handmade.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
handmade.social is for all handmade artisans to create accounts for their Etsy and other handmade business shops.

Server stats:

37
active users

#mediatek

0 posts0 participants0 posts today

Phone rooted with #Magisk and mostly degoogled with Canta and uh, Shizuku. #AdAway installed.

Now I have to play hide and seek with my bank auth app 😩

Still not found a #GCam version that works with this camera though. #Mediatek one is bad, same as Blackview.

Fingerprint reader is crappier than on the old Blackview. The chunky camera blob on the back is weird, but that is the price of having thermal imaging, which is extremely useful.

#cve_2024_20017 recap
⬇️
"Affected chipsets: MT6890, MT7915, MT7916, MT7981, MT7986, MT7622
⬇️
Affected software: SDK version 7.4.0.1 and before (for MT7915) / SDK version 7.6.7.0 and before (for MT7916, MT7981 and MT7986)"
⬇️
""4 exploits, 1 bug: exploiting cve-2024-20017 4 different ways"
👇
blog.coffinsec.com/0day/2024/0
⬇️
[PoC]
👇
github.com/mellow-hype/cve-202
⬇️
"Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability (CVE-2024-20017) Threatens Routers and Smartphones"
👇
blog.sonicwall.com/en-us/2024/

[#Mediatek advisory]

"In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation"
⬇️
"March 2024 Product Security Bulletin"
👇
corp.mediatek.com/product-secu

[#Ubiquity statement]

"Ubiquiti is NOT affected. We don't have any product that uses the vulnerable code."
👇
community.ui.com/questions/CVE

hyprblog · 4 exploits, 1 bug: exploiting CVE-2024-20017 4 different waysa post going over 4 exploits for CVE-2024-20017, a remotely exploitable buffer overflow in a component of the MediaTek MT7622 SDK.