exploitability is the same as for the "window title reporting" issue
in DSA-380: include the DCS string in an email message to the victim,
or arrange to have it in syslog to be viewed by root.
So for example:
perl -e 'print "eP$qnetstatne\' > bla.log
cat bla.log ; would run the ""netstat"" command.
"

Introduction i-SOON (上海安洵), a prominent contractor for various Chinese government agencies such […]
When I saw a threat actor hijacking the X account of Google's […]
LOCKBIT 3.0 is a notorious Ransomware Group that was first identified on […]