bk99.de entertain the web since 1997

Blog 2023

31 posts

Projects, Linux, networks, systems, finds and internet standards from 2023.

Recovering files encrypted by Black Basta

Tobias Mueller analyses the Black Basta encryptor and uses a faulty reuse of the keystream to recover files with a known-plaintext attack. Ransomware can undermine strong primitives itself through faulty use. Data recovery benefits from knowledge of file formats, reverse engineering and cryptography together.

Read the full post

Mixtral and mixture of experts

Mixtral activates only part of its experts per token and combines high model capacity with limited computation. The article explains the architecture, usage and open availability. Mixtral uses eight experts and activates two of them per token.

Read the full post

4.5 billion years of Earth’s history in one hour

KG scales the entire history of the Earth to a film in which each second shows roughly one million years of biological and geological change. A continuous presentation conveys duration differently from a list of historical milestones. Complexity emerges over long unspectacular phases and short visible transitions.

Read the full post

Security holes: patches protect Cisco firewalls and switches

In August 2023 Cisco closed several holes in firewalls and switches. Rated high were an SNMP hole in Firepower 4100 and 9300 through which authenticated attackers could trigger restarts, an IS-IS hole in Nexus 3000 and 9000 without authentication, and a DoS hole in NX-OS. Further medium holes affected, among others, the Application Policy Infrastructure Controller.

Read the full post

Making LLMs lighter with AutoGPTQ

The AutoGPTQ integration quantises already trained language models to a few bits and integrates them directly into Transformers. This considerably lowers the memory requirement for local inference. GPTQ typically quantises weights to four bits after training.

Read the full post

Print management solution: security holes endanger PaperCut servers

In August 2023 PaperCut closed two high-rated holes in its print management software. Via CVE-2023-3486, attackers could upload files without logging in and fill up the hard disk; via CVE-2023-39143 they could view and modify files, and according to Horizon3 even execute code. The Windows hole required the External Device Integration function, which was active by default in PaperCut NG Commercial and MF.

Read the full post

Return of compulsory routers? Dispute over the network termination point for fibre

In 2023 network operators and consumer advocates disputed whether the freedom of choice of router, in force since 2016, also applies to GPON fibre connections. The associations Anga, Buglas, Breko, VKU and VATM applied to the Federal Network Agency to move the network termination point behind the operator’s fibre modem (ONT). Customers would then no longer be able to operate their own fibre router directly at the connection socket.

Read the full post

Training LLaMA with RLHF

StackLLaMA combines supervised fine-tuning, a reward model and PPO into a complete RLHF pipeline. The guide shows how PEFT and quantisation lower the hardware requirements. The pipeline first uses instruction data for supervised fine-tuning.

Read the full post

Federated learning with Flower

The article trains transformers via Flower without bringing the participants’ raw data together centrally. Only local model updates are coordinated and aggregated. Flower coordinates federated training rounds between clients and server.

Read the full post

Cisco warns of security holes it will not patch

In January 2023 Cisco warned of critical holes in the small business routers RV016, RV042, RV042G and RV082, but announced that it would not deliver any more updates. Manipulated HTTP requests to the web interface could bypass authentication and gain root access (CVE-2023-20025). As the devices had reached end of life, Cisco only pointed to blocking ports 443 and 60443, although proof-of-concept code already existed.

Read the full post

Security hole in SugarCRM servers actively exploited

In early 2023 attackers exploited a critical hole in SugarCRM (CVE-2023-22952) to take over servers and install malware. Authentication could be bypassed via the path /index.php/, after which a POST request uploaded a PNG file containing PHP code that was executed when called up later. By 11 January Censys found 354 compromised servers, just under twelve percent of all 3,059 reachable instances.

Read the full post

Linux developers ask for focus for touchpad support

Since April 2020, Linux users had been funding better touchpad gestures under Linux through a Gitclear donation campaign, implemented by Povilas Kanapickas. By early 2023 the core goals had been achieved: gestures worked in many Wayland and X servers, XWayland and in GTK and Qt. The team asked the community in a survey whether it should continue working on support in individual applications.

Read the full post