bk99.de entertain the web since 1997

Blog 2015

21 posts

Projects, Linux, networks, systems, finds and internet standards from 2015.

Dieselgate: Fraud becomes executable code

Daniel Lange and Felix Domke analyse Dieselgate technically, organisationally and procedurally and examine software extracted from real engine control units. For the analysis, control units from eBay and from Volkswagen were read out. Code can reproduce an organisational lie precisely and millions of times.

Read the full post

LinuxCNC gets an integrated CAM tool

Hackaday describes LinuxCNC-Features, which creates simple machining sequences, exports them as G-code and visualises them directly in LinuxCNC. At the time of the report, LinuxCNC-Features had been available for about two years. The tool supports milling and turning.

Read the full post

Part of this answer would unsettle you

A handwritten tick-box note transfers Thomas de Maizière’s much-discussed wording about the Hanover terror warning to the harmless question “Will you go out with me?”. The Germany versus Netherlands football match was called off on 17 November 2015. The German interior minister justified withholding details by saying they could unsettle the public.

Read the full post

The evolution of storage solutions on Linux

Lenz Grimmer traces the path from local file systems through LVM and cluster file systems to distributed, parallel and fault-tolerant Linux storage. Every additional storage layer trades simplicity for flexibility or resilience. Distribution removes single hardware failures but creates new consistency and operational problems.

Read the full post

Free Wi-Fi: Freifunk volunteers provide internet for refugees

In 2015 Freifunk initiatives provided refugee accommodation in Hamburg, Stuttgart, Hanover, Dortmund and other cities with free Wi-Fi. There was often no internet connection there; the Freifunk volunteers built the infrastructure, partly using directional radio, and financed it through donations. Authorities held back because of the German “Störerhaftung” (secondary liability), which the volunteers circumvented by routing the traffic via VPN to their own provider.

Read the full post

Web browsers: critical security hole in Firefox closed

In August 2015 attackers exploited a hole in Firefox’s same-origin policy that only affected versions with the built-in PDF viewer. Code distributed via advertising on a Russian website sent local files to a server in Ukraine. It specifically looked for developer files: on Linux, for example, /etc/passwd, SSH configurations and shell histories; on Windows, FTP and Subversion configurations.

Read the full post

O2 tests roaming with the E-Plus network

In January 2015 O2 tested national roaming with the network of E-Plus, which had belonged to Telefónica since October 2014. Registered customers in the Gummersbach, Siegen and Altenkirchen area could use the E-Plus UMTS network, where O2’s coverage was poorer. LTE was explicitly excluded.

Read the full post

Security hole discovered in Red Star OS

In January 2015 security researcher David Jorm found the first hole in North Korea’s Linux distribution Red Star OS 3.0. The udev rules file 85-hplj10xx.rules was writable by all users, so anyone could add a rule with arbitrary commands. udev executed it with root privileges as soon as a matching HP LaserJet printer (or, after adjustment, any USB device) was connected.

Read the full post

Google publishes Windows security hole

In early 2015 Google published a hole in Windows 8.1 after Microsoft had not closed it within 90 days. Via NtApphelpCacheControl, a user with restricted rights could gain administrator rights. Google’s experts had found the vulnerability at the end of September 2014 and informed Microsoft.

Read the full post