Personal 2008 IT highligts

Debian & the predictable random number generator

Ok this proves that even the best server OS out there has some lame security implementations. Lucky for me I only had to replace about a dozen SSH keys…..

Debian was awarded the pwnie award 2008 in the category EPIC FAIL for this one at BlackHat 2008.

Exchange 2003 and the Greylisting Bug

This one actually pissed me off so much, that I will never ever trust a Microsoft MTA again…. The worst part was the lacking acknowledgement by Microsoft… At least they decided to release a hotfix after the bug was first reported to them in 2006!!!

On the other hand I dont regret putting a lot of time and effort into postfix afterwards.

Netbooks

Starting out as a cool little gadget for computer geeks – the insanely fast development has turned these little machines into a serious alternative for mobile computing. Im very happy with my Aspire One 110L running Ubuntu 8.10 so far combined with my mobile phone for 3G connectivity. My EEE 701 however only lasted for 2 Months.

Might take a shot at the 10 Inch generation this year.

Back to Intel

After more than 10 years of AMD-CPU dominace in my personal and custom assembled machines (since my Intel Pentium 60) i finally chose an Intel based system again. I guess the price has been an important factor to me all those years. Just for the records:

  • AMD 486 SX25
  • AMD 486/100 DX4
  • Intel Pentium 60
  • AMD K6-2 350 Mhz
  • AMD K6-2 500 Mhz
  • AMD Duron 750 Mhz
  • AMD Athlon 1,2 Ghz
  • AMD Athlon XP 1,6 Ghz
  • AMD Athlon 64 XP 3000
  • AMD Athlon 64 x2 3600
  • IntelCore 2 Duo E8400

SOMA.FM: Webradio review

I actually took the time to look into the Firefox bookmarks for the current backtrack 3 security analisys distro and immediately got hooked to SOMA.FM

14 unique channels of listener-supported, commercial-free, underground/alternative radio broadcasting from San Francisco.

Very nice tunes indeed, my favorites are:

Drone Zone Served best chilled, safe with most medications. Atmospheric textures with minimal beats.

Space Station Soma Tune in, turn on, space out. Spaced-out ambient and mid-tempo electronica

Tag`s Trip Progressive house / trance. Tip top tunes.

I recommend you check out alle the channels listed directly on the main page!

Current Study reveals Acer as Netbook market leader

A current Quarterly Notebook PC Shipment and Forecast Report by displaysearch.com reveals Acer as the current leader on the Netbook market.

Here are the figures:

  • Acer — 38.3
  • Asus — 30.3
  • HP — 5.8
  • MSI — 5.7
  • Dell — 2.8
  • OLPC — 2.3
  • Medion — 2.3
  • Kohjinsha — 1.0
  • Intel — 1.0
  • Lenovo — 0.7
  • Toshiba — 0.5
  • All others — 9.1

Further info can be found at:

http://www.linuxdevices.com/news/NS8222978703.html

http://www.displaysearch.com/cps/rde/xchg/displaysearch/hs.xsl/quarterly_notebook_pc_shipment_and_forecast_report.asp

Analyzing SOHO Router Security

http://www.sourcesec.com/2008/11/09/hacking-the-routers-soho-router-security/

With embedded devices permeating today’s home networks, they have begun to attract a higher level of scrutiny from the security community than in previous years. In particular, the members of GNUCitizen have been relentlessly testing routers and wireless access points. Their discovery of multiple vulnerabilities in the BT Home Hub router affected a wide range of home networks in the UK [1], and their Router Hacking Challenge prompted a flurry of vulnerability reports against a variety of popular home routers, including the venerable Linksys WRT54G [2]. Specific vulnerabilities in home routers range from traditional Web attacks, such as XSS and CSRF, to authentication bypass attacks and buffer overflows; it is assumed that the reader has at least a passing knowledge of the attacks described in this paper.

SMTP flaming…

I always expect to find weird SMTP status codes… After all i dont trust Exchange MTA anymore since the greylisting bug….

But it is always amusing to find something like this (used by qmail)

25 - - 354+go+ahead+punk,+make+my+day  with reference to http://pobox.com/~djb/docs/smtplf.html

This was actually caused by bad formatting  with a non RFC 821 compliant SMTP client…

If you keep in mind that this error code message may appear in NDR to a user – which may potenially be a customer – this method is not really  suited to handle noncompliance.

Black Hat Webcast No. 4 today

Trust Doesn’t Scale: Practical Hijacking On the World’s Largest Network
Thursday, October 16 1:00 pm PST/4:00 pm ET • FREE

Speakers:

– Jeff Moss, Founder and Director of Black Hat
– Anton Kapela,Co-Owner and Partner at 5Nines Data
– David Mortman, CSO-in-Residence, Echelon One
– Max Kelly, CSO of FaceBook
– Ariel Futorasnky, Co-Founder of Core Security

http://www.blackhat.com/html/webinars/practicalhijacking.html

An interesting topic covering the border gateway protocol

Open Offfice 3 released – web servers down….

Here are some mirrors 😉

http://ftp.stardiv.de/mirmon/mirror-state.html

The language specific installers are usually located in the localized branch

Update: Even 2 days later, the website ist still struggling ver very excessive performance issues:

Apologies – our website is struggling to cope with the unprecedented
demand for the new release 3.0 of OpenOffice.org. The technical teams are
trying to come up with a solution.

Thank you for your patience.