frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

RCE via ND6 Router Advertisements in FreeBSD

https://www.freebsd.org/security/advisories/FreeBSD-SA-25:12.rtsold.asc
23•weeha•1h ago

Comments

imvetri•1h ago
is my understanding right?

"PC or computers or hardware that uses OS that consume FreeBSD, has a faulty software for the router's firmware?"

"The router's software performs ad distributions?"

"The version of internet, the router uses, is updated, whereas, the target machine, or the user's machine is still running a old version"

"The security patch works for the modern but not the precursor version?"

"This leaves older systems obsolete in the market?"

"is this a step-by-step instructions to business owners to introduce new products, selling that older products are obsolete" ?

eptcyka•1h ago
No, I don't think you are understanding this right, but there are some good questions you are asking. Where is the flag button?

If you are a real human, the most interesting question you're bringing up is What about all the appliances backed by FreeBSD? Yes, they are obsolete if they use IPv6 and accept RAs and if they don't get updates.

jacquesm•1h ago
That was my first thought, if this is an embedded system without an update path this will be super hard to solve. People usually are not even aware of what OS their appliances run under the hood and whether or not they are updated automatically and how to update them if they are not.
jacquesm•1h ago
Oh that's a nasty one, embedded FreeBSD users will have a hard time mitigating this.
formerly_proven•59m ago
Free jailbreaks for everyone though!
jacquesm•49m ago
We had a soccer player in NL that was wildly popular and he had these funny remarks every now and then which got him nicknamed the most well known dutch philosopher. One of these was 'every advantage has its disadvantage', I guess this is one of those.
TekMol•1h ago

    vulnerable to remote code execution from
    systems on the same network segment
Isn't almost every laptop these days autoconnecting to known network names like "Starbucks" etc, because the user used it once in the past?

That would mean that every FreeBSD laptop in proximity of an attacker is vulnerable, right? Since the attacker could just create a hotspot with the SSID "Starbucks" on their laptop and the victim's laptop will connect to it automatically.

francasso•55m ago
If you run FreeBSD on your laptop you don't auto connect to public WiFi.

Joking, but not that much :)

badgersnake•13m ago
Your wifi chip probably isn’t supported tbh.
hhh•54m ago
dozens of people will be affected
rs_rs_rs_rs_rs•1h ago
IPv6 is a prerequisite for the bug to be exploited, it won't affect anyone.
ale42•55m ago
Why, is IPv6 activation manual in FreeBSD?
rs_rs_rs_rs_rs•50m ago
It's enabled by default, I was mostly talking about being in a lan with active ipv6, imo that's not that common.
shakna•49m ago
That's pretty standard where I am. Every Telstra router comes with IPv6 enabled.
ale42•24m ago
IMHO you do not need "active" IPv6. Most LANs (unless you have some switch-level filtering that blocks router advertisements from "unauthorized" nodes) can transport such IPv6 packets. Then it just takes being connected to the LAN and being able to send an arbitrary ICMP6 packet (which probably means being root on the attacker machine, not a very high barrier I'd say).
tuetuopay•1m ago
Can we be done with the house of cards that are shell scripts everywhere?

Anyways, this feels like a big issue for "hidden" FreeBSD installs, like pfSense or TrueNAS (if they are still based on it though). Or for servers on hosting providers where they share a LAN with their neighbors in the same rack.

And it's a big win for jailbreaking routers :D

Webpage content should not be able to influence GC via WeakRef

https://codeberg.org/librewolf/issues/issues/2753
1•mimasama•3m ago•0 comments

Aaron Van Wirdum predicts the future of crypto

https://altcoindesk.com/perspectives/interviews/aaron-van-wirdum-predicts-the-future-of-crypto/
1•CryptoBabe•4m ago•0 comments

DCMS Pheix – First RTM Release «from the Basement»

https://pheix.org/embedded/from-the-basement-release
2•pheix•5m ago•1 comments

Visualizing interaction-driven restructuring of quantum Hall edge states

https://www.nature.com/articles/s41586-025-09858-3
1•westurner•7m ago•0 comments

Microsoft kills IntelliCode in favor of the paid Copilot

https://visualstudiomagazine.com/articles/2025/12/17/microsoft-quietly-kills-intellicode-as-ai-st...
1•todsacerdoti•7m ago•0 comments

Show HN: Map of median rent per m² in Berlin

https://allaboutberlin.com/tools/rent-map
2•nicbou•13m ago•0 comments

Discovering Clara Rules: Business Logic That AI Can Understand

https://claude.ai/public/artifacts/445f4394-c6a7-49cf-b639-900ea34541b0#no_universal_links
1•tamnd•17m ago•0 comments

GitHub cancels Actions price change for self-hosted runners

https://docs.github.com/en/billing/reference/actions-runner-pricing
3•axelfontaine•19m ago•2 comments

Attempting cross translation unit taint analysis for Firefox

https://attackanddefense.dev/2025/12/16/attempting-cross-translation-unit-static-analysis.html
1•fanf2•19m ago•0 comments

The App Paradigm Inversion

https://blog.dougbelshaw.com/app-paradigm-inversion/
1•dajbelshaw•19m ago•0 comments

Online Textbook for Braid groups and knots and tangles

https://matthematics.com/redoak/redoak.html
2•marysminefnuf•21m ago•0 comments

Hacker News Reader created using Claude

https://claude.ai/public/artifacts/7efd244e-e747-4a25-aa76-687d21e796c0
1•rogermungo•22m ago•1 comments

How a major convenience store chain became a hub for crypto scams

https://www.cnn.com/2025/12/17/us/crypto-atm-scams-circle-k-invs-vis
3•breve•28m ago•0 comments

Is Stackoverflow.com Broken?

https://stackoverflow.com/questions
1•tannhaeuser•29m ago•1 comments

Hybrid Search: OLAP with vector search and full-text search and SQL analytics

https://www.velodb.io/blog/apache-doris-4-0-engine-analytics-fulltext
1•qinchencq•31m ago•0 comments

The "Zero-Employee" Marketing Stack: Scaling SaaS from Seed to Series A

https://blog.vect.pro/saas-founder-marketing-guide
1•MMAFRAZ•32m ago•1 comments

Rayneo Air 3s Pro AR Glasses Review

https://boilingsteam.com/rayneo-air-3s-pro-review/
1•ekianjo•33m ago•0 comments

OpenAI Academy for News Organizations

https://openai.com/index/openai-academy-for-news-organizations/
1•narram•35m ago•0 comments

Ask HN: Self-hosted AD/Entra ID alternative that works with Windows and Linux?

2•marenkay•35m ago•1 comments

Blue States Used to Lead in Education. Not Anymore

https://www.city-journal.org/article/education-reform-students-reading-math-republican-states
1•barry-cotter•39m ago•1 comments

Hacking LLDB for a great Zig debugging experience

https://joel.id/hacking-lldb-for-a-great-zig-debugging-experience/
1•joelreymont•41m ago•1 comments

Ask HN: Decentralized Auth for Information Exchange?

1•vxsz•41m ago•2 comments

Harry Potter–Style 'Moving Invisibility Cloak' Technology Developed

https://news.kaist.ac.kr/newsen/html/news/?mode=V&mng_no=56050
1•JeanKage•46m ago•0 comments

What Is Orthokeratology?

https://www.aao.org/eye-health/glasses-contacts/what-is-orthokeratology
3•thunderbong•55m ago•1 comments

'It's an open invasion': how quagga mussels changed Lake Geneva

https://www.theguardian.com/environment/2025/dec/18/invasive-quagga-mussels-lake-geneva-aoe
2•n1b0m•57m ago•0 comments

Nvidia Publishes Complete Evaluation Recipe for Nemotron 3 Nano

https://huggingface.co/blog/nvidia/nemotron-3-nano-evaluation-recipe
2•victormustar•57m ago•0 comments

Prompts Are Broken

https://godofprompt.beehiiv.com/p/your-prompts-are-broken
1•kiyanwang•59m ago•0 comments

Differential Fuzzing Across the Language Divide

https://R9295.github.io/posts/differential-fuzzing-accross-languages/
1•r9295•1h ago•0 comments

Show HN: SuperchargeBrowser – Privacy-first Chrome extension to fix performance

https://github.com/SuperchargeBrowser/supercharge-browser
1•superchargeext•1h ago•1 comments

King William's College – Isle of Man "The World's Most Difficult Quiz" [pdf]

https://kwc.im/wp-content/uploads/2025/12/GKP_2025_26.pdf
2•beardyw•1h ago•5 comments