HUP cikkturkáló

EncFS biztonsági audit

This document describes the results of a 10-hour security audit of EncFS 1.7.4. The audit was performed on January 13th and 14th of 2014.

[...]

This audit finds that EncFS is not up to speed with modern cryptography practices. Several previously known vulnerabilities have been reported [1, 2], which have not been completely fixed. New issues were also discovered during the audit.

The next section presents a list of the issues that were discovered. Each issue is given a severity rating from 1 to 10. Due to lack of time, most issues have not been confirmed with a proof-of-concept.

A teljes dokumentum itt olvasható.

TCP-32764 útvonalválasztó hátsó ajtó (router backdoor)

Egyes útvonalválasztók a 32764-es TCP porton olyan szolgáltatást tesznek elérhetővé, ami lehetőséget nyújt többek közötött az útvonalválasztón rendszergazdai jogosultságokkal parancsértelmezőt futtatni, konfigurációs paramétereket lekérdezni és beállítani (ide értve az útvonalválasztó felhasználói jelszavakat is). A felfedező elérhetővé tett egy diasorozatot (PDF) a jelenség leírására. Egy Python script pedig segít eldönteni, hogy egy kérdéses eszköz tartalmazza-e ezt a "szolgáltatást".

[ github elvanderb/TCP-32764 | cikk az index.hu-n | kovi blogbejegyzése a HUP-on ]

(Nagyon) Távoli szoftverfrissítés

"This is the third upgrade version since Curiosity's landing on Mars 16 months ago. Completing the switch from version 10 took about a week, Nasa said. An earlier switch to version 11 prompted an unintended reboot on November 7 and a return to version 10, but the latest transition went smoothly."

Mars rover Curiosity’s software upgraded

Theo de Raadt a FreeBSD security-ről

"FreeBSD has caught up to what OpenBSD has been doing for over 10 years," De Raadt (pictured above) told iTWire. "I see nothing new in their changes.

"You are not the only person who asked if we will now do something in the same direction as FreeBSD. We can't follow them - we were already leading in 2003."

"Basically, it is 10 years of FreeBSD stupidity. They don't know a thing about security. They even ignore relevant research in all fields, not just from us, but from everyone."

Az interjú részletei itt.

Microsoft Update team - SVCHOST and Windows Update

Original Issue

In September we witnessed a large number of reports of SVCHOST taking high CPU for extended periods of time. This was primarily on Windows XP machines running IE6 or IE7. There were a few reports of this happening on Windows XP with IE8, but only a few.

A microsoftos Doug Neal levele: SVCHOST and Windows Update

Az Ars Technica cikke a témában:

Exponential algorithm making Windows XP miserable could be fixed

Amúgy meg lazán kapcsolódik:

Microsoft: jövőre veszélyes lesz az XP