Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×

Comment Re:Malicious Website? (Score 1) 147

1.0.5.48_1.1.79 is vulnerable. As I had one laying around, plugged it in and it would execute code when I shot it the url.

Updated to V1.0.7.2_1.1.93 also vulnerable.

http://router-address/cgi-bin/...'

Kills the httpd demon and doesn't allow remote execution (or web management) until rebooted, where router-adress is the netgear. That is work around enough.

Comment Re:Y'know... (Score 2) 599

" ...You hadn't exactly gone out of your way to call attention to them had you? I mean like actually telling anyone or anything.' But the plans were on display...' o n display? I eventually had to go down to the cellar to find them.' `That's the display department.' `With a torch.' `Ah, well the lights had probably gone.' `So had the stairs.' `But look you found the notice didn't you?' `Yes,' said Arthur, `yes I did. It was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying "Beware of The Leopard".' -- Douglas Adams.

It's about the same to turn off the ads. Or will be soon. You get what you pay for.

Submission + - U.S. Government: Sorry, We're Closed 2

theodp writes: CNN reports that the U.S. government shut down at 12:01 a.m. ET Tuesday after lawmakers in the House and the Senate could not agree on a spending bill to fund the government. Federal employees who are considered essential will continue working. But employees deemed non-essential — close to 800,000 — will be furloughed, and most of those are supposed to be out of their offices within four hours of the start of business Tuesday.

Comment I read the Faq for their project (Score 3, Informative) 37

I'd rather use Fedora 17.

From the FAQ:

It supports the Essex version and will support the next rev when released, but this part bothers me:

"What are the requirements for using the preview software?

A: The preview version of the Red Hat OpenStack software only works with Red Hat Enterprise Linux 6.3 or higher. You'll need a Red Hat Enterprise Linux subscription for each server you install with the Red Hat OpenStack software."

It maybe less work than with Fedora 17- but 17 includes OpenStack and has a how to get started (some bash-ing required).

http://fedoraproject.org/wiki/Getting_started_with_OpenStack_on_Fedora_17

Comment The fine article is wrong (Score 2, Informative) 260

"Each campus or office got a /48 address block, which meant that it was allotted 280 addresses. In turn, each building got a /56 block of those addresses (or about 272 addresses) and each VLAN (Virtual Local Area Network) received a /64 block, or about 264 addresses."

a /48 block is 65536 subnets for each campus. A /64 has 18,446,744,073,709,551,616 IP addresses.

The RFCs on this type of thing are RFC 6177 which replaced 3177 and RFC 5375. For a itworld/usenix article, fact checking is really low.

Submission + - American Traveler Dignity Act (govtrack.us)

agristin writes: The American Traveler Dignity Act may finally roll back some of the ridiculous "security measures" performed by the TSA at airports across the United States. In the introduction to the bill covers two large objections to the way the TSA handles screening- 1) if the elite, like congress, were to be subjected to these screenings the TSA would be rolling back these measures and 2) the security measures are more invasive and allow less personal liberty than travelling behind the now defunct iron curtain. The Transportation Security Administration rolls up under the Department of Homeland Security in the United States.

Comment Re:Future of Internet and firewalls (Score 1) 414

You should check out the Palo Alto Networks firewall. It does some interesting things, and came to that obvious conclusion a while ago.

And it deals with Port 80 and Port 443 really well.

My other favorite thing is applications- ever try to let ftp through a firewall (or stop skype?)- port hopping, neither a client nor a server, very interesting. Well the PAN stuff has that nailed down- you can't depend on port and protocol anymore, you need multiple ways to identify an app- and it has them.

Comment Re:Vaguely related questions... (Score 1) 284

DD on OSX is what I use.

      1. Download the desired .img or .iso file
      2. Open a Terminal (under Utilities)
      3. Run diskutil list to get the current list of devices
      4. Insert your flash media
      5. Run diskutil list again and determine the device node assigned to your flash media (e.g. /dev/disk2)
      6. Run diskutil unmountDisk /dev/diskN
      7. Execute sudo dd if=/path/to/downloaded.img of=/dev/diskN bs=1m
      8. Run diskutil eject /dev/diskN and remove your flash media when the command completes

Comment Re:general purpose != good (Score 3, Interesting) 98

UTM is a crock. It loads multiple single purpose apps on to a general purpose computing device and then tries to do it quickly.

The best thing in this field I've seen recently is Palo Alto Networks firewall (www.paloaltonetworks.com).

Knows the applications, even web apps. It can tell the difference between Gmail and gchat. Bittorent and wow torrent patching. Can do user based rules when integrated with AD. And can proxy SSL to look in the SSL stream if necessary. Malware blocking, url filtering via subscription. Because ports or protocols != applications and IP address != user anymore.

Comment Eat their own dog food (Score 2, Insightful) 84

Either they don't use McAfee secure ( http://www.mcafeesecure.com/us/ Probably the right website, who knows really ), or their own dog food is garbage.

Either way it is bad gaffe. XSS is pretty well known in security circles. And this mistake is a relatively simple one (output validation or output filtering? please. After you read the linked article, you'll be even more sad they didn't catch this.

Comment I hope not (Score 1) 469

I hope not. There are a few pieces that are critical in education that are very difficult to do with distance learning:

1- make relationships with students and teachers. Sometimes the relationships with other students or teachers are what makes the difference in life.

2- the moral component is very hard to teach with distance learning. I'd rather nuclear chemistry or even computer science be taught within a moral framework- because it is easy to use great knowledge for the wrong purpose

3- subtlety of expression- sometimes lost in distance learning- actually it is lost in large classroom sizes sometimes as well.

Comment Warning 10 click article (Score 1) 1

It was actually a pretty good article. I'd disagree with the order, but those would all be on my list.

The summary is:

        * 1. Diablo II
        * 2. MechWarrior 4: Mercenaries
        * 3. People's General
        * 4. StarCraft
        * 5. Fallout
        * 6. Baldur's Gate (and BG2)
        * 7. WarCraft III
        * 8. Battlefield 1942
        * 9. Freelancer
        * 10. Allegiance

Comment Re:Kinda reminds me of a Chumby (Score 4, Informative) 85

Read a little further along the article for your answer;

Price? it can be built for less than $250, including packaging. Add in fixed costs and other stuff you have to deal with (like returns), and you can sell it for $300 and probably not go out of business.

I'd like to see that business plan. I suspect if you build it at 250$ the least you could sell it for and not go out of business is 500$. That might be normal.

83% cost of manufacture? At a price point of a few hundred dollars, it is almost impossible to break even, much less turn a profit.

You could survive 80%+ cost of manufacture if you had a very low price point (1$ or less), had no support or return costs, and very low advertising and could sell millions or billions of them. Even then you would want to get down to 50% or less.

Slashdot Top Deals

Marriage is the triumph of imagination over intelligence. Second marriage is the triumph of hope over experience.

Working...