bk99.de entertain the web since 1997

Blog 2012

19 posts

Projects, Linux, networks, systems, finds and internet standards from 2012.

hß Security update check shut down because of a security hole

In August 2012 heise Security shut down its online update check because it required Java, and Java 7 had just been found to have a highly critical hole that was already being exploited. The hole affected all browsers with the Java 7 plugin; modules for the Blackhole exploit kit were already circulating, and no patch from Oracle had been announced yet. As an alternative, heise recommended the locally installed Personal Software Inspector.

Read the full post

Wi-Fi mesh as an emergency radio network

In 2012 researchers at TU Darmstadt used wardriving to investigate whether private Wi-Fi routers in cities could form an emergency radio network for first responders. In half a square kilometre they found 1,971 Wi-Fi cells; with a range of 30 metres, each node had an average of ten neighbours and only 2 percent were isolated. However, the routers would need mesh firmware and a power supply that holds up in disasters.

Read the full post

New Linux kernels bring performance improvements

In 2012 kernels 3.0.39 and 3.2.25 were the first to deliberately bring performance optimisations into the stable and longterm branches. Mel Gorman and Greg Kroah-Hartman had extended the rules to also allow changes that fix important performance or interactivity problems. Typical systems were hardly expected to get faster, but on an SGI UV system with 640 cores, throughput when writing to tmpfs rose from 300 to 430 MByte/s.

Read the full post

Root privileges possible via memory exploit

In January 2012 a hole became known in the Linux kernel from version 2.6.39 through which local users could gain root privileges via /proc/pid/mem. Since 2.6.39 write access had been possible there, and the check via self_exec_id could be bypassed with a child process. Jason A. Donenfeld explained the bug, and shortly afterwards exploits via the setuid program su were circulating; Android was affected too.

Read the full post

Bug in network protocol causes crashes

Since Linux 2.6.36 the IGMP code of the IPv4 stack had contained a bug that could trigger a kernel panic (CVE-2012-0207). Simon McVittie found it after a notebook crashed several times: a crash log recorded with netconsole revealed a division by zero when processing an IGMP packet. The bug was fixed in 3.0.17, 3.1.9 and 3.2.1.

Read the full post

Aptosid and Siduction with Linux kernel 3.1

The Debian Unstable-based distributions Aptosid and Siduction appeared in new versions in early 2012. Aptosid had emerged from Sidux after a dispute between developers and the association, and Siduction in turn split off from Aptosid in summer 2011. Aptosid 2011-03 brought kernel 3.1, Wake-on-WLAN for Broadcom and Realtek cards and booting on UEFI systems.

Read the full post