Security

共 294 篇文章。

升级了FreeBSDChina.org的论坛

Security

没完没了的phpBB漏洞!!再也不能忍下去了!

今天终于找到alu跟他要了www的root,然后开始升级。

首先import新版本。

然后开始合并冲突,phpBB这群家伙居然到了这么多的patchlevel还在改表结构,真不知道他们的大脑是用来想什么的,预想www必然会出问题,果然,不过一切在掌控之中。

阅读全文… ( 本文约 174 字,阅读大致需要 1 分钟 )

spammers get smarter

Security

Spammers get smarter. My e-mail server has passed one or two spams for me each day, which is much more than it used to be.

They begin to use GIFs for sending spams… So, smarter, smarter spammers are going to win in some areas, but…

We have something to stop this! Hahaha… Let me try!

参与评论

学校终于还是启用了流量整形

Security

从禁止ping,到最后的流量整形。不知道明天会是什么。

我不认为这是有助于安全的设施。

如果你相信——你生活在一个没有任何安全威胁的环境,那么,任何人都会变得缺少防备的意识。

阅读全文… ( 本文约 263 字,阅读大致需要 1 分钟 )

不安全的原因

Security

我们来看看那个人说的这段话:

I’d be really surprised if somebody is actually able to get a real-world attack on a real-world pgp key usage or similar out of it (and as to the covert channel, nobody cares). It’s a fairly interesting approach, but it’s certainly neither new nor HT-specific, or necessarily seem all that worrying in real life.(HT and modern CPU speeds just means that the covert channel is _faster_ than it has been before, since you can test the L1 at core speeds. I doubt it helps the key attack much, though, since faster in that case cuts both ways: the speed of testing the cache eviction may have gone up, but so has the speed of the operation you’re trying to follow, and you’d likely have a really hard time trying to catch things in real life).

It does show that if you want to hide key operations, you want to be careful. I don’t think HT is at fault per se.

阅读全文… ( 本文约 821 字,阅读大致需要 2 分钟 )

Why you should not hide version.bind?

Security

This article has suggested a way of hiding version.bind string. From a security perceive, this is an overkill and can usually be harmful:

  • While it’s true that you can hide version.bind, the fact that version.bind is can be queried reveals that you are running BIND. It makes little sense to fake a version.
  • The need of hiding information, which is unnecessarily hidden like this, means that the system administrator is neglecting security.
  • Therefore, FOREACH(version.bind is queriable and is hidden) HACKEM :-)

Security can NOT be built on what others are not aware of.

参与评论

3 security advisories, and FreeBSD 5.4-RELEASE has been tagged

Security

Today, Colin has committed three security fixes that addresses three medium-risk security issues in FreeBSD kernel. That results in p11, p12 and p13 of FreeBSD 5.3-RELEASE, and has been committed to RELENG_5_4 as well so we will get that in the final release build.

Ken Smith has announced the tagging (with a mini heads-up in developers@), and then committed the naming (5.4-RELEASE) to the RELENG_5_4 tree. After that, RELENG_5_4 was tagged as RELENG_5_4_0_RELEASE, which is the last step of the release engineering that is related to the src/tree.

Please note that, this is not the final step of the final release. FreeBSD is very careful about the quality (not only as opposed to the kernel with colorful history of its security record, which is released under GPL and often release from time to time, haha, you know which is that) of a release, therefore, tagging does not mean that “we made it”, that is just a stage. Please be patient to wait for the PGP signed 5.4-RELEASE announcement BEFORE you download isos, even they were found on any sites.

阅读全文… ( 本文约 200 字,阅读大致需要 1 分钟 )

如何处理中迷药的情形 zz

Shared Chaos

From: ChinaUnix 清茶斋 女性中"迷藥"的處理方式 (很實用)

请转寄给您身边的女性朋友!

如果您是老师!更应该提供女性同学这一份数据!

1﹒争取时间
害人药片的药效会在15~30分钟内完全发挥作用,如果这一类药物被搀在酒精里,发作更快。如果发现得快,意识清楚,赶快喝大量的水催吐。如果已经出现头晕无力的现象,就不要再喝水催吐,因为在意识不清的时候催吐,容易呛到,甚至窒息。此时妳只有3分钟或更短的时间向可靠的人求助,为自己找安全的场所。

阅读全文… ( 本文约 1581 字,阅读大致需要 4 分钟 )