Security

共 234 篇文章。

Spammer!!

• Security

So someone has hacked 210.51.165.42, which apparantly is an open proxy that can lead to attacks. The box has tried to trick my mail server into trusting him and thus relay spams, but my postfix configurations has rejected all its requests. Considering to have pf configuration to avoid it…

参与评论

portsnap added to base

• Security

Colin has finally added portsnap and related stuff (bsdiff, etc) to FreeBSD 7.0-CURRENT. This would not be MFC’ed before 6.0-RELEASE, but still good enough because it will attract more users to use it.

Portsnap is a secure and efficient alternative to the current ports tree update approach. Since it goes through HTTP, it is much easier than other existing methods to use it to obtain ports, especially from some brain-damaged administrated networks.

参与评论

ssh.com的sshd2:疑似有問題

• Security

今天有人跟我說他裝的sshd2莫名其妙地起了100多進程,登上去一看果然如此,十分吊詭。用OpenSSH就一點事都沒有,於是開始建議所有人改回OpenSSH(過去OpenSSH確實有過一些安全上的不良記錄,不過在OpenBSD一群人的努力之下已經兩年沒有出過安全問題了,所以我認爲可以重新開始信任這一軟体)

参与评论

升级了FreeBSDChina.org的论坛

• Security

没完没了的phpBB漏洞!!再也不能忍下去了!

今天终于找到alu跟他要了www的root,然后开始升级。

首先import新版本。

然后开始合并冲突,phpBB这群家伙居然到了这么多的patchlevel还在改表结构,真不知道他们的大脑是用来想什么的,预想www必然会出问题,果然,不过一切在掌控之中。

阅读全文… ( 本文约 174 字,阅读大致需要 1 分钟 )

spammers get smarter

• Security

Spammers get smarter. My e-mail server has passed one or two spams for me each day, which is much more than it used to be.

They begin to use GIFs for sending spams… So, smarter, smarter spammers are going to win in some areas, but…

We have something to stop this! Hahaha… Let me try!

参与评论

学校终于还是启用了流量整形

• Security

从禁止ping,到最后的流量整形。不知道明天会是什么。

我不认为这是有助于安全的设施。

如果你相信——你生活在一个没有任何安全威胁的环境,那么,任何人都会变得缺少防备的意识。

阅读全文… ( 本文约 263 字,阅读大致需要 1 分钟 )

Keeping your ssh connection alive

• Security

Sometimes, when you are in a NAT’ed environment, ssh connection may be dropped when the gateway is busy.

OpenSSH has provided a solution against this.

The option is called “ClientAliveInterval”. With this setting in your sshd_config, sshd(8) would send a ping message through the encrypted channel periodically, thus prevent the early drop.

The default setting is 15, meaning the ping period is 15 seconds.

阅读全文… ( 本文约 79 字,阅读大致需要 1 分钟 )

不安全的原因

• Security

我们来看看那个人说的这段话:

I’d be really surprised if somebody is actually able to get a real-world attack on a real-world pgp key usage or similar out of it (and as to the covert channel, nobody cares). It’s a fairly interesting approach, but it’s certainly neither new nor HT-specific, or necessarily seem all that worrying in real life.(HT and modern CPU speeds just means that the covert channel is _faster_ than it has been before, since you can test the L1 at core speeds. I doubt it helps the key attack much, though, since faster in that case cuts both ways: the speed of testing the cache eviction may have gone up, but so has the speed of the operation you’re trying to follow, and you’d likely have a really hard time trying to catch things in real life).

It does show that if you want to hide key operations, you want to be careful. I don’t think HT is at fault per se.

阅读全文… ( 本文约 821 字,阅读大致需要 2 分钟 )