Owner: Digital Cartel URL:http://www.digitalcartel.org Join Date: Thu, 19 Apr 2007 02:32:47 -0500 Rating:0 Site Description: Digital Cartel - Networking, Security, Insecurity, & Coding Blog Site statistics:Click here
Linux printing with DELL 3100 CN 2007-04-19 08:32:00 The goal I set out is to be able to print over the network from my Debian Etch laptop to a Dell 3100CN printer. The first part was just figuring out how to set the printer to have a static IP address. So I hit up the dell support site
for the manual. There is a web interface, but thats for noobs. I myself am a panel hacker. So below is how you would setup your network connectivity. Pay Read more:Linux
Linux and open file descriptors 2007-04-19 08:20:00 Increasing open file descriptors
I remember back in the day coming across file descriptors when running an ircd. In order to have a big bad ass ircd you would often need to increase the number of open file descriptors. By increasing this value, you can really push your server to the limit and whatever software you run on it.
A small number of open file descriptors (sockets) can significantly Read more:Linux
Meet Linux 2007-04-14 20:36:00 Novell's funny answer clips to those Mac versus Windows PC television commercials. My favorite one is clip 3. :)
Meet Linux
.
Human Computation, Captcha, and ESP 2007-03-14 22:46:00 I was trying to do some work when I stumbled upon this link. Needless to say, my work got put off until the video was over. This is a really kickass presentation on Human Computation
. The presentation is by Luis von Ahn who is an assistant Professor at Carnegie Mellon University. Pre-interview he looks nervous and bit squirrely. Needless to say, he did an awesome job. He starts off Read more:Captcha
Wordpress server compromised 2007-03-10 00:15:00 Long story short: If you downloaded WordPress 2.1.1 within the past 3-4 days, your files may include a security exploit that was added by a cracker, and you should upgrade all of your files to 2.1.2 immediately.
Long explanation...
No Good. Circle with da slash. I have a few wordpress installs. Even though they are not a few days old... I upgraded anyway. I suggest everyone running wordpress Read more:Wordpress
, server
, compromised
TLD DNS DDoS fact sheet released 2007-03-09 19:34:00 Back in February, there was a rather large DDoS attack on the Internet's root DNS servers (TLD). There really wasn't many details on the attack, except for rumors that it originated somewhere in the Asia-Pacific region. Well now we have something to sink our teeth into. ICANN has released an official fact sheet
with more information on the attack. There are still some unanswered questions,
The Buzz about the OpenPGP Bug 2007-03-09 01:48:00 When encoding trumps encryption (or: the latest GnuPG issue)
Published: 2007-03-06,
Last Updated: 2007-03-07 12:39:48 UTC
by Arrigo Triulzi (Version: 1)
The latest GnuPG security advisory is, in the specific case of GnuPG, more of a "Human-Computer Interaction" than a security hole proper. The flaw is not in the encryption but in the way in which OpenPGP, a standard way of transmitting
Check Point SecurePlatform Hardware Compatibility 2007-03-07 18:55:00 Check Point's Secureplatform(SPLAT) and hardware do not always play nicely together. In the past, I have experienced many issues with SPLAT not supporting newer system hardware. I have bumped my head on the unsupported network interface card many times. The following link is their official hardware compatibility page. However, I just recently discovered they have released a Secureplatform Read more:Check
, Hardware
New Checkpoint UTM appliance is on Crossbeam! w00t! 2007-02-24 08:27:00 Finally, Checkpoint
has come out with some good news! Their new small to medium business appliance is on crossbeam hardware. The appliance follows the all-in-one trend most security companies are following. The list of features include: Firewall, Web Application Firewall(isn't this included in firewall? lol), VoIP security, SSL VPN connectivity, anti-spyware, URL filtering, and IM/P2P blocking
Packet Sniffing 101 with Pcap 2007-02-20 08:21:00 This a good article on packet sniffing and has some example uses of Net::Pcap in Perl.
Reliable Packet
Dissection and Sniffing
Fingerprint authentication on latest Toshiba Smart Phones 2007-02-17 05:43:00 Toshiba isn't really known for bleeding edge cell phones. However, they have recently made a major leap towards a more secure cell phone. I think this is cool and I expect more cell phones to follow. Supposedly, this is the year for mobile device security. There has been mobile device encryption out for some time from companies like PointSec. Also, two-factor authentication has been around Read more:Toshiba
, Smart
, Phones
People are still using telnet? 2007-02-14 21:17:00 Apparently, there are people out there still using telnet. If that's not bad enough, recently a nasty zero day vulnerability in the telnet daemon of Solaris 10 & 11 was discovered. Nowadays, almost everything has SSH support so there is no excuse to be using telnet. I really don't think telnet is a good idea even behind your perimeter line of defense. In my opinion, if something needs a
Apache Mod Rewrite Cheat Sheet 2007-05-08 02:28:00 Today I was struggling with mod rewrite and as usual feeling lazy. I really didn't want to dig through my apache books/ebooks. I came across this cheat sheet and it was exactly what I needed. Read more:Apache
, Rewrite
, Cheat
Apache Mod Rewrite Cheat Sheet 2007-05-08 02:28:00 Today I was struggling with mod rewrite and as usual feeling lazy. I really didn't want to dig through my apache books/ebooks. I came across this cheat sheet and it was exactly what I needed. Also, see the Apache
mod_rewrite reference documentation and URL Rewriting Guide. Maybe if I'm not too lazy sometime next week I will post some examples of how I have used it. :) Read more:Rewrite
, Cheat
Linux printing with DELL 3100 CN 2007-04-19 08:32:00 The goal I set out is to be able to print over the network from my Debian Etch laptop to a Dell 3100CN printer. The first part was just figuring out how to set the printer to have a static IP address. So I hit up the dell support site
for the manual. There is a web interface, but thats for noobs. I myself am a panel hacker. So below is how you would setup your network connectivity. Pay Read more:Linux
Linux and open file descriptors 2007-04-19 08:20:00 Increasing open file descriptors
I remember back in the day coming across file descriptors when running an ircd. In order to have a big bad ass ircd you would often need to increase the number of open file descriptors. By increasing this value, you can really push your server to the limit and whatever software you run on it.
A small number of open file descriptors (sockets) can significantly Read more:Linux
Meet Linux 2007-04-14 20:36:00 Novell's funny answer clips to those Mac versus Windows PC television commercials. My favorite one is clip 3. :)
Meet Linux
.
Human Computation, Captcha, and ESP 2007-03-14 22:46:00 I was trying to do some work when I stumbled upon this link. Needless to say, my work got put off until the video was over. This is a really kickass presentation on Human Computation
. The presentation is by Luis von Ahn who is an assistant Professor at Carnegie Mellon University. Pre-interview he looks nervous and bit squirrely. Needless to say, he did an awesome job. He starts off Read more:Captcha
Wordpress server compromised 2007-03-10 00:15:00 Long story short: If you downloaded WordPress 2.1.1 within the past 3-4 days, your files may include a security exploit that was added by a cracker, and you should upgrade all of your files to 2.1.2 immediately.
Long explanation...
No Good. Circle with da slash. I have a few wordpress installs. Even though they are not a few days old... I upgraded anyway. I suggest everyone running wordpress Read more:Wordpress
, server
, compromised
TLD DNS DDoS fact sheet released 2007-03-09 19:34:00 Back in February, there was a rather large DDoS attack on the Internet's root DNS servers (TLD). There really wasn't many details on the attack, except for rumors that it originated somewhere in the Asia-Pacific region. Well now we have something to sink our teeth into. ICANN has released an official fact sheet
with more information on the attack. There are still some unanswered questions,
The Buzz about the OpenPGP Bug 2007-03-09 01:48:00 When encoding trumps encryption (or: the latest GnuPG issue)
Published: 2007-03-06,
Last Updated: 2007-03-07 12:39:48 UTC
by Arrigo Triulzi (Version: 1)
The latest GnuPG security advisory is, in the specific case of GnuPG, more of a "Human-Computer Interaction" than a security hole proper. The flaw is not in the encryption but in the way in which OpenPGP, a standard way of transmitting
Check Point SecurePlatform Hardware Compatibility 2007-03-07 18:55:00 Check Point's Secureplatform(SPLAT) and hardware do not always play nicely together. In the past, I have experienced many issues with SPLAT not supporting newer system hardware. I have bumped my head on the unsupported network interface card many times. The following link is their official hardware compatibility page. However, I just recently discovered they have released a Secureplatform Read more:Check
, Hardware
New Checkpoint UTM appliance is on Crossbeam! w00t! 2007-02-24 08:27:00 Finally, Checkpoint
has come out with some good news! Their new small to medium business appliance is on crossbeam hardware. The appliance follows the all-in-one trend most security companies are following. The list of features include: Firewall, Web Application Firewall(isn't this included in firewall? lol), VoIP security, SSL VPN connectivity, anti-spyware, URL filtering, and IM/P2P blocking
Packet Sniffing 101 with Pcap 2007-02-20 08:21:00 This a good article on packet sniffing and has some example uses of Net::Pcap in Perl.
Reliable Packet
Dissection and Sniffing
Fingerprint authentication on latest Toshiba Smart Phones 2007-02-17 05:43:00 Toshiba isn't really known for bleeding edge cell phones. However, they have recently made a major leap towards a more secure cell phone. I think this is cool and I expect more cell phones to follow. Supposedly, this is the year for mobile device security. There has been mobile device encryption out for some time from companies like PointSec. Also, two-factor authentication has been around Read more:Toshiba
, Smart
, Phones
People are still using telnet? 2007-02-14 21:17:00 Apparently, there are people out there still using telnet. If that's not bad enough, recently a nasty zero day vulnerability in the telnet daemon of Solaris 10 & 11 was discovered. Nowadays, almost everything has SSH support so there is no excuse to be using telnet. I really don't think telnet is a good idea even behind your perimeter line of defense. In my opinion, if something needs a
Blogger with Your Own Domain 2007-05-22 00:12:00 The goal I set out for is simple. I own the blog digitalcartel.blogspot.com and I have a few posts, but I wanted it on my own domain. I didn't want to migrate the existing posts and content to another blog system. I browsed blogger's management interface a little and noticed that in the Settings section there is a publishing tab that has domain options. Once your there, google has a very helpful Read more:Blogger
Wordpress 2.1 Vulnerabilities 2007-05-24 01:48:00 Over the past few weeks there has been some vulnerabilities that have surfaced for Wordpress
2.1.* releases. The first link is sql injection attack in a weakness of xmlrpc.php. A prerequisite is that you must be a user on the target wordpress blog. The second link describes a blind sql injection attack on admin-ajax.php. The third link is the advisory of the admin-ajax.php exploit. The fourth