bk99.de entertain the web since 1997

Blog 2007

16 posts

Projects, Linux, networks, systems, finds and internet standards from 2007.

The truth and what really happened

Ron and Frank Rieger examine how events become a socially accepted majority narrative through perspectives, selection and repetition. The announcement refers to Bruce Sterling’s term “major consensus narrative”. Consensus measures social acceptance and not automatically historical accuracy.

Read the full post

DoS hole in Cisco IOS endangers internet providers’ routers [Update]

In 2007 a DoS hole in Cisco’s IOS allowed routers to be forced to restart via the command “show ip bgp regexp” with certain regular expressions. Many providers offered such commands publicly via telnet route servers or looking glass websites; repeated restarts could cause other networks to ignore the provider’s routes. As a workaround, providers filtered the expressions or blocked the command, and Cisco recommended the “Deterministic Regular Expression Engine”.

Read the full post

Gentoo takes servers offline because of security holes

In August 2007 Gentoo took several servers offline after a command injection hole had been discovered on packages.gentoo.org. The affected systems were examined forensically; whether any manipulation had taken place was unclear. According to Gentoo, packages and sources could not have been changed at any time, as the server only displayed information from the Portage tree.

Read the full post

Critical hole in Norton AntiVirus and Internet Security

In 2007 Symantec reported critical holes in Norton AntiVirus 2006, Norton Internet Security and SystemWorks through which a prepared website could take over a Windows PC. The cause was two ActiveX controls in NAVCOMUI.DLL that processed certain objects incorrectly. The updates were already being distributed via LiveUpdate, and the enterprise products were not affected.

Read the full post

Linux kernel 2.6.19.2 fixes storage bug

In January 2007 Linux kernel 2.6.19.2 fixed a critical bug that could, under certain circumstances, cause data not to be written to disk correctly. Ext3 was particularly affected, but other file systems were too; tracking down the bug took around four weeks. The version also closed security holes, for example in the Bluetooth stack, with around 50 patches in total.

Read the full post

Security holes in the X.org X server

In January 2007 the X.org X server contained several integer overflow holes in the DBE module and the Render extension, affecting all versions since X.org 6.8.2. Faulty parameters could overwrite memory even outside the affected functions. This could only be exploited by an already authenticated client, and patches were available.

Read the full post

Network backup Bacula 2.0 with encryption

In January 2007 the free network backup software Bacula appeared in version 2.0 and could now store data encrypted on volumes. Also new were the migration of jobs between volumes, faster restores from hard disk, better support for removable media and the BWeb web interface. Scripts could be started on server and client before and after jobs.

Read the full post