bk99.de entertain the web since 1997

Blog 2003

11 posts

Projects, Linux, networks, systems, finds and internet standards from 2003.

Linux kernel 2.4.22 released

In August 2003 Marcelo Tosatti released Linux kernel 2.4.22, which above all reworked ACPI support. There were also improvements to Wi-Fi, Bluetooth, USB and 64-bit processors; the version was identical to release candidate 4. At the same time, test versions of kernel 2.6 with a new scheduler, better memory management and a faster IP stack were available.

Read the full post

Linux kernel developer Cox withdraws for a year

In 2003 Alan Cox announced on the kernel mailing list a one-year withdrawal from Linux development starting in September. Cox’s employer Red Hat granted leave for an MBA course, and improving Cox’s Welsh was also on the agenda. Cox, often described as the second most important kernel developer, named successors for the areas concerned and, given the grown community, no longer felt like a “crucial cog”.

Read the full post

Critical security hole in the wu-ftpd server

In 2003 Janusz Niewiadomski published a buffer overflow in the FTP server wu-ftpd, versions 2.5.0 to 2.6.2, on Bugtraq. The function fb_realpath() mishandled paths longer than 4096 bytes; anyone with write access who was allowed to create directories could exploit it. The major distributions delivered updates; as a workaround, prohibiting new directories with “upload … nodirs” helped.

Read the full post

Security hole in the encryption of Outlook 2002 (update)

In January 2003 Outlook 2002 sent emails unencrypted even though users had chosen encryption with a V1 Exchange Server Security certificate. The bug only affected HTML messages and only this method; PGP and S/MIME were not affected. Microsoft provided a patch, initially only in English and a few days later in German as well.

Read the full post

AMD presents flash memory with security functions

In January 2003 AMD presented the Am29PDL640G flash memory with 64 megabits and multi-level security functions, including 64-bit password protection. It was intended for mobile phones and set-top boxes and was meant to prevent hackers from making calls at other people’s expense or pirating pay TV. The chip was also supposed to extend battery life.

Read the full post

Security hole in ISC DHCPD

In January 2003 the Internet Software Consortium found holes in its DHCP server ISC dhcpd during a code review that allowed attackers to execute code remotely, usually with root privileges. Versions 3.0 to 3.0.1RC10 were affected. The bug lay in the error handling of the minires library, which is used for dynamic DNS updates.

Read the full post

Examining devices with JTAG

The talk presents JTAG as a hardware-level interface for debugging processors, examining memory and analysing embedded devices. Manufacturing interfaces often turn into powerful analysis tools after production. Physical access fundamentally changes the threat model of embedded systems.

Read the full post