Senin, 16 Agustus 2010

Re-connected

Shock! Horror! I'm back online. 

Bah Humbug I say to the nay-sayers amongst you who refused to believe I could disconnect from the digital world for a month. I am a stubborn geek with resolve and stamina. Admittedly having spent quite a lot of that time either at sea, or in the sea, both activities that aren't very connection friendly, it really wasn't that tricky.

What did I miss? 

There were a few occasions I'd normally have turned to Facebook to talk about stuff, mostly because sharing our lives has become terribly habitual, (I'll save my rant about the TGV / Eurostar for another day), there were a few occasions when curiosity would have lead me to a search engine, and had I been inclined and prepared to pay for overseas data roaming,  I could probably have added some new venues to FourSquare, and yes I probably should have read my race instructions before getting on the boat last weekend again but I knew I could rely on my crewmates to have done the honours, knowing that I was away, so none of these things were a big enough deal to make me feel I've missed much.  Sure, I will no doubt get around to uploading some pictures to Facebook and Flickr over the next little while, because it is nice to share what you've been up to with friends and family, but overall it's been rather refreshing to be living life in real time rather than reading about real time for a few weeks!

Who knows what's changed in the digital world, I've yet to catch up on a pile of alerts, round-ups and reading, let alone the email boxes stuffed to overflowing, but I'm sure if it was important I'll find out over the next few days.


I think it's a genuinely useful exercise for the geek fraternity to disconnect for a while, it gives you a healthy injection of perspective on how and where digital activity fits into the lives of other people in other places. Big cities and working in the industry distort your view.  Not that that stopped me smiling and making internal mental note when a 70 something friend of mine at the beach, someone whom I've known for over 20 years, whipped out his mobile to take some photos of me. He's not on Facebook (I asked) but he does download pics to his computer and share them via email.  

Nothing changes. Digital's not just for the young or the techy.

Senin, 09 Agustus 2010

Wikipedia Is Mostly Down Due to Database Problems

No word on when the matter will be resolved

Wikipedia is currently experiencing problems and can be unavailable at times. The site has tracked down the issue to a filled-up hard drive and is currently looking at ways to resolve this.

“At 10:57 UTC, the master database server for s3 (the cluster that holds most of our wikis) had a full disk and stopped writing. For this reason it’s no longer possible to edit these
wikis. Because all slave servers for s3 stopped as a result, these wikis are now running read-only from a single server, which means you’ll probably see lots of database errors even when just reading,” the site explains.

“The larger wikis live on separate clusters and are not affected. For details on which wikis are affected, see below. We are working on resolving this issue as fast as we can,” the announcement added.

As Wikipedia explains, the problem is rather trivial yet, for a site its size, it proved critical. Since there is no more space on the hard drive, new entries can’t be written to the database. This means that any attempts to write data will fail. This doesn’t relate only to editing articles or adding new ones, any action that would be logged and added to the database won’t work. Right now, even logging it doesn’t work.

Some sections of the site are accessible and most of the individual entries work. The main wikipedia.org page though doesn’t load. Wikipedia provides a list of wikis that are not entirely down, though you may experience problems on them as well: bg.wikipedia.org, bg.wiktionary.org, commons.wikimedia.org, cs.wikipedia.org, de.wikipedia.org, en.wikipedia.org, en.wikiquote.org, en.wiktionary.org, eo.wikipedia.org, fi.wikipedia.org, fr.wikipedia.org, id.wikipedia.org, it.wikipedia.org, ja.wikipedia.org, nl.wikipedia.org, no.wikipedia.org, pl.wikipedia.org, pt.wikipedia.org, ru.wikipedia.org, sv.wikipedia.org, th.wikipedia.org, tr.wikipedia.org, zh.wikipedia.org.

There’s no word on when you can expect the site to be back up and running as it should.

Parted Magic 5.2 Incorporates GParted 0.6.2 - Free Download

Asian language support was improved

Patrick Verner announced a few minutes ago (August 3rd) the immediate availability of Parted Magic 5.2 operating system for partitioning tasks. This second maintenance version of Parted Magic 5 comes with the newly released GParted 0.6.2 application. Beside the usual bug fixes, Patrick Verner improved the support for Asian languages, by adding SCIM and GCIN. Parted Magic is an operating system created to help users easily partition their hard drives or perform various recovery tasks.

"The new GParted re-enables MiB partition alignment option and fixes the problem with logical partition move overwriting the EBR. A mess of bugs have been fixed with the help of Dick Burggraaff (burdi01), Jason Vasquez, and most of all, users willing to take the time to report them and help us test. [...] GCIN is automatically started when Taiwanese is selected at the boot menu and SCIM is automatically started when Japanese or Chinese is selected at the boot menu." said Patrick Verner on the official release announcement.

The following applications were updated in Parted Magic 5.2:

· gDisk 0.6.9;
· LFTP 4.0.9;
· ms-sys 2.2.0;
· SimpleBurn 1.5.2.1;
· chntpw 100627;
· hdparm 9.29;
· memtest86+ 4.10;
· Partclone 0.2.12;
· Wiper 2.7;
· Partimage 0.6.9;
· GParted 0.6.2.

The following packages were added in the new Parted Magic 5.2 operating system:

· GCIN 1.5.4;
· SCIM 1.4.9;
· scim-anthy 1.2.4;
· scim-bridge 0.4.16;
· scim-hangul 0.3.2;
· scim-input-pad 0.1.2;
· scim-m17n 0.2.3;
· scim-pinyin 0.5.91;
· scim-tables 0.5.9.

About Parted Magic

Parted Magic is a business-card operating system based on Slackware Linux, with programs that allow you to partition hard disks with ease. Programs like Partition Image, TestDisk, fdisk, sfdisk, dd, ddrescue, and a good documentation will help you in your partitioning tasks. Parted Magic is licensed under the GNU General Public License (GPL).

Download Parted Magic 5.2 right now from here.

Linux Kernel 2.6.35 Officially Released - Download Now!

Includes Btrfs and XFS improvements

Last night, August 1st, Linus Torvalds proudly announced the release of Linux kernel 2.6.35. The new version includes Direct-IO Support for the Btrfs filesystem, XFS filesystem experimental journal mode, perf improvements, VC1 and H.264 video acceleration for Intel G45+ chipsets, initial support for the Intel Cougarpoint graphic chipset, AMD Radeon power management support, CAIF protocol support (see below for a detailed list), and many other fixes.

"This may have been a fairly odd release cycle with my rather strict -rc rules before -rc3, but on the whole I think I liked it, and it seems to have worked out ok. I relaxed my extreme stance after getting back from vacation, so the latter half of the rc series was more normal. But even then I got the feeling that people were perhaps a bit more aware of the whole "regression fixes only" model, which is all good. It's a bit hard to judge, but there are some numbers to back it up: in the 2.6.34 release, there were 3800 commits after -rc1, but in the current 35 release cycle we had less than 2000." - Linus Torvalds said in the official release announcement.


Highlights of Linux Kernel 2.6.35:

· Support for transparent spreading of incoming network traffic load, across CPUs;
· Btrfs filesystem improvements;
· Delayed logging for XFS filesystem;
· Kernel debugger (KDB) frontend;
· perf improvements;
· Intel graphics improvements;
· Memory compaction;
· Multiple multicast route tables support;
· Support for L2TP v3 (RFC 3931);
· Support for the CAIF protocol;
· APEI (ACPI Platform Error Interface) support.

These are just a few of the new features available in the Linux kernel 2.6.35. For a complete list of all the newly supported devices, newly added drivers, etc., please visit the official release notes page.

You can download Linux Kernel 2.6.35 sources right now from here.

New Windows Vulnerability Could Re-Enable Old Exploits

Killbit bypass flaw being investigated

A newly discovered Windows vulnerability might allow hackers to re-enable any ActiveX exploit previously blocked by Microsoft. Vulnerability researchers from VUPEN Security have successfully crafted a proof-of-concept attack that leverages the flaw to bypass an active killbit.

Setting killbits is the default method used by Microsoft to close security holes that can be exploited via ActiveX. Each ActiveX control has a corresponding unique identifier known as CLSID. Killbits are registry values that tell software like Internet Explorer or Microsoft Office not to execute controls with specific CLSIDs because they are malicious.

"We found a potential Windows Kill Bit bypass vuln which could open hundreds of flaws exploitable via killed ActiveX controls," VUPEN announced via Twitter. "We are still investigating the Windows Kill Bit bypass but we already created an exploit working with a kill bit set to True!" a later update reads.

If indeed the vulnerability found by VUPEN can be used to bypass any killbits, attackers could theoretically leverage it to make previously blocked ActiveX exploits work on fully patched Windows systems. Normally, this shouldn't be the case, because when bugs are discovered, vulnerability research companies work with vendors to help them create a patch.

However, VUPEN has recently changed its policy and is no longer offering vulnerability intelligence for free to affected developers. The company only shares the research with its customers, which include governments, intelligence agencies, law enforcement units, security vendors and corporations.

Since Microsoft has publicly declared itself unwilling to pay for bug information, it will have to find this vulnerability on its own or with assistance from other companies, preferably before the malicious hackers figure it out. And even if they do manage to find it and patch it, this could still spell trouble for a large number of users.

First of all, there are a lot of computers still running Windows XP SP2, which will not receive a fix for this issue because Microsoft cut support for that version of the operating system last month. And then there's the huge percentage of users that fail to install security patches. Lets take for example a user who did a fresh install of Windows Vista with SP2, but did not install any updates afterward. He used to be protected from all ActiveX exploits that appeared before Vista SP2, but not anymore.

New Firefox Extension Can Thwart BHSEO Attacks

Attackers' own tricks turned against them

Security researchers from Zscaler, a provider of cloud-based security solutions, have developed a Firefox extension aimed at protecting users from black hat search engine optimization (BHSEO) attacks. Dubbed Search Engine Security (SES), the add-on allows altering the Referer header, which tricks the malicious pages into not delivering their payload.

Black hat search engine optimization, otherwise known as search result poisoning, is the practice of hijacking popular search keywords and pushing malicious links at the top of search results in order to trick users into visiting them. This is currently one of the most common methods of distributing scareware, rogue applications that pose as antivirus products.

"Blackhat SEO has become the most prevalent threat facing end-users on the web today, surpassing social networking threats. Our research has shown that virtually any popular search term will contain malicious sites within the top 100 results at all major search engines including Google, Yahoo! and Bing. In some cases, up to 50% of search results are malicious. When combined with social engineering attacks such as delivering fake antivirus applications or fake software updates, these attacks are incredibly effective," Michael Sutton, VP of Security Research at Zscaler, explains.

The security industry has struggled to come up with an effective solution to block these attacks for a long while now. Practice has already demonstrated that blacklist-based approaches are ineffective, because attackers rotate the malicious links too quickly. Real-time scanning all pages shown in search results before the user actually visits them has brought strong criticism from web developers because the practice was generating extra and unnecessary traffic for their websites.

Zscaler's solution is simple and elegant, as it turns the attackers' own tricks against them. Before delivering the payload, most, if not all of these malicious pages check to see if the visiting user actually came through the poisoned search engine results. This is done by inspecting the Referer field in the request header sent by their browser. Attackers employ this method in order to prevent the landing page from being discovered by crawlers or other automated security scanners.

The Search Engine Security Firefox extension allows setting the Referer header to a particular URL for all major search engines. This will trick the BHSEO landing pages to no longer serve their payload to SES users. However, there are some legitimate uses for websites to know if a visitor came through a particular search engine. That's why the add-on also comes with a whitelist, where users can add exceptions for the websites they trust.

The Search Engine Security add-on can be downloaded and installed from here.

You can follow the editor on Twitter @lconstantin

New Code Injection Masquerades as Google Analytics

Part of a scareware distribution campaign

A new mass injection tries pass the rogue code added to compromised websites as the Google Analytics script. The attack is actually part of a malicious campaign to distribute a new piece of scareware that has a very low detection rate.

The compromises are likely the result of SQL injection vulnerabilities in mostly ASP and ASP.NET websites. Successful exploitations leads to a rogue <script> tag being injected right after the </title> element in the HTML output.

The src of the this tag loads a script called urchin.js from a domain with the name google-server43.info. This is clearly meant to hide the infection and pass the code as being part of Google Analytics, with which the urchin.js name is normally associated. The domain name is also indicative of this.

Searching for the rogue script tag on Google reveals some 154,000 hits. Although these results include multiple infected pages under the same domain, it's pretty safe to assume that tens of thousands of websites have already been affected by this new attack.

The rogue script performs a check to see if the visitor has already been targeted and if they weren't, proceeds to bombard them with bogus security alerts, which claim their system is infected with fictitious malware. This scareware campaign pushes a fake antivirus program called System Security AntiVirus.

This sort of applications try to scare users into buying a license for a fake an useless product in order to clean their system of infections that didn't exist in the first place. This is a very profitable criminal model that has been for years now. Unfortunately victims of such scams, will not only depart with a considerable sum of money, but will also compromise their credit card details.

The scareware file distributed in this case has a very low detection rate based on signatures alone. Only 4 of the 42 antivirus engines on VirusTotal currently identify it as malicious.