bk99.de entertain the web since 1997

Blog 2004

12 posts

Projects, Linux, networks, systems, finds and internet standards from 2004.

Linux on the iPod

Hackaday shows an early iPod Linux port that extends Apple’s music player with games, recording and image viewing via dual boot. Third-generation iPods, among others, were supported. Open systems extend the experimental life of closed devices.

Read the full post

Running HostAP Wi-Fi networks securely on Linux

Jan Fiegert explains how Linux provides an access point with HostAP and secures it with WPA-PSK or WPA-EAP. A working access point is not yet a trustworthy network without suitable authentication. Open drivers enable network functions that would otherwise be reserved for special hardware.

Read the full post

Novell brings SUSE Linux server with kernel 2.6

In August 2004 Novell presented SUSE Linux Enterprise Server 9 with kernel 2.6, available for x86, AMD64, Intel’s EM64T, Itanium, IBM Power and zSeries. Prices started at 349 US dollars a year for a server with two CPUs and rose considerably for Itanium and mainframes. Besides YaST, the package included ZENworks for Linux and the Service Location Protocol, and Common Criteria EAL4+ certification was planned.

Read the full post

Security leak allows reading Linux kernel memory

In 2004 Paul Starzetz found several bugs in the Linux kernel’s handling of file offsets through which a logged-in user without special privileges could read kernel memory. The causes were incorrect conversions of 64-bit offsets into 32-bit values and a race condition in the 64-bit file API. In tests, Starzetz found the password of an administrator logged in via SSH in this way.

Read the full post

Unisys supports Linux on multiprocessor servers

In 2004 Unisys, until then a Microsoft partner focused on Windows, announced Linux support for its ES7000 servers. The machines with 4 to 32 Xeon or Itanium 2 processors were to receive Red Hat and SUSE with kernel 2.6 and dynamic partitioning. According to the COO it was a difficult decision, but authorities and financial service providers only wanted to buy the servers with Linux.

Read the full post

Another security hole in Internet Explorer

In January 2004 the security researcher “http-equiv” documented a hole in Internet Explorer on Full Disclosure through which files with fake extensions could be slipped to users. The browser did not check fake CLASSIDs, so that, for example, an HTML file disguised as a PDF was executed as HTML when opened. There was no patch yet; the only protection was to save files locally first.

Read the full post

Security hole in the Linux kernel

In January 2004 Paul Starzetz reported a critical hole in the memory management of Linux kernels 2.2, 2.4 and 2.6. An insufficient check in do_mremap() made it possible to create a virtual memory area with a length of zero bytes and thus confuse memory management. Since mremap(2) requires no special privileges, any process could exploit the hole; an unpublished exploit delivered a root shell.

Read the full post