bk99.de entertain the web since 1997

Blog 2013

19 posts

Projects, Linux, networks, systems, finds and internet standards from 2013.

Scanning the entire IPv4 internet in minutes

J. Alex Halderman presents ZMap, which scans the public IPv4 address space efficiently and thereby makes vulnerability, deployment and remediation measurable across the internet. Tools change research when measurements that used to take months become possible in minutes. Internet-wide visibility turns local misconfigurations into quantifiable global patterns.

Read the full post

The history and future of everything on one timeline

KG condenses the development of the universe from the Big Bang into the distant future and makes unimaginable periods of time comparable. Scales change meaning, because the same span of time seems tiny or overwhelming depending on the frame of reference. A temporal perspective links scientific facts with the question of human responsibility.

Read the full post

SSH client PuTTY 0.63 plugs security holes

In August 2013 PuTTY 0.63 closed four holes rated as critical in the SSH client widely used on Windows. They affected the modmul function, the handling of public key signatures, buffer overflows when checking DSA signatures, and the wiping of session keys and passphrases from memory. Since PuTTY had not been updated since 2011 and has no update function, users had to act themselves.

Read the full post

More secure temporary files for Linux

In 2013 Linux 3.11 allowed temporary files that are not visible in the file system at all. For this purpose the open() and openat() system calls received the O_TMPFILE flag. This removes the basis for attacks in which attackers gain higher privileges via predictable names of temporary files, for example using symlinks.

Read the full post

Long-term maintenance for Linux kernel 3.10

In August 2013 Greg Kroah-Hartman announced plans to maintain Linux 3.10 for two years as a longterm kernel; the LTSI kernel for device manufacturers was also to be based on it. Alongside it, the longterm branches 3.0, 3.2 and 3.4 continued with different end dates. Ben Hutchings wanted to maintain 3.2 until about 2016 because Debian 7 was based on it.

Read the full post

Kernel hacker Alan Cox takes a break

In January 2013 Alan Cox announced a withdrawal for family reasons, giving up the job at Intel and kernel development. Cox, 44 at the time, had long been regarded as number two after Linus Torvalds and had been working on the kernel for Intel since 2008. Shortly before, Cox had criticised Fedora 18 as the “worst version I have ever seen”.

Read the full post

Critical security hole in the Security Manager

In January 2013 an already actively exploited hole became known in the Security Manager of Java 7 up to and including Update 10. A combination of JMX MBean and internal JavaScript classes in an applet could be used to bypass the Security Manager and execute code from websites. US-CERT recommended disabling Java in the browser; there was no patch from Oracle yet.

Read the full post

OpenVPN fully implements IPv6

In January 2013 OpenVPN 2.3.0 appeared with full IPv6 support, as developer Gert Doering announced. A serious bug in the last beta version had delayed the release by a few days. Also new was the optional use of PolarSSL, which the Dutch government had already been using since 2011 as OpenVPN-NL.

Read the full post