Enabled SPF protection on beastie
A decision was made to enable SPF on beastie. SPF is a technology that mitigates forged spam (while it itself is not totally spam proof, as spammers can set up their own SPF record :-)
共 234 篇文章。
A decision was made to enable SPF on beastie. SPF is a technology that mitigates forged spam (while it itself is not totally spam proof, as spammers can set up their own SPF record :-)
This article has suggested a way of hiding version.bind string. From a security perceive, this is an overkill and can usually be harmful:
Security can NOT be built on what others are not aware of.
Colin Percival has released his paper about a complex security issue that accompany with Intel HyperThreading Technology. This has became FreeBSD Security Advisory SA-05:09.htt.
Colin is very effective man that has made some changes to the kernel, and so@ has approved this, and 5.4-RELEASE gets its first patchlevel.
I’m happy that this did not forced me to go to the hosting provider :-)
Today, Colin has committed three security fixes that addresses three medium-risk security issues in FreeBSD kernel. That results in p11, p12 and p13 of FreeBSD 5.3-RELEASE, and has been committed to RELENG_5_4 as well so we will get that in the final release build.
Ken Smith has announced the tagging (with a mini heads-up in developers@), and then committed the naming (5.4-RELEASE) to the RELENG_5_4 tree. After that, RELENG_5_4 was tagged as RELENG_5_4_0_RELEASE, which is the last step of the release engineering that is related to the src/tree.
Please note that, this is not the final step of the final release. FreeBSD is very careful about the quality (not only as opposed to the kernel with colorful history of its security record, which is released under GPL and often release from time to time, haha, you know which is that) of a release, therefore, tagging does not mean that “we made it”, that is just a stage. Please be patient to wait for the PGP signed 5.4-RELEASE announcement BEFORE you download isos, even they were found on any sites.
Many SSH clients supports “key agent” or “authentication agent”, which holds private key for you, and ease the authentication process.
By default, OpenSSH does not enable this. You can easily use ssh-agent(1) to accomplish the mission.
ssh-agent startx
The above command will start X session with ssh-agent. This means that you can add private key to the agent.
ssh-add ~/.ssh/id_dsa
Add your own ssh key.
Then ssh authentications will be accomplished automatically. Note that you may need to use ssh -A in certain configurations.
They did it again!
CAN-2005-0176
CAN-2005-0177
CAN-2005-0178
CAN-2005-0449
Before patching your already fragile kernel, consider other true Open Source operating systems, like FreeBSD and DragonFlyBSD!
一个神话的最终结束……
http://www.schneier.com/blog/archives/2005/02/sha1_broken.html
Every quarter we got the same news: Linux did it again!
Yes, they DID it again. Many sites became victim during the last scan of awstats vulnerability, the most famous ones are www.phpbb.com, and moto.debian.org.tw, etc. You can Google the cracker organization and find more.
Why Linux is again and again vulnerable to these hack attempts? Why other systems doesn’t have such serious security issues even when an exploit is published? The answer is apparant: Linux did worst ever, among all Operating Systems, even when you include Windows. Imagine, a kernel which can permit normal users to gain root privilege.
What is a privilege elevation? It meant that someone who (maliciouslly) obtain higher privilege through some method that is not predicated by programmer.
In order to prevent it, we should avoid giving unnecessary privileges, and validate all input. However, in a imperfect world, just validating everything is not enough, since there are too many things that can not be validated easily.
On most Unix systems, we have a “set uid” bit that can allow subsequent process to run under other credentials. This, however, opens an window that we can potentially allow malicious code to be injected into the system, to obtain higher privileges.