Home Blog Page 9441

Legal threats shut down NetSaint

Author: JT Smith

logic writes: “In a post to NetSaint mailing lists last night, Ethen Galstad announced that he would be stopping work on the GPL-licensed network monitoring software due to the threat of legal action from World Wide Digital Security, Inc. (makers of Saint, a security vulnerability testing tool, which is the claimed target of name infringement). This bears a striking similarity to previous stories, but with a very different outcome.”

Verbatim’s got CD-Rs certified for 24x recording

Author: JT Smith

The Register: “Verbatim is claiming its got the industry’s first CD-R discs
certified for full-speed 24x recording.

Its press statement says that “in addition to providing highly
reliable audio, video and data recordings at speeds of up to 3.5
MBps with the new 24x drives and 3.0MBps with the new 20x
drives, the media can be used with existing CD drives at speeds
ranging from 1x to 16x.”

First European Zope conference

Author: JT Smith

beehive writes: “The 1st
European Zope Conference
will take place on the 12th and 13th of July in Berlin. If you are a serious Zope developer or are thinking about becoming one this is the conference you shouldn’t miss. Learn more about Zope technologies such as Squishdot/Swishdot, ZPatterns, Smart Objects, MetaPublisher, and how companies and organisations are using these technologies.

Security geek developing WinXP raw socket exploit

Author: JT Smith

The Register: “Security specialist Steve Gibson has created quite a fracas with
his increasingly vocal opposition to the raw-socket
connectivity planned for Windows-XP, and upon which he
bases predictions of impending chaos for the entire Internet, so
he’s decided to exploit the very threat he claims will make the
Internet permanently unstable.”

Category:

  • Linux

The condemned and their websites

Author: JT Smith

Wired: “Death row is full of those who plead their innocence, and the world is full of those who despise the death penalty. They’ve found a common ground online.”

Closed circuit of execution stays closed

Author: JT Smith

CBSNews: “Officials from the Justice Department, FBI and
Bureau of Prisons have been secretive about how
they would make sure the videoconference was
secure, and several computer security experts
have said it would not be out of the question for a
hacker to splice into the video feed and decrypt
the signal.”

Category:

  • Linux

ISS Xforce: BIND inadvertent local exposure of HMAC-MD5 keys

Author: JT Smith

LinuxSecurity: “A flaw exists in the dnskeygen utility under BIND version 8 and the dnssec-keygen utility
included with BIND version 9. The keys generated by these utilities are stored in two files. In
the case of HMAC-MD5 shared secret keys that are used for dynamic updates to DNS servers,
the same secret keying material is present in both files. Only one of the files is configured by
default with strong access control. The resulting exposure may allow unauthorized local users
to obtain the keying information. This may allow attackers to update DNS servers that support
dynamic DNS updates.”

Category:

  • Linux

Talking with Jim Gettys

Author: JT Smith

“Jim Gettys is a living legend in the Linux and Unix community. He started the original X Window System
which today forms the basis of the Linux and Unix GUI. Today Jim is still active in the community working at
Compaq making Linux and X run on the iPaq. He was also elected to the GNOME Foundation board by
GNOME hackers. Jim Gettys is (as you might expect) an extremely busy man, but I was lucky enough to catch
up with him for a few questions.” More at LinuxPower.org.

Category:

  • Linux

Password snafu blocks net access for millions

Author: JT Smith

PCWorld: “Password problems at EarthLink knocked as many as 1.5 million users off the Internet Monday,
preventing them from accessing the Web and their e-mail for much of the day.

The outage impacted EarthLink customers with MindSpring-labeled accounts (EarthLink
bought MindSpring in 1999). Starting at about 11:30 a.m. EST, customers who tried to go online
ran into an impassable “authentication problem.”

eZ Publish announces contest

Author: JT Smith

pkej writes: “eZ systems and MyGold.com would like to invite the community to a competition where the three winners will receive free 12 months eZ publish hosting and a DEM 100.- gift certificate redeemable at MyGold’s online store. The competition are in three classes, eZ publish design, eZ publish site and eZ publish module. The closing date is August 1, 2001. Read the full announcement and the rules