Projects, Linux, networks, systems, finds and internet standards from 2010.
bushing, marcan and sven take console security apart and show how implementation errors made custom code possible on hardware that was supposedly fully controlled. The three of them gave the talk together. The focus is on the break of PlayStation 3 security at the time.
Read the full post →
Michael Steil shows how high-resolution chip photos were turned into a functional transistor model of the MOS 6502 and new insights into illegal opcodes. The MOS 6502 was developed in 1975. Visual6502 simulates the reconstructed mask at transistor level.
Read the full post →
A Russian government order required federal authorities to migrate to GNU/Linux step by step.
Read the full post →
Johannes publishes PC/SC for PHP, a native extension for smart card communication via pcsc-lite. The source code was published on 17 December 2010. The project uses pcsc-lite.
Read the full post →
Stuxnet showed how malware could specifically attack industrial Siemens controllers and their operating environment.
Read the full post →
Hackaday describes a Perl script that captures XML readings from a Current Cost electricity monitor on Linux and sends them to an analysis service. The device used is the Current Cost CC128. The manufacturer documented its XML format.
Read the full post →
Hackaday describes RootStock as a tool that creates an Ubuntu root file system for a Gumstix ARM board. The target board comes from Gumstix. The base system cost about 150 US dollars at the time.
Read the full post →
Using early Stuxnet analyses, Brian Krebs shows how several Windows vulnerabilities, stolen signatures and PLC manipulation made a targeted attack on industrial plants possible. Stuxnet used at least four Windows vulnerabilities that were unknown at the time. Microsoft closed the printer sharing vulnerability with MS10-061.
Read the full post →
Manuel Schmitt reminds readers to make every physical drive of a Linux software RAID 1 bootable with GRUB. The article refers to the GRUB documentation for RAID 1 at the time. As examples, /dev/sda and /dev/sdb are given in device.map.
Read the full post →
Andre Steincke explains KVM as part of the Linux kernel and covers guest management, migration, high availability and graphical tools such as virt-manager. Kernel integration ties virtualisation directly to Linux scheduling and memory management. Operational tools often matter more for everyday use than the hypervisor alone.
Read the full post →
In 2010 Rafal Wojtczuk described a problem in Linux memory management in which the stack and shared memory segments could grow into each other. Using the X server as an example, Wojtczuk showed how an attacker could overwrite return addresses on the stack by writing to the shared memory and gain root privileges. The fix, a guard page between the stack and other areas, came in 2.6.32.19, 2.6.34.4 and 2.6.35.2, although SUSE had offered a fix as early as 2004.
Read the full post →
With Linux 2.6.36-rc1, the merge window, in which most new features enter the main branch, ended in August 2010. Among other things, the AppArmor security framework was accepted after years of attempts, as were fanotify for virus scanners and a driver for Intel’s Intelligent Power Sharing. As with 2.6.35, Torvalds wanted to accept strictly only bug fixes in the following stabilisation phase.
Read the full post →
In August 2010, Linus Torvalds released Linux kernel 2.6.35, just under eleven weeks after 2.6.34. New features included power saving for Radeon graphics and H.264 decoding on Intel’s Ironlake processors. Changes to the network stack and to the use of CPU power-saving states were expected to speed up some systems considerably.
Read the full post →
RFC 5961 improves TCP checks so that spoofed segments find it harder to reset or disrupt existing connections. Small state checks can greatly increase the cost of an attack. Old protocols stay robust through targeted, compatible fixes.
Read the full post →
An AKURUM wall cabinet brings together patch panel, router and cabling with cable openings, shelves and an active fan. The commercial equivalent started at over 150 US dollars. The house was wired according to TIA-568A.
Read the full post →
DNSSEC adds signed data and verifiable chains of trust to name resolution.
Read the full post →
In January 2010 the fifth release candidate of Linux 2.6.33 brought a driver for DVB cards with the widely used Mantis chipset into the main branch. The Intel graphics driver gained support for embedded DisplayPorts, and there were fixes for Radeon KMS, XFS and eCryptfs. According to the report, Nouveau, DRBD and Ceph had made it into the kernel before, while Btrfs was still considered experimental.
Read the full post →
In January 2010 Ruckus Wireless released the source code of its Wi-Fi test program Zap. Zap measures the throughput of wireless networks over time and predicts the minimum performance a network achieves 99.5 percent of the time. It was originally developed to characterise the real-time behaviour of IP video streaming.
Read the full post →
In January 2010 exploits were circulating for the Internet Explorer hole through which attackers had previously attacked Google and other companies. According to The Register, both Metasploit and Immunity Canvas had the code, which allowed control of the computer through an invalid pointer access. In tests it worked in IE 6 and 7 under Windows XP SP3, while IE 8 initially only crashed.
Read the full post →