Responsive Ad Slot

Tech

PHOTOGRAPHY

Games

Tech

Showing posts with label Linux. Show all posts
Showing posts with label Linux. Show all posts

Black Hat Asia Conference 2015

Posted on Tuesday, 17 February 2015 with No comments


Black Hat Briefings, which have taken place since the late 90s, are the most important events of the year for security professionals. Sponsored by the likes of Microsoft and Cisco, they regularly feature prescient and grounded security concerns to IT professionals in ways that enable them to improve security within their domain. This year’s Black Hat Asia Conference will be no exception, with several radically important security concerns being brought to the surface.

It’s Only Impossible if You Know It’s Impossible


black hatterThe first and most buzzworthy talk to be given at the 2015 Black Hat Asia Conference (March 24 – 27) has to be the advent of cryptocurrency block chain malware. INTERPOL researcher Christian Karam believes that the transparency of the block chain – one of its most advertised and applauded features – may, in fact, be its Achilles’ heel.

Karam has been investigating the possibility that the block chains of Bitcoin and other cryptocurrencies could be used to embed malware on thousands of computers in a perpetual manner. He will be presenting a proof-of-concept to this effect.

    Transactions and data are encrypted throughout the blockchain networks using different versions of public/private key encryption. Could malware survive eternally inside crypto-transactions? A proof of concept will be explained highlighting the concerns revolving around the “abuse and bloating” of the blockchain while comparing it to previous malware hosting and deployment models.

How to Keep the Cloud from Leaking without Shutting Off the Sun


Recently, everything’s gone “cloud” in the name of convenience. Organization-level networks are becoming a thing of the past as cloud-based alternatives become cheaper and easier to maintain. They also create centralized points of failure. Never fear, because presenters Nir Valtman and Moshe Ferber say they now have an app for that. Called “Cloudefigo,” they promise to demonstrate on the fly with Amazon Web Services how they can patch and audit cloud instances without losing data or, apparently, much (if any) downtime at all.

Live security updates could revolutionize server administration and eventually make outages due to upgrading a thing of the past. It goes in line with recent news that the Linux kernel can now be patched without a system reboot – something unimaginable for the longest unless one was using something special like Ksplice.

You CAN Hack a Car (but You’d Heard That Already)


Former Tesla software engineer Eric Evenchick will be unveiling an open source tool that makes communication with the Controller Area Network (CAN) – the protocol used mainly in automobiles – relatively easy. He will demonstrate exploits of CAN systems and the advertisement makes the following promise:
    By the end of the talk, attendees will not only gain an understanding of automotive systems, but will also have the tools to attack them.

CAN has long been a vulnerable system, but it is only in recent years that increased wireless capabilities have come to cars.

This presentation will hopefully serve as a good reminder to the automotive industry that networking is not like auxiliary audio or air conditioning. That is, if they’re going to be implementing all these new features, they’d better put the same care they put into the variable speed windshield wiper into it or they’re bound to have serious breach after serious breach.

Hacked will keep our readers abreast of exciting developments at this and other Black Hat events as they become available.
READ MORE

Red Hat launches Red Hat Enterprise Virtualization 3.5

Posted on Sunday, 15 February 2015 with No comments


Sydney, Australia - Red Hat, Inc. (NYSE: RHT), the world's leading provider of open source solutions, announced the general availability of Red Hat Enterprise Virtualization 3.5, enabling organisations to deploy an IT infrastructure that services traditional virtualisation workloads while creating an enterprise-grade foundation for cloud infrastructure. Red Hat Enterprise Virtualization 3.5 delivers standardised services for mission critical workloads, and offers IT organisations greater visibility into provisioning, configuring and monitoring of their virtualisation infrastructure, all based on open standards.

Red Hat is a recognised leader in the scale and performance of virtual machine workloads, and Red Hat Enterprise Virtualization 3.5 extends this leadership with support for four terabytes (4 TB) of memory per host, 4 TB of vRAM, and 160 vCPUs per virtual machine.

Notable new features in Red Hat Enterprise Virtualization 3.5 include:


• Lifecycle management and provisioning of bare-metal hosts via integration with Red Hat Satellite.
• Compute resource optimisation through advanced real-time analytics with oVirt Optimizer integration. This enables users to identify the balance of resource allocation that best meets their needs while provisioning new virtual machines.
• Workload performance and scalability provided through non-uniform memory access (NUMA) support, which is extended to Host NUMA, Guest Pinning and Virtual NUMA. This enables customers to deploy highly scalable workloads with improved performance and minimises resource overload related to physical memory access times.
• Enhanced disaster recovery via improved storage domain handling, providing support for migrating storage domains between different datacenters supported by Red Hat Enterprise Virtualization, enabling partner technologies to deliver site recovery capabilities.

Red Hat Enterprise Virtualization also serves as an ideal foundation both traditional virtualisation and highly flexible cloud-enabled workloads built on OpenStack. Red Hat Enterprise Virtualization 3.5 includes features that enhance this foundation for cloud-enabled workloads:

• Integration and shared common services with OpenStack Image Service (Glance) and OpenStack Networking (Neutron), available as a Tech Preview, enabling administrators to break down silos and to deploy resources once across the infrastructure.
• Instance types, unifying the process of provisioning virtual machines for both virtual and cloud-enabled workloads.

Red Hat Enterprise Virtualization Availability

• As a standalone offering - Red Hat Enterprise Virtualization 3.5 - including Hypervisor and Manager for virtualised enterprise workloads for supported guest operating systems.
• As an integrated offering called Red Hat Enterprise Linux with Smart Virtualization, aimed at customers looking to maximise the benefits of their virtualised infrastructure with Linux workloads. This offering combines the innovation, performance, scalability, reliability and security features of Red Hat Enterprise Linux with the advanced virtualisation management capabilities of Red Hat Enterprise Virtualization.
• Via Red Hat Cloud Infrastructure, a comprehensive solution that supports organisations on their journey from traditional datacenter virtualisation to OpenStack-powered clouds. Red Hat Cloud Infrastructure is a single subscription offering that includes Red Hat CloudForms, Red Hat Satellite, Red Hat Enterprise Linux OpenStack Platform, and Red Hat Enterprise Virtualization.

Supporting Quotes
Jim Totton, vice president and general manager, Platforms Business Unit, Red Hat              
“As more enterprises look to reap the benefits of bimodal IT in their virtualised and cloud-based environments, Red Hat Enterprise Virtualization offers a key component of an infrastructure ready to accommodate traditional enterprise virtualisation while building a foundation for cloud enabled workloads.”

Steven Bellistri, manager, IT, LDI Integrated Pharmacy Services

"The healthcare industry is undergoing significant changes that require us to rapidly adopt to new business and regulatory compliance requirements. Because Red Hat Enterprise Virtualization is built on open standards that enable flexibility and fast innovation, we can more quickly adopt our IT infrastructure and deploy services with stability and speed.”

Lucas Harms, senior infrastructure engineer, Speed Commerce, Inc.
"With Red Hat Enterprise Virtualization, we are able to deploy stable and efficient offerings that handle our enterprise compute needs while still being able to integrate into a larger hybrid cloud solution through the use of common open source virtualisation technologies."

Doug Matthews, vice president, Information Availability, Symantec
“Symantec’s continued collaboration with Red Hat provides customers with seamless, global availability for their bimodal IT environments, whether it is quality of service for critical applications on physical Red Hat Enterprise Linux platforms or more future-looking Red Hat Enterprise Virtualization based OpenStack environments.”

Additional Resources

• Learn more about Red Hat Enterprise Virtualization 3.5
• Learn more about Red Hat Enterprise Linux with Smart Virtualization

Connect with Red Hat

• Learn more about Red Hat
• Get more news in the Red Hat newsroom
• Read the Red Hat blog
• Follow Red Hat on Twitter
• Join Red Hat on Facebook
• Watch Red Hat videos on YouTube
• Join Red Hat on Google+

 

About Red Hat, Inc.

Red Hat is the world's leading provider of open source software solutions, using a community-powered approach to reliable and high-performing cloud, Linux, middleware, storage and virtualization technologies. Red Hat also offers award-winning support, training, and consulting services. As the connective hub in a global network of enterprises, partners, and open source communities, Red Hat helps create relevant, innovative technologies that liberate resources for growth and prepare customers for the future of IT. Learn more at http://www.redhat.com.

 

Forward-Looking Statements

Certain statements contained in this press release may constitute "forward-looking statements" within the meaning of the Private Securities Litigation Reform Act of 1995. Forward-looking statements provide current expectations of future events based on certain assumptions and include any statement that does not directly relate to any historical or current fact. Actual results may differ materially from those indicated by such forward-looking statements as a result of various important factors, including: risks related to delays or reductions in information technology spending; the effects of industry consolidation; the ability of the Company to compete effectively; the integration of acquisitions and the ability to market successfully acquired technologies and products; uncertainty and adverse results in litigation and related settlements; the inability to adequately protect Company intellectual property and the potential for infringement or breach of license claims of or relating to third party intellectual property; the ability to deliver and stimulate demand for new products and technological innovations on a timely basis; risks related to data and information security vulnerabilities; ineffective management of, and control over, the Company's growth and international operations; fluctuations in exchange rates; and changes in and a dependence on key personnel, as well as other factors contained in our most recent Quarterly Report on Form 10-Q (copies of which may be accessed through the Securities and Exchange Commission's website at http://www.sec.gov), including those found therein under the captions "Risk Factors" and "Management's Discussion and Analysis of Financial Condition and Results of Operations". In addition to these factors, actual future performance, outcomes, and results may differ materially because of more general factors including (without limitation) general industry and market conditions and growth rates, economic and political conditions, governmental and public policy changes and the impact of natural disasters such as earthquakes and floods. The forward-looking statements included in this press release represent the Company's views as of the date of this press release and these views could change. However, while the Company may elect to update these forward-looking statements at some point in the future, the Company specifically disclaims any obligation to do so. These forward-looking statements should not be relied upon as representing the Company's views as of any date subsequent to the date of this press release.
Red Hat and Red Hat Enterprise Linux are trademarks of Red Hat, Inc., registered in the U.S. and other countries. Linux® is the registered trademark of Linus Torvalds in the U.S. and other countries. The OpenStack mark is either a registered trademark/service mark or trademark/service mark of the OpenStack Foundation, in the United States and other countries, and is used with the OpenStack Foundation's permission. We are not affiliated with, endorsed or sponsored by the OpenStack Foundation, or the OpenStack community.

READ MORE

Linux system backdoor turns boxes into DDoS

Posted on Saturday, 14 February 2015 with No comments

Xnote.1 - the Swiss Army knife of malware

 



To spread the new Linux backdoor, dubbed Linux.BackDoor.Xnote.1, criminals mount a brute force attack to establish an SSH connection with a target machine. Doctor Web security researchers believe that the Chinese hacker group ChinaZ may be behind this backdoor.

Once Linux.BackDoor.Xnote.1 gets in, it checks to see whether its copy is already running in the infected system. If it is, the backdoor exits. The malware will only be installed in a system if it has been launched with superuser (root) privileges. During installation, the malware creates a copy of itself in the /bin/ directory in the form of a file called iptable6. It then deletes the original file that was used to launch it. Linux.BackDoor.Xnote.1 also searches the /etc/init.d/ directory for a script that starts with the line "#!/bin/bash" and adds another line to it so that the backdoor will be launched automatically.

The program uses the following routine to exchange data with the intruders' control server. To obtain configuration data, the backdoor looks for a special string in its body—the string points to the beginning of the encrypted configuration block, then decrypts it and starts sending queries to control servers on the list until it finds a responding server or until the list ends. Both the backdoor and the server use the library zlib to compress the packets they exchange.

First, Linux.BackDoor.Xnote.1 sends information about the infected system to the server. It then goes into standby mode and awaits further instructions. If the command involves carrying out some task, the backdoor creates a separate process that establishes its own connection to the server through which it gets all the necessary configuration data and sends the results of the executed task.

Thus, when commanded to do so, Linux.BackDoor.Xnote.1 can assign a unique ID to an infected machine, start a DDoS attack on a remote host with a specific address (it can mount SYN Flood, UDP Flood, HTTP Flood and NTP Amplification attacks), stop an attack, update its executable, write data to a file, or remove itself. The backdoor can also perform a number of actions with files. Having received the appropriate command, Linux.BackDoor.Xnote.1 sends information about the file system of the infected computer (the total number of data blocks in the file system and the number of free blocks) to the server and stands by for other directives which can include:
  • List files and directories inside the specified directory.
  • Send directory size data to the server.
  • Create a file in which received data can be stored.
  • Accept a file.
  • Send a file to the command and control (C&C) server.
  • Delete a file.
  • Delete a directory.
  • Signal the server that it is ready to accept a file.
  • Create a directory.
  • Rename a file.
  • Run a file.
In addition, the backdoor can run a shell with the specified environment variables and grant the C&C server access to the shell, start a SOCKS proxy on an infected computer, or start its own implementation of the portmap server.
READ MORE

Get Your Data Back with Linux-Based Data Recovery Tools

Posted on with No comments
Data is the crucial bit in our personal and professional existence. Without data we would be lost in a vast expanse of nothingness. Spreadsheets, email, documents, contacts, databases, files, folders … the list goes on and on. In a perfect world, every byte of local storage would be backed up to an external hard drive or cloud storage service.

We don’t always live in a perfect world.

Sometimes data has to be recovered. When that tragedy strikes, it’s good to know you have the tools on hand to get the job done. Thankfully, Linux is no stranger to data recovery. In fact, there are a number of solid tools you can use to get back lost data. I want to introduce you to a few tools that do a great job of recovering data.

Of course, as with any instance of recovering lost data ─ nothing is perfect. You can try any of the various tools available only to find the data simply not recoverable. That is the nature of the digital age. To that end, always make sure you have a solid, recent backup available in the event your system goes down hard.
SystemRescueCD

Let’s first start with tools to help you recover data from a downed machine (say a machine with file system or partition issues). These tend to be the easiest to work with as they are all-inclusive tools. My favorite of these tools is SystemRescueCD. This particular rescue CD supports most of the known partition formats and includes all the tools you need to recover data (including sfdisk, Gparted, TestDisk, PhotoRec, FSArchiver, and much more) and includes plenty of tools to work with.

Like most rescue disks, SystemRescueCD works by booting your system from either the CD or USB drive and then uses the tools to work with your file system. Unlike a lot of other rescue tools of this nature, SystemRescueCD offers a full-blown graphical environment to aid you in the task of recovering data 


If you are rescuing data from one machine to another, you will need to attach an external hard drive to the system in order to move the rescued data (or you can use the built-in Samba support and copy data to a networked location). If the idea is to recover or repair a partition table, I strongly suggest copying sensitive data over over anyway ─ on the chance the partition table or file system is further damaged.

There are other rescue systems available that are similar in both intent and style as SystemRescueCD. Each has its pros and cons but, in the end, will get the job done. Some of my favorite Linux data/system recovery distributions include:

  •     Trinity Rescue Kit
  •     Knoppix
  •     Ultimate Boot CD.

Individual rescue tools


Once you get beyond a full-blown distribution, you start looking at purpose-driven tools geared toward recovering data. Linux has just about any tool you need for this task. Let’s take a look at some of them.

Ddrescue

If you’re looking for the command line tool that will copy data from one file or block device to another, it’s Ddrescue that you need. There are a few things you should know about using the Ddrescue:
  •     Never use this tool on a read/write mounted drive or partition.
  •     Do not try to repair a file system with I/O errors.
  •     Destination will be overwritten ─ so make sure destination is free of important data.

This tool is great for recovering data from a failing drive to an external source. You would first need to install the tool on your working system, attach both the failing drive and a destination drive, via USB, and use the tool to extract the necessary data.

Installing the tool on an Ubuntu system can be done with a single command:
sudo apt-get install gddrescue

The command structure of Ddrescue is:
ddrescue [options] infile outfile [logfile]

Let’s use Ddrescue to copy a partition from drive /dev/sdg to drive /dev/sdb. The command (run on a system that works with sudo) would look like:
sudo ddrescue /dev/sdg /dev/sdb

The above command would copy everything from the failing source to the healthy target. Data recovered!

Testdisk

This particular data recovery tool doesn’t actually try to copy data. Instead it attempts to correct partition-level issues that might be preventing you from accessing or recovering your data. Testdisk can:
  •     Recover lost partitions
  •     Make disks bootable again
  •     Fix a partition table
  •     Restore the master boot record
  •     Restore boot sectors
  •     Restore filesystem tables
  •     Undelete files from NTFS, FAT, exFAT, and ext2 filesystems
  •     Copy files from deleted NTFS, FAT, exFAT, and ext2/3/4 filesystems.

Testdisk is an ncurses tool that runs within a terminal


To install Testdisk on an Ubuntu system, issue the command:
sudo apt-get install testdisk

Run the tool with sudo testdisk and walk through the easy-to-use wizard for working with your externally attached drive.

Photorec

If you’re looking to recover lost files, photos, videos, etc. Photorec is what you want. This tool is part of Testdisk, so once you’ve installed Testdisk, Photorec is ready to serve. This particular tool completely ignores the file system and looks directly at the underlying data. This means, if your file system is damaged, there’s a chance the data can still be recovered.

To start Photorec, issue the command:
sudo photorec

The interface for Photorec is similar to that of Testdisk. As Photorec works, it will display, in real time, what types of files it has recovered


You do want to make sure the destination partition has enough space to contain the rescued data (you can copy the data to internal storage or external storage).

If you are looking for tools to help you recover data on a Linux system, there are plenty to be had. This post offers you a look into what is available for admins to use ─ from full-blown disk recovery suites to individual tools. There are plenty of other tools ready to aid you in your quest to recover data.

For more information on such tools, check out the Linux.com System Management Forum, where you can interact with your peers and learn even more about data recovery.
READ MORE

Latest

Blog Archive

Hit Me