serverok.pl is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
lonely small server
Admin email
postmaster@serverok.pl
Admin account
@mend0za@serverok.pl

Search results for tag #linux

Keepita :verified: :keepita: »
@Keepita@mastodon.world

There’s something special about a clean terminal and a fresh coffee on a system that just works the way you want it to.

Spent way too much time hopping distros, but Arch + KDE is where I finally settled. It’s nice not having to fight your own OS for once.

Anyone else rocking a custom setup? Drop a neofetch or a screenshot below, I’m looking for some fresh inspiration.

    brainwashed by lentils »
    @pelle@veganism.social

    SNeela »
    @vmcall@infosec.exchange

    Davide Ornaghi and Giuseppe Caruso found a very interesting bug in 's in-kernel Samba3 server from 6.12 to 6.19.x. Essentially, from the commit message and description:

    > Currently, ksmbd does not verify if the user attempting to reconnect to a durable handle is the same user who originally opened the file. This allows any authenticated user to hijack an orphaned durable handle by predicting or brute-forcing the persistent ID.

    Very interesting stuff! The kernel let's users resume their connection to an open file even after WiFi drops (durable handle), and a bug in this code let another authenticated user become this WiFi-dropped user, letting the hijacker access all files.

    github.com/TurtleARM/CVE-2026-

    CVE-2026-31717

      TelH90 »
      @kkarhan@c.im

      @mrmasterkeyboard @f4grx @projectanchorage yeah, I got build times of ~ 15min on an i7-6700k for -6.6.6 @ i486 and a stripped-down version of .

      Right now I try to replace with on @OS1337 so I don't waste >200 kB just on a when all I have is 1440 kB…

      It's jist that I don't get the quietness and time to do this properly…

        Rev Mook »
        @rev_mook@lsngl.us

        David Bombal »
        @davidbombal@infosec.exchange

        Learn Linux with David

          TelH90 »
          @kkarhan@c.im

          @mrmasterkeyboard @f4grx @projectanchorage *pressing thumbs*

          In terms of userland, you may want to take a look at when it comes to smol, tho that requires at least so propably not an option for you.

          - Not shure if i486 is a hard requirement or if @landley didn't bother with as it was 'd by .

            TelH90 »
            @kkarhan@c.im

            @landley @mrmasterkeyboard @f4grx @projectanchorage good to know. I guess prebuilds are not done due to lack of demand, which is understandable given mainline axed that before got released.

              matthew - retroedge.tech »
              @matthew@social.retroedge.tech

              Video Essay on "The Linux Anti-Distro Path" by YouTux Channel.

              https://youtu.be/kRqyllM_QAM

              #Linux #Alpine #gentoo #slackware #artix #Void

                Jonathan Mergy »
                @mergy@self.social

                @thomasfuchs made me flashback to the NAS I made running reiserFS...

                  Linux Renaissance PeerTube »
                  @darth@watch.linuxrenaissance.com

                  Your LG and Samsung TV's are, basically, spying on you

                  Automatic Content Recognition on your smart TV's is something that you should disable while you still can.

                  https://www.consumerreports.org/electronics/privacy/how-to-turn-off-smart-tv-snooping-features-a4840102036/

                  https://www.lg.com/global/newsroom/news/home-entertainment/lg-smart-tvs-get-a-new-acr-solution-legacy-technology-replaced-by-lg-ads-solutions/

                  Ad-free and privacy-respecting version of this video: https://tux-edu.tv/w/phzcXJWeLnVkeHxqGCzPcw

                  Make sure to motivate me for more content by, at least, liking the video and leaving a comment. It means a lot to me. Sharing this video with your friends is most welcome as is following this channel!

                  You can support the work financially here:
                  - https://ko-fi.com/darth

                  Social links:
                  - My webpage: https://linuxrenaissance.com
                  - I am fairly active on Mastodon: https://silversword.online/@darth
                  - My Matrix chat space: https://matrix.to/#/!LWfgnmBeCrpLbcWIlr:matrix.org
                  - My PeerTube channel: https://tux-edu.tv/c/lxr
                  - My YouTube chanel: https://youtube.com/@LinuxRenaissance
                  - My Odysee channel: https://odysee.com/@LinuxRenaissance:1

                  This video was edited with Kdenlive.

                  Intro / outro music is borrowed with permission from H0ffman:
                  https://soundcloud.com/h0ffman/sets/protracker-amiga

                  Alt...---

                    9Lukas5 🚂 🐧 »
                    @9Lukas5@mastodontech.de

                    *wants to see the help page for "reboot"
                    *types "reboot -h" 💁
                    *pc immediately reboots 😑
                    *tries again with "man reboot" 🤪

                      🗳

                      Kris Warner »
                      @kdwarn@social.coop

                      If you were thinking about switching from Debian/a Debian derivative, because you wanted to get away from LLMs/systemd, what would you switch to, particularly if you wanted the least amount of hassle? Other answers/reasons in comments if you like!

                      Debian but with OpenRc:0
                      Alpine Linux:0
                      Chimera Linux:0
                      OpenBSd:0

                        PH4NTXM :verified: »
                        @PH4NTXMOFFICIAL@infosec.exchange

                        🚨 PH4NTXM News!

                        PH4NTXM has officially entered its most stable state so far.

                        After extensive restructuring, cleanup, testing, and internal improvements, the project has moved beyond its experimental phase and is now operating in a far more mature and reliable form.

                        For long-time followers of the project:
                        thank you for sticking around during the early development and experimental stages. The repository has evolved significantly since then.

                        For newcomers discovering PH4NTXM for the first time:
                        welcome. Now is a great time to explore the project, test it, review the architecture, and follow its development.

                        The repository now includes:
                        • improved structure
                        • cleaner documentation
                        • refined operational flow
                        • better modularity
                        • more consistent behavior across components
                        • extensive technical documentation

                        PH4NTXM now ships with more than 60 dedicated documentation files covering the environment in depth, explaining components, architecture, operational flow, usage, deployment, and system behavior step-by-step.

                        The goal is not only to provide tooling, but also to make the project understandable, transparent, and accessible to the open-source community.

                        PH4NTXM remains fully open-source and community-driven.

                        Feedback, testing, discussions, issue reports, and contributions are always welcome from anyone interested in privacy, operational security, hardened Linux environments, and defensive tooling.

                        The experimental era is over.

                        PH4NTXM is now entering its stable phase.

                          Larvitz :fedora: »
                          @Larvitz@burningboard.net

                          Let's Encrypt just stopped the issuance of certificates after an "incident":

                          letsencrypt.status.io/pages/in

                          If anyone encounters issues today with failed certificate renewals: It's probably not your setup.

                            /G|T|R|O|N|I|X\ :python: :emacs: :nix: :linux: »
                            @gtronix@infosec.exchange

                            "Another major Linux security flaw revealed — 'Dirty Frag' allows root on all major distros, with no patch or fix available yet"

                            "A researcher shared their findings with Linux distro maintainers, but leaked before a patch was built."

                            techradar.com/pro/security/ano

                              hasamba » 🤖
                              @hasamba@infosec.exchange

                              ----------------

                              🎥 Video
                              ===================

                              Opening: The announcement describes a free webinar titled “Digital Forensics: Basic Linux Analysis After Data Exfiltration — Hackers Arise” scheduled for February 13, 2026. The core narrative emphasizes that intrusions often present as an adversary already resident in an environment rather than beginning with an obvious malware drop.

                              Technical Details: The event framing indicates a focus on post-exfiltration Linux analysis. Topics implied by the title and tagline include identification of forensic artifacts left after data exfiltration, methods to examine Linux hosts for traces of adversary activity, and investigator-centric techniques for reconstructing actions when initial compromise is not observable. The announcement explicitly centers on the concept that adversaries can be present before any exploit or payload execution.

                              Analysis: Framing investigations around the “adversary-inside” perspective shifts attention to persistence mechanisms, lateral movement artifacts, evidence of data staging and egress, and gaps in audit/visibility that enable prolonged dwell time. While the announcement does not list IoCs or specific tools, it signals an emphasis on host-level evidence collection and reasoning about timelines and artifact correlation on Linux systems.

                              Detection: Although the source does not provide detection signatures, the webinar’s scope suggests discussion of detection opportunities such as anomalous outbound connections, unusual file access patterns, unexpected scheduled jobs or services, and forensic indicators in system logs and memory snapshots.

                              Implications for IR practitioners: The stated narrative reinforces the need to treat post-exfiltration analysis as a distinct investigative discipline with its own priorities—establishing a timeline, locating exfiltration vectors, and validating whether data staging or covert channels were used.

                              Limitations: The announcement is a webinar summary and does not publish technical IoCs, ATT&CK IDs, or tooling details. Attendees should expect conceptual framing and case-oriented walkthroughs rather than a repository of signatures.

                              References: Event title and date as published by the organizers: “Digital Forensics: Basic Linux Analysis After Data Exfiltration — Hackers Arise”, Feb 13, 2026.

                              🔹 digitalforensics

                              🔗 Source: hackers-arise.com/digital-fore

                                lwnbot » 🤖
                                @lwnbot@c.im

                                [$] Forgejo "carrot disclosure" raises security questions lwn.net/Articles/1071499/

                                  Anthony »
                                  @adx@infosec.exchange

                                  The main complaint about the Linux on the desktop was how ugly and inconsistent the GUI applications looked.

                                  Looks like Mac and Windows devs are doing their best to have their platforms to be on par with Linux.

                                    Wouter 🛰️ »
                                    @pa3weg@mastodon.social

                                    Holy Shit, this is awesome! on the badge.

                                    github.com/mrbreaker/why2025-l

                                    Screenshot from the GitHub

                                    Screenshot of the WHY2025 badge running linux, showing some directory listings

                                    Alt...Screenshot of the WHY2025 badge running linux, showing some directory listings

                                      🦠Toxic Flange (Gurjeet)🔬⚱️🌚 »
                                      @Toxic_Flange@infosec.exchange

                                      Something I've complained about when people deploy Linux kernel based OS's is so few people ever tune or customizes their kernels or their base distro's.

                                      This used to be something old school sysadmins would do, as part of the basic security hygiene practice - "If you don't need it, don't include it", which applies to daemons , services and packages.

                                      Kernel compilation is something that rarely seems to happen too..

                                      Do you have hardware encryption capabilities you want things like wolfssl to use? Then sure use . Anything else? Highly unlikely.

                                      Are you running OpenSwan, or some other VPN or tunneling software that uses encapsulating tunnel options? No? Probably don't need ESP4/ESP6 modules.

                                      Easy for me to call out sure, and i'm taking myself to task as well, since really at work, they don't want people deep diving and compiling kernels in many places. "Trust the vendor" where many mgmt types don't get it or care. "Apt/DNF update and carry on".

                                      Funny because this the antithesis of their "resist patches, and updates" attitude towards software.

                                      The number of mongodb 3.x db's out there because the dev hasn't updated the driver, or the number of npm warnings "this is vulnerable, don't use this" that are ignored are high.

                                        securityaffairs »
                                        @securityaffairs@infosec.exchange

                                        John Shaft »
                                        @shaft@piaille.fr

                                        kernel exploit mitigation:

                                        rm -rf /boot /lib/modules && reboot

                                        Will mitigate all exploits, not just 🧐☝️

                                          :mastodon: decio »
                                          @decio@infosec.exchange

                                          Nouveaux kernels stables : 7.0.5 / 6.18.28 / 6.12.87 / 6.6.138

                                          Ils embarquent un fix partiel pour (CVE-2026-43284) et Copy Fail 2.

                                          Partiel, car Greg Kroah-Hartman a confirmé qu'un second patch est encore en développement et n'a pas encore été mergé.

                                          La mitigation par blacklist des modules reste donc recommandée en attendant.
                                          👇
                                          lwn.net/Articles/1071775/

                                            :mastodon: decio »
                                            @decio@infosec.exchange

                                            variante peu sympa 👀
                                            "Unprivileged Linux LPE via xfrm ESP-in-UDP MSG_SPLICE_PAGES no-COW fast path. Page-cache write into any readable file. Overwrites a nologin line in /etc/passwd with sick::0:0:...:/:/bin/bash and sus into it. Same class as Copy Fail (CVE-2026-31431), different subsystem."
                                            ⬇️
                                            github.com/0xdeadbeefnetwork/C

                                              Michaela Molthagen »
                                              @michaela@meerjungfrauengrotte.de

                                              Hm, neuerdings reagiert mein PC während der Boot-Phase, einschließlich GRUB, nicht mehr auf die Funkmaus oder Funktastatur.

                                              Erst, wenn der Anmeldebildschirm von Kubuntu auftaucht, funktionieren Maus und Tastatur.

                                              Bin mir nicht bewusst, im BIOS irgendetwas geändert zu haben.

                                              Kennt jemensch das Phänomen?

                                              Kubuntu 25.10

                                              :boostplease:

                                                :mastodon: decio »
                                                @decio@infosec.exchange

                                                [VULN] ⚠️ "Dirty Frag : cette faille zero-day donne les droits root sur Linux"

                                                "Dirty Frag, c’est le nom de la nouvelle faille de sécurité critique qui affecte les machines Linux. Cette faille zero-day est similaire à Copy Fail puisqu’elle permet une élévation de privilèges en tant que root. Voici l’essentiel à savoir sur cette menace potentielle.

                                                La vulnérabilité Dirty Frag a été découverte par le chercheur Hyunwoo Kim, qui avait initialement planifié une divulgation coordonnée pour le 12 mai 2026. Cependant, quelqu’un est parvenu à détecter des informations relatives à cette vulnérabilité, et donc tout a été publié en avance ce jeudi 7 mai 2026."

                                                Hyunwoo Kim a pris la décision de publier tous les détails, notamment pour alerter la communauté : “Parce que l’embargo a été rompu, aucun correctif ni CVE n’existe pour ces vulnérabilités. Après consultation avec les mainteneurs de linux-distros@vs.openwall.org, et à la demande des mainteneurs, je publie publiquement ce document Dirty Frag.”."
                                                👇
                                                it-connect.fr/dirty-frag-cette
                                                ⬇️
                                                openwall.com/lists/oss-securit
                                                👇
                                                github.com/V4bel/dirtyfrag/blo

                                                💬
                                                ⬇️
                                                infosec.pub/post/46121720

                                                  Kevin Decherf »
                                                  @kdecherf@n.kdecherf.com

                                                  Happy Frid^WCVE-2026-43284

                                                  #Linux #DirtyFrag #CopyFail

                                                    Veera Laukkarinen »
                                                    @mustikkasoppa@mementomori.social

                                                    Harmaa sydän -ongelma (ratkaistu jo aiemmin)

                                                    Pari kuukautta ihmettelin miksi tykkäämäni Mastodon postauksen sydän on aina harmaa, paitsi silloin kun refreshaan sivun.

                                                    Ärsytti nyt tämä pikkuvika niin paljon, että oli pakko selvittää mikä homma. Vaikeinta oli lähteä etsimään oikeasta paikasta juurisyytä. Ensin epäilin, että @rolle n BirdUI:ssa on joku CSS-ongelma. Rolle sanoi ettei pitäisi olla mitään ongelmaa. Mun sydänongelma (ei sentään oma elin :blob_sweat: ) koski nimenomaan CachyOSia, muilla käyttöjärjestelmissä näkyy oikein selaimesta riippumatta.

                                                    Nyt vasta hoksasin tarkistaa KDE Plasman asetukset tarkemmin ja sieltä löytyikin syypää.

                                                    Ulkoasut ja Teemat > Animoinnit > Animoinnin nopeus 'välitön'. Välitön tila laukaisi tämän ongelman. Säädin animoinnin nyt hitaammaksi ja heti ratkesi ongelma. 'Välitön' aiheutti sydämen animoinnin poistamisen, kun se on aktiivisena. Kyseisen asetuksen lisäinfossa mainitaan, että ongelma saattaa koskea nimenomaan GTK sovelluksia ja animointi ei toimi niissä oikein tässä tilassa.

                                                    PS. Tämä oli muistiinpano itselleni. 🤓

                                                      Blue DeviL // SCT »
                                                      @bluedevil@infosec.exchange

                                                      DirtyFrag: Linux LPE

                                                      This works by chaining the xfrm-ESP Page-Cache Write vulnerability and the RxRPC Page-Cache Write vulnerability.

                                                      github.com/V4bel/dirtyfrag

                                                        heise online English » 🤖
                                                        @heiseonlineenglish@social.heise.de

                                                        “Dirty Frag”: Linux flaws grant root access

                                                        Further vulnerabilities named “Dirty Frag” enable privilege escalation. All distributions are reportedly affected.

                                                        heise.de/en/news/Dirty-Frag-Li

                                                        heise Security »
                                                        @heisec@social.heise.de

                                                        „Dirty Frag“: Linux-Lücken verschaffen root-Rechte

                                                        Weitere Lücken mit dem Namen „Dirty Frag“ ermöglichen die Rechteausweitung. Betroffen sind wohl alle Distributionen.

                                                        heise.de/news/Dirty-Frag-Linux

                                                        Veera Laukkarinen »
                                                        @mustikkasoppa@mementomori.social

                                                        Asensin Brave Origin testiin CachyOSissa. Se on ilmainen Linuxille. 👌

                                                        Origin versio on riisuttu ja siinä ei ole kryptolompsajuttuja. Myös Leo-AI on poistettu. Selaimen pitäisi olla käsitykseni mukaan myös kevyempi.

                                                          knoppix »
                                                          @knoppix95@mastodon.social

                                                          Ubuntu’s X account was briefly compromised to promote a fake AI crypto project using cloned branding, Solana tags, and a deceptive Ubuntu-style domain ⚠️
                                                          The phishing thread followed days of DDoS attacks on Canonical services 🔐

                                                          🔗 itsfoss.com/news/ubuntu-twitte

                                                            JimmyChezPants 🇨🇦 »
                                                            @jpaskaruk@growers.social

                                                            So I'm curious,

                                                            There are now legions of people using for recording, synthesis, processing, etc - it's a full-on cottage industry at this point.

                                                            There are also a large number of Music Professionals using , but they call it MacOS.

                                                            But what I'm curious about, what is the state of Music Production on and other non-Apple BSD.

                                                            I will not be surprised if it turns there are none, nor will I be surprised if it turns out that there is a tiny community of elite DSP nerds making high-end products with it.

                                                              /G|T|R|O|N|I|X\ :python: :emacs: :nix: :linux: »
                                                              @gtronix@infosec.exchange

                                                              "fdisk Cheatsheet"

                                                              "Quick reference for fdisk commands: list disks, create partition tables, add partitions, change partition types, write changes, and quit safely"

                                                              linuxize.com/cheatsheet/fdisk/

                                                                nixCraft 🐧 »
                                                                @nixCraft@mastodon.social

                                                                Dirty Frag: Universal Linux LPE openwall.com/lists/oss-securit

                                                                This is a report on "Dirty Frag", a universal LPE that allows obtaining root privileges on all major distributions. This vulnerability has a similar impact to the previous Copy Fail.

                                                                  ARGVMI~1.PIF »
                                                                  @argv_minus_one@mastodon.sdf.org

                                                                  Oh good, another high-severity vulnerability that somebody botched the disclosure of, turning it into a high-severity zero-day.

                                                                  Because wasn't bad enough. Now we've got too.

                                                                  Can people please stop botching vulnerability disclosure? Thanks.

                                                                  github.com/V4bel/dirtyfrag/blo

                                                                    Markus »
                                                                    @markus@social.row-social.de

                                                                    heute für meinen Vater ein Acer Aspire 1 mit einem LinuxMint installiert.

                                                                    Ich habe ihm KDE Plasma installiert. Dabei ist mir aufgefallen, dass die Angebotenen Meta Pakete von KDE nicht gut zusammengestellt sind.

                                                                    Sogar bei kde-full - fehlte so einiges, dass man nachinstallieren musste.

                                                                      lwnbot » 🤖
                                                                      @lwnbot@c.im

                                                                      Dirty Frag: a zero-day universal Linux LPE lwn.net/Articles/1071719/

                                                                        zaicurity »
                                                                        @zaicurity@infosec.exchange

                                                                        Looks like 2026 is the year of privilege escalation on the Desktop.

                                                                          Riku Silvola »
                                                                          @rikusilvola@infosec.exchange

                                                                          RE: infosec.exchange/@harrysintone

                                                                          > Due to external factors, the embargo has been broken, so no patch exists for any distribution.

                                                                          To mitigate, disable rxrpc, esp4 and esp6

                                                                            wtfismyip »
                                                                            @wtfismyip@gnu.gl

                                                                            Another fucking day, another fuckling : github.com/V4bel/dirtyfrag

                                                                              JRT »
                                                                              @jrt@infosec.exchange

                                                                              Frank »
                                                                              @rincewind@unseen-university.social

                                                                              Hatte dann endlich mal die Zeit, meinen public server mit WireGuard zu versehen um anschließend ssh (mit agressivem fail2ban gesichert) von extern abzuschalten.

                                                                                Tsuri »
                                                                                @tsuri_by@mastodon.social

                                                                                Hey there users, what are you using and why? I used to run , then . Currently on for the proprietary Nvidia support, though I generally prefer the vanilla gnome experience.

                                                                                  Rpsu (326 ppm) »
                                                                                  @rpsu@mas.to

                                                                                  Notta saapa nähdä montako päivää tässä menee totutellessa, tahi tuleeko meille nyt sittenkin uusi tietokone kotiin. Harmi, että olen itse treeniohjelman vuoksi jumissa Applessa, sitä kun ei Linuxille saa.

                                                                                  En kyllä tiedä saisiko edes millään Linux versiolla vaihdetuksi tilistä toiseen pelkän lepotilan kautta, kirjautumatta joka välissä ulos.

                                                                                  Liane M. Dubowy »
                                                                                  @lmd@social.heise.de

                                                                                  Niri bringt frischen Wind auf den -Desktop: Der Tiling-Wayland-Compositor reiht Fenster wie Perlen auf eine Schnur und lässt schnell horizontal hindurchscrollen. Flinke Tastensteuerung, wenig Ballast und eine optionale Desktop-Shell machen aus Niri eine elegante Desktop-Alternative. Läuft bei mir jetzt seit einigen Wochen und gefällt mir sehr.

                                                                                  heise.de/ratgeber/Minimalistis

                                                                                    Matthias »
                                                                                    @pixel@social.dyn.pxlb.de

                                                                                    For my fellow friends: This is a small project, I have worked on.

                                                                                    It is a solar system animation, coded in rust, that runs in your terminal.
                                                                                    You'll find packages for your distro on GitHub. Nix users will find a flake and Arch users can install from the AUR.

                                                                                    and users can compile from source.

                                                                                    Link to the Repo: github.com/the-unknown/solarust

                                                                                    Alt...Solarust Animation Preview

                                                                                      Back to top - More...