• henfredemars@infosec.pub
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 month ago

    Entirely personal recommendation, take it or leave it: I’ve seen and attacked enough of this codebase to remove any CUPS service, binary and library from any of my systems and never again use a UNIX system to print. I’m also removing every zeroconf / avahi / bonjour listener. You might consider doing the same.

    Great advice. It would appear these developers don’t take security seriously.

    • masterofn001@lemmy.ca
      link
      fedilink
      arrow-up
      1
      ·
      1 month ago

      Mdns is something most people have no idea exists.

      Oh, neat, all my devices broadcast all their open ports, services, addresses, hardware and names? Cool!

      No.

      • SmoothLiquidation@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 month ago

        If your router/firewall is configured to let these broadcasts through you have a problem. If it is working correctly and you have an attacker on your lan? You have already lost.