From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from firstgate.proxmox.com (firstgate.proxmox.com [212.224.123.68]) by lore.proxmox.com (Postfix) with ESMTPS id 1069E1FF15C for ; Wed, 27 Nov 2024 01:30:58 +0100 (CET) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id D631DD3D1; Wed, 27 Nov 2024 01:30:56 +0100 (CET) To: "=?utf-8?B?RmFiaW8gRmFudG9uaSB2aWEgcHZlLWRldmVs?=" Date: Wed, 27 Nov 2024 08:14:28 +0800 MIME-Version: 1.0 Message-ID: List-Id: Proxmox VE development discussion List-Post: From: James Brown via pve-devel Precedence: list Cc: =?utf-8?B?SmFtZXMgQnJvd24=?= X-Mailman-Version: 2.1.29 X-BeenThere: pve-devel@lists.proxmox.com List-Subscribe: , List-Unsubscribe: , List-Archive: Reply-To: Proxmox VE development discussion List-Help: Subject: [pve-devel] SPAM: [Security] Arbitrary file reading via malicious VM config Content-Type: multipart/mixed; boundary="===============8484104457925600506==" Errors-To: pve-devel-bounces@lists.proxmox.com Sender: "pve-devel" This is a multi-part message in MIME format. --===============8484104457925600506== Content-Type: message/rfc822 Content-Disposition: inline Return-Path: X-Original-To: pve-devel@lists.proxmox.com Delivered-To: pve-devel@lists.proxmox.com Received: from firstgate.proxmox.com (firstgate.proxmox.com [212.224.123.68]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by lists.proxmox.com (Postfix) with UTF8SMTPS id 16229CA929 for ; Wed, 27 Nov 2024 01:30:55 +0100 (CET) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with UTF8SMTP id D505DD384 for ; Wed, 27 Nov 2024 01:30:24 +0100 (CET) Received: from out162-62-57-137.mail.qq.com (out162-62-57-137.mail.qq.com [162.62.57.137]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by firstgate.proxmox.com (Proxmox) with UTF8SMTPS for ; Wed, 27 Nov 2024 01:30:22 +0100 (CET) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=foxmail.com; s=s201512; t=1732667412; bh=/3dRtADDam/NAprcAn/1yICNTMCigiVahZgyJCNBLYw=; h=From:To:Subject:Date; b=LYqsE4p1NEaREG9pmSKvqPsaIY9x5momsYAUjkbDYThHYUwTywoq8qxS1CbaZLgwX fMhyMux/f/zOnblM8nn7ACmb0A6MIepYr+Shlhri6zW2gXstt0VX2fQsi/q54kH/b9 S9E4z0GXpNzP77DYgsblCU5wr4KxpdGurzd1Bpwo= X-QQ-XMRINFO: OWPUhxQsoeAVDbp3OJHYyFg= X-QQ-XMAILINFO: MOQpAxjIVJukdWwJLiSKZAgFVEl6LzOlNtI4Rke/uKmI5aw+93u8jdva+4lYaa +l7aLfEvp0mNpeBoAUBJvbJy8ttL/wY29qvXE7rRQ0KTyE6G41zysWvyr3Xr9InEoMZtlmHsa32sp uBojXEe2lvuLVPcJqSrdLTpcaYDmJsdPKdfvKrnNMDxwQzbP+48ZZ/nKWa/Vzj7wVLDyRSvyLSBmA XcaKwxPZ7jTeh0CkuytxO4Yz/PURayGwVgzo04Pp71uimeDCrnrUGHYtTyrYokiQwcKJl9iPyX9tg TMakuigyXyMnHdIAbgRI+YpBPteOvPG8K+9MDwbVlqHVADW2HOIcT4NtOeoyTI2mOjffew8YtjGor xy0cGvCRcIGZ2+rvIMVPMxxHDfdQV9TFmr/3cA5FtQymRCMSeGTv6vgPGx+E9Vnk1k6yecr4uMYdW NcDQNXTzpbE1Uw6Q2/QTxMDZoVzzJwPprUbIeuBv2KwkaTTgw2ORZ6ARlO9yo0xxXXb7Mr2SzksaY bqjNhdrW6GGe05H8ZoCVwyefRQrMm2b61ENukXfxWGxuExOVxx8rqguh1NWCzYWKoZbyPoc5Ma+Gd AjcC8FDHHyvBESZG4NsmM05w+wB8xoG7RkW3MMMwT31mDDqYTdRgXnV27pE0QgOpO+R0o/XBd69Cz LTwHpgzymXaEzxCOAHd/76zw9dDEBKWD8dDiXu/GlUy6I5NxJKae6SBVqYc1Ee2uVlhVztP2+z+Jh 1RRSJdFWlBvQX7+1EMSs//UJsVd5RRVeg8IyeRP5HEmaobRSQAUZZVvaLZy+q30ltT2G/VY5x7197 tUp67fKMRfXvZBmNHXsjonrwU7T4gTh0fxQJ2KklZNBt3iQnQOzfW2KP0rDySclUCFKGB+6grVzYq ktzgEK3BJDTW/kyesDc6DF2r6sb8Ps7i5AgTiy2khCH/7aoK6xLVppWk8IDfRrcK6ueiJKSqzykDb 0qPeAuJhAp2AJpn7M6uBe0mP4CbG9hs+WXcsbknDeIkC/hN1WTO7AZ34hTzLtawLCxYuW2haeKmjn 6OFvzf1r6svH9fxXCFDtXuNAkJg== From: "=?utf-8?B?SmFtZXMgQnJvd24=?=" To: "=?utf-8?B?RmFiaW8gRmFudG9uaSB2aWEgcHZlLWRldmVs?=" subject: SPAM: [Security] Arbitrary file reading via malicious VM config Mime-Version: 1.0 Date: Wed, 27 Nov 2024 08:14:28 +0800 X-Priority: 3 Message-ID: X-QQ-MIME: TCMime 1.0 by Tencent X-Mailer: QQMail 2.x X-QQ-Mailer: QQMail 2.x X-QQ-mid: xmappua3-0t1732666468toijsmq9i X-SPAM-LEVEL: Spam detection results: 3 BAYES_50 0.8 Bayes spam probability is 40 to 60% DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy FREEMAIL_FROM 0.001 Sender email is commonly abused enduser mail provider FROM_EXCESS_BASE64 0.001 From: base64 encoded unnecessarily HELO_DYNAMIC_IPADDR 1.951 Relay HELO'd using suspicious hostname (IP addr 1) HTML_MESSAGE 0.001 HTML included in message RCVD_IN_DNSWL_NONE -0.0001 Sender listed at https://www.dnswl.org/, no trust RCVD_IN_VALIDITY_CERTIFIED_BLOCKED 0.001 ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. RCVD_IN_VALIDITY_RPBL_BLOCKED 0.001 ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. RCVD_IN_VALIDITY_SAFE_BLOCKED 0.001 ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. RDNS_DYNAMIC 0.982 Delivered to internal network by host with dynamic-looking rDNS SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record URIBL_BLOCKED 0.001 ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [foxmail.com] Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 X-Content-Filtered-By: Mailman/MimeDel 2.1.29 SSBzdXNwZWN0IGEgc2VjdXJpdHkgZmxhdyB3aXRoaW4gRVNYaSBWTSBpbXBvcnQuIElmIGEg bWFsaWNpb3VzIGFjdG9yIGZvcmdlcyBhIFZNV2FyZSBWTSBjb25maWcgd2l0aCByb290IHBh dGhzIHN1Y2ggYXMgL3Zhci9sb2cvYXV0aC5sb2csIGNvdWxkIGxlYWQgdG8gcG90ZW50aWFs IGRhdGEgbGVhayBpZiB0aGUgaW1wb3J0IHRhc2sgaXMgZXhlY3V0ZWQu --===============8484104457925600506== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ pve-devel mailing list pve-devel@lists.proxmox.com https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-devel --===============8484104457925600506==--