The archives for `Sicurezza'


Lug 16

Ubuntu fortress

The news is old of some month, but, to my opinion, it deserves of being riesaminata, above all from who as me it has a lot to heart the risen ones of “pinguino”. According to the site register in “hacking contest” svoltosi ones during a famous conference of Canadian emergency, the CanSec West, the surer operating system has demonstrated Ubuntu. 

fortezza.jpg

In contest the more famous O.S, Seen Windows, Mac You add “Ubuntu Fortress” to Of the .icio.usYou add “Ubuntu Fortress” redditYou add “Ubuntu Fortress” to TechnoratiYou add “Ubuntu Fortress” to Stumble UponYou add “Ubuntu Fortress” to DiggitaYou add “Ubuntu Fortress” to Wikio

Down 19

First bug for firefox 3

I lack already released and baggato? It would seem! Some investigators who join to the program Zero Day Initiative di Tipping Point have found a vulnerability in Firefox 3, to said they, somewhat important they have communicated and it to Mozilla. 

vulnerability.jpg

Own yesterday Tipping Point has published article in which bug evidences like this, that it plagues version 3,0 thus as in past had interested the 2,0, would allow the execution of arbitrary code, but only through the interaction of the customer. In good substance it is necessary to cliccare an email or to visit a page web “malicious”.
While Mozilla works to the resolution of the Tippin problem point declares not to want to disclose ulterior deepenings approximately the vulnerability in issue, promising but that hardly a patch it will be ready of it will give immediately communication on the pages of own site.

Down 16

Ubuntu/Debian, vulnerability in Openssl

Here ready on a silver plate a beautiful security bug for Debian and derived in openssl. In good substance the generator of accidental numbers in the package debian of opessl is expectable, consequently also the crittografata key can be discovered. 

security-bug.gif

Here the data in synthesis:
=> Package: openssl
=> Vulnerability: predictable random number generator
=> Problem type: remote
=> Debian-specific: yes
=> CVE Id (s): CVE-2008-0166
=> Checkout description and recommended fix to here:

To execute a control for the location of keys “weak people”:

# wget http://security.debian.org/project/extra/dowkd/dowkd.pl.gz
# wget http://security.debian.org/project/extra/dowkd/dowkd.pl.gz.asc
# gpg - keyserver subkeys.pgp.net - recv-keys 02D524BE
# gpg - verify dowkd.pl.gz.as c
# gunzip dowkd.pl.gz
# Perl dowkd.pl host localhost

The result would have to be 0. If instead we use Debian or Ubuntu we must supply to a upgrade of openssl that it will carry out “fix” (the repair) of the software vulnerable. In this wiki there is a complete and detailed trattazione of the problem and its solutions.

Source nixCraft.