Announcing: Slashdot Deals - Explore geek apps, games, gadgets and more. (what is this?)

Thank you!

We are sorry to see you leave - Beta is different and we value the time you took to try it out. Before you decide to go, please take a look at some value-adds for Beta and learn more about it. Thank you for reading Slashdot, and for making the site better!



Grinch Vulnerability Could Put a Hole In Your Linux Stocking

alanw Over-hyped. (118 comments)

From the oss-sec mailing list:

This is not a vulnerability, this is expected behaviour.


This paragraph suggests so many things which are simply wrong, confused,
or irrelevant that i don't know what to make of the rest of the article.

  * modern debian GNU/Linux systems do not have a wheel group at all. No
particular versions or flavors of "Linux system"

  * on systems where members of group wheel really do have unrestricted
access to the su command, having wheel in the first place *is* the
vulnerability -- it is a misconfiguration to expect an account to be
non-privileged if it is a member of wheel.

  * the last sentence appears to be about setuid/setgid binaries, but
makes no mention that the overwhelming majority of binaries are not

Later on, the post suggests that wheel group membership is related to
sudo privileges.

It also seems to assume that polkit always permits access for members of
group wheel. I can find no such configuration on a modern debian system.

I don't think there's anything significant in this ambiguous,
underspecified, and confused report.


Yeah I looked into this (the article/etc was completely confusing and
took some time to parse):

1) the article states they contacted red hat, we were unable to find
any inbound email or bugzilla entry pertaining to this issue, as always
if you have an issue you wish to report please contact secalert@...hat.com

2) this is expected behaviour, admin users can install software (do I
have to say this? really? yes. I was told I should say this).

3) don't run web apps as admin users (do I have to say this? really?
yes. I was told I should say this).

4) if you feel the need to run a web app as an admin user restrict what
they can do via SELinux, and don't let them install software (do I have
to say this? really? yes. I was told I should say this).

So TL;DR: it's not a security vulnerability, and it will NOT be getting
a CVE.

I can only assume this article/vuln is perhaps referring to something
like Cpanel and other control panels that people sometimes install
insecurely/improperly and then never update. Or something. Who knows.

about a month ago

Army To Launch Spy Blimp Over Maryland

alanw Orion Shall Rise (177 comments)

Will it have lasers? And will they call it Skyholm?

about a month and a half ago

Belkin Router Owners Suffering Massive Outages

alanw Re:Mod parent up. (191 comments)

Yeah! Who the fuck thought that was a good idea?

The same clueless marketroid that thought that inserting adverts into http traffic was a good idea?

> The marketing geniuses at Belkin, the consumer networking vendor, have dreamed up a new form of spam - ads served to your desktop, by way of its wireless router
> The router would grab a random HTTP connection every eight hours and redirect it to Belkin’s (push) advertised web page.

about 4 months ago

One-a-Day-Compiles: Good Enough For Government Work In 1983

alanw When I was a lad (230 comments)

School, circa 1974. Sending off your sheets and hoping that the keypunch operators didn't get 0's and O's confused. O's were slashed, or perhaps it was the other way round. Getting your job back on music ruled paper the next week

University. There were teletypes that you could use to get access to the ICL mainframe, but for exams you had to use punched cards, and only got 3 goes to compile and run your program. There were always queues for the big punch machines, so if you just needed one card doing, you could use a hand punch.

There's a good page with a photo of one here: http://www.staff.ncl.ac.uk/rog...

By my first job in 1979, we had VT52's and then VT100's, as well as a LA120 for the console.

about 9 months ago

Telescope Designer and Astronomer John Dobson, 1915-2014

alanw Brief Encounter (57 comments)

I once spent an interesting weekend in his company. He'd been born in Beijing, a walled city, and we took him via Chester on our way to North Wales. It was the first time he'd been in a walled city since his childhood. Walking near Llanberis, he found a Yew tree and enjoyed eating the berries. Still my photo of him on the Wikipedia page. Amazing guy, I hope his enthusiasm and inspiration lives on as his legacy.

1 year,12 days

Chang'e-3 Lunar Rover Landing Slated For 13:40 UTC Saturday

alanw The Rabbit has Landed (90 comments)


about a year ago

Chang'e-3 Lunar Rover Landing Slated For 13:40 UTC Saturday

alanw Install what? (90 comments)

To watch the live feed I'm being asked to install CNTVLive2 plugi

http:/// player . cntv . cn /flashplayer/config/plugins/npCNTVLive2_Linux_64.xpi

I think not.

There seems to be a custom compression algorithm used for

mplayer/xine/vlc don't like it.

In Firefox and Chromium it shows a loading page but stops at 80-something percent.

about a year ago

Online Retailers Cruising Tor To Hunt For Fraudsters

alanw IPv6 tunnels (188 comments)

I've been getting up to speed on IPv6 and have a tunnel from he.net (tunnelbroker.net). It seems to pop out somewhere on the other side of the Atlantic, judging from geographically targeted advertising. Several big sites are already IPv6 enabled (Firefox plugin SixOrNot), e.g. Facebook, Google, Youtube.

about a year ago

Ask Slashdot: How To Diagnose Traffic Throttling and Work Around It?

alanw EFF's Switzerland Network Testing Tool (251 comments)

The OP mentions Sandvine: the EFF has a tool called Switzerland.

Is your ISP interfering with your BitTorrent connections? Cutting off your VOIP calls? Undermining the principles of network neutrality? In order to answer those questions, concerned Internet users need tools to test their Internet connections and gather evidence about ISP interference practices. After all, if it weren't for the testing efforts of Rob Topolski, the Associated Press, and EFF, Comcast would still be stone-walling about their now-infamous BitTorrent blocking efforts.

Developed by the Electronic Frontier Foundation, Switzerland is an open source software tool for testing the integrity of data communications over networks, ISPs and firewalls. It will spot IP packets which are forged or modified between clients, inform you, and give you copies of the modified packets.

Switzerland is designed to detect the modification or injection of packets of data traveling over IP networks, including those introduced by anti-P2P tools from Sandvine (widely believed to be used by Comcast to interfere with BitTorrent uploads) and AudibleMagic, advertising injection systems like FairEagle, censorship systems like the Great Firewall of China, and other systems that we don't know about yet.

about a year and a half ago

Crowd-Funding a Mission To Jupiter's Moons

alanw Re:Radiation makes Europa a bad target (86 comments)

sorry - slip of the cheap crappy touchpad - tried to mod informative, modded down instead. posting here will undo

about a year and a half ago

Same Programs + Different Computers = Different Weather Forecasts

alanw Re:Lorenz, the Butterfly Effect and Chaos Theory (240 comments)

another link: http://www.aps.org/publications/apsnews/200301/history.cfm

Instead of starting the whole run over, he started midway through, typing the numbers straight from the earlier printout to give the machine its initial conditions. Then he walked down the hall for a cup of coffee, and when he returned an hour later, he found an unexpected result. Instead of exactly duplicating the earlier run, the new printout showed the virtual weather diverging so rapidly from the previous pattern that, within just a few virtual "months", all resemblance between the two had disappeared.

about a year and a half ago

Sent To Jail Because of a Software Bug

alanw Another set of court cases (239 comments)

where a large financial institution insisted its systems were bug free and secure,
eventually to be proved wrong:
... at that time the computing department of one of the banks issuing ATM cards had "gone rogue", cracking PINs and taking money from customers' accounts with abandon ... more than 2,000 people who had suffered "phantom withdrawals" from their bank accounts

about a year and a half ago

Worldwide IPv6 Adoption: Where Do We Stand Today?

alanw Re:Still not working... (327 comments)

I run the Firefox plugin SixOrNot. Google - a green 6. Youtube and Facebook ditto. Slashdot, a red 4. There are major sites out there running IPv6.

I have a free tunnel from Hurricane Electric. The only issue is that Google thinks I'm in the USA, which can't be a bad thing.

Now that there are no more IPv4 addresses available in Europe, it's in the interests of the established players to suppress IPv6 and lock out disruptive new startups: e.g. ISP's or Co-Lo's.

about 2 years ago



alanw has no journal entries.

Slashdot Login

Need an Account?

Forgot your password?