bk99.de entertain the web since 1997

Blog 2005

20 posts

Projects, Linux, networks, systems, finds and internet standards from 2005.

Attacks on the IPv6 protocol stack

van Hauser explains the differences from IPv4, demonstrates weaknesses in IPv6 environments and presents the THC-IPv6 attack toolkit. A larger address field removes neither local attacks nor configuration mistakes. Unnoticed IPv6 can bypass the security rules of operations designed only for IPv4.

Read the full post

Security hole in HP server when powered down

In 2005 HP recommended an unusual workaround for the ProLiant DL585 server: pull the power cable. A bug in the Integrated Lights-Out remote management module up to firmware 1.8 allowed unauthorised network access to the server controls while it was switched off. Only without power was the iLO switched off as well, but then every restart required a trip to the server room.

Read the full post

Linux-VServer 2 for kernel 2.6

In 2005 Linux-VServer 2.0 was the first stable version to run on kernel 2.6, isolating several Linux environments on one computer from each other. Similar to BSD jails, each environment formed its own context in which processes only saw their part of the file system and no other processes. Unlike User Mode Linux or Xen, the guests did not run their own kernel.

Read the full post

How secure is the Linux kernel?

After several kernel holes, the Linux kernel mailing list discussed in January 2005 how secure the kernel is. Brad Spengler blamed the new development model, while Alan Cox and Theodore Ts’o saw a positive trend. More bugs found did not mean more bugs, but better searching, for example with tools such as Coverity and sparse.

Read the full post

Allnet router with Powerline, Wi-Fi and Fast Ethernet

In January 2005 Allnet presented the ALL1681 DSL router, which connects devices to the internet via Ethernet, Wi-Fi or the power line (HomePlug Powerline). It offered four 10/100 Mbit ports, an 802.11g access point with 54 Mbit/s and an SPI firewall. Up to 14 Mbit/s within a radius of around 200 metres were to be possible over the power grid.

Read the full post

Security holes in the Linux kernel

With grsecurity 2.1.0 in January 2005, Brad Spengler pointed out four local holes in the Linux kernel, and Paul Starzetz reported another in the binary loader. All of them allowed local users to escalate their privileges up to root. Spengler criticised that the holes were still open three weeks after being reported to Torvalds and Morton, despite patches being attached.

Read the full post