Projects, Linux, networks, systems, finds and internet standards from 2005.
van Hauser explains the differences from IPv4, demonstrates weaknesses in IPv6 environments and presents the THC-IPv6 attack toolkit. A larger address field removes neither local attacks nor configuration mistakes. Unnoticed IPv6 can bypass the security rules of operations designed only for IPv4.
Read the full post →
NetBSD encryption protected complete disks and thus sensitive notebook data in case of physical theft.
Read the full post →
Rop Gonggrijp and Frank Rieger analyse the foreseeable loss of privacy and civil rights and look for effective answers beyond technical resignation. A lost battle can clarify the strategy without ending the whole conflict. Infrastructure decisions become civil rights issues as soon as they make behaviour permanently observable.
Read the full post →
Hackaday reports on a Linux port with drivers for video, network, audio, input and self-made boot media. The port used a Linux kernel. PAL and NTSC framebuffers already worked.
Read the full post →
Manuel Schmitt documents his exchange with another hosting provider after a manually created MySQL user unexpectedly gained access to other customers’ databases. The other provider traced the error to a user created manually after a server shutdown. According to its account, only this single user had wrong permissions.
Read the full post →
Manuel Schmitt describes a customer who reports frequent outages, although monitoring shows continuous availability and no fault had been reported before. The operator’s monitoring showed the server as permanently reachable. The customer had not reported any individual faults beforehand.
Read the full post →
A Gumstix computer logs GPS data, controls two cameras and sends position fixes by SMS from a high-altitude balloon. Pegasus 1 reached 66,585 feet. The mission took more than 600 pictures.
Read the full post →
Manuel Schmitt describes compromised FTP accounts through which attackers uploaded PHP scripts to web hosting accounts. The attackers uploaded PHP scripts through regular FTP users. The hosting provider disabled the accounts, blocked the scripts and informed the affected customers.
Read the full post →
In 2005 HP recommended an unusual workaround for the ProLiant DL585 server: pull the power cable. A bug in the Integrated Lights-Out remote management module up to firmware 1.8 allowed unauthorised network access to the server controls while it was switched off. Only without power was the iLO switched off as well, but then every restart required a trip to the server room.
Read the full post →
In 2005 Linux-VServer 2.0 was the first stable version to run on kernel 2.6, isolating several Linux environments on one computer from each other. Similar to BSD jails, each environment formed its own context in which processes only saw their part of the file system and no other processes. Unlike User Mode Linux or Xen, the guests did not run their own kernel.
Read the full post →
In 2005 the NetBSD project filled two seats on its core team, which decides on the development and goals of the free Unix. After six years, Frank van der Linden and Luke Mewburn stepped down and were succeeded by Valeriy Ushakov and Yamamoto Takashi. NetBSD is regarded as the BSD with the most ports to different hardware.
Read the full post →
Hackaday presents MisterHouse as Perl-based home automation with a web interface, speech recognition and support for numerous devices. MisterHouse is free software. Among other things, the project supports X10.
Read the full post →
RFC 4122 standardises the UUID structure and several generation methods for distributed unique identifiers. RFC 4122 was superseded by RFC 9562. Decentralised identifiers decouple data creation from central numbering authorities.
Read the full post →
A practical test of the SchilliX live CD failed on an Athlon 64 because of hardware detection and usability.
Read the full post →
The LPIC-1 certification marked the start of an important chapter of my Linux journey. It is still active and valid until 25 August 2029.
Read the full post →
The talk describes customised Linux firmware on Linksys home routers and the functions gained as a result.
Read the full post →
RFC 4033 introduces DNSSEC and explains the chain of trust, signed answers and validating resolvers. DNSSEC protects data origin, not confidentiality. Key and delegation operations decide its practical reliability.
Read the full post →
After several kernel holes, the Linux kernel mailing list discussed in January 2005 how secure the kernel is. Brad Spengler blamed the new development model, while Alan Cox and Theodore Ts’o saw a positive trend. More bugs found did not mean more bugs, but better searching, for example with tools such as Coverity and sparse.
Read the full post →
In January 2005 Allnet presented the ALL1681 DSL router, which connects devices to the internet via Ethernet, Wi-Fi or the power line (HomePlug Powerline). It offered four 10/100 Mbit ports, an 802.11g access point with 54 Mbit/s and an SPI firewall. Up to 14 Mbit/s within a radius of around 200 metres were to be possible over the power grid.
Read the full post →
With grsecurity 2.1.0 in January 2005, Brad Spengler pointed out four local holes in the Linux kernel, and Paul Starzetz reported another in the binary loader. All of them allowed local users to escalate their privileges up to root. Spengler criticised that the holes were still open three weeks after being reported to Torvalds and Morton, despite patches being attached.
Read the full post →