bk99.de entertain the web since 1997

Blog 2017

19 posts

Projects, Linux, networks, systems, finds and internet standards from 2017.

Freeing robot vacuums from the manufacturer’s cloud

Dennis Giese and DanielAW examine connected robot vacuums, expose their data collection and internal Linux systems and show ways to run your own IoT cloud. A household appliance becomes a privacy risk as soon as its sensors are tied to someone else’s infrastructure. Owning a device remains incomplete if essential functions only work with a manufacturer cloud.

Read the full post

ShadowPad: espionage backdoor uncovered in admin tools for Unix and Linux servers

In 2017 Kaspersky discovered the “ShadowPad” backdoor, which for 17 days was hidden in admin tools such as Xshell, Xmanager and Xftp from the Korean vendor NetSarang. The trojanised DLL was signed with valid NetSarang certificates and distributed via the regular update channel to banks, pharmaceutical and energy companies. The malicious code consisted of encrypted modules that only became active after a signal from the command server.

Read the full post

Dangerous SSH commands: critical security hole in GitLab

In 2017 GitLab contained a critical hole (CVE-2017-12426) through which attackers could execute commands on the server when importing a repository by URL. An option flag injected into the URL caused the rest of the address to be interpreted as a command. Versions 7.9.0 to 9.4.3 were affected; Recurity Labs had previously found similar bugs in Git, Mercurial and other version control systems.

Read the full post

RFC 8200: The IPv6 base standard

RFC 8200 replaces the original IPv6 specification and consolidates the matured base standard. An Internet Standard can become more precise through operational experience without changing its architecture. Deploying IPv6 requires full support in security and monitoring.

Read the full post

Why automation could have a different effect this time

KG examines how learning software is increasingly taking over cognitive routines alongside physical work and changing entire professions. Automation becomes a problem of distribution as soon as productivity grows faster than new participation. Professions look stable, although their individual tasks carry very different automation risks.

Read the full post

DirectAccess breaks DNSSEC

In the lab, Lutz Donnerhacke shows how DirectAccess, DNS64 and policy-based name resolution can prevent valid DNSSEC checks. DNSSEC initially recognised the answer altered by DNS64 as insecure. The test distributed trust anchors and validation policies via group policy.

Read the full post

BSI warns of security hole in 60 Netgear models

In January 2017 the BSI warned of a hole in around 60 Netgear router models through which attackers could read out the password of the web interface. It could be exploited if password recovery was disabled and the attacker was on the same network or remote management was active. The BSI rated the risk at level 5 without clearly explaining what that means.

Read the full post

Kernel maintainers need a manifesto to work

At linux.conf.au 2017, Intel developer Daniel Vetter proposed a manifesto for kernel maintainers because maintainers are increasingly overloaded. A single maintainer does not scale, and the kernel lacks people responsible for many areas of code. Vetter drew on experience as a maintainer in the Linux graphics stack.

Read the full post

Free firmware for the Raspberry Pi boots the Linux kernel

In January 2017 a free bootcode firmware for the Raspberry Pi was able to boot the Linux kernel directly for the first time. On the Pi, hard-wired code loads the proprietary Broadcom firmware onto the graphics unit, which then initialises the hardware. The free alternative was created mainly by reverse engineering, but still had gaps in USB, eMMC and power and clock management.

Read the full post