Forgot your password?
typodupeerror

Submission + - Pwn2Own 2017 Takes Aim at Linux (eweek.com)

darthcamaro writes: For the first time in its ten year history, the annual Pwn2Own hacking competition is taking direct aim at Linux. Pwn2Own in the past has typically focused mostly on web browsers, running on Windows and macOS. There is a $15,000 reward for security researchers that are able to get a local user kernel exploit on Ubuntu 16.10. The bigger prize though is a massive $200,000 award for exploiting Apache Web Server running on Ubuntu.
Security

"Very Severe Hole" In Vista UAC Design 813

Cuts and bruises writes "Hacker Joanna Rutkowska has flagged a "very severe hole" in the design of Windows Vista's User Account Controls (UAC) feature. The issue is that Vista automatically assumes that all setup programs (application installers) should be run with administrator privileges — and gives the user no option to let them run without elevated privileges. This means that a freeware Tetris installer would be allowed to load kernel drivers. Microsoft's Mark Russinovich acknowledges the risk factor but says it was a 'design choice' to balance security with ease of use."
Microsoft

Microsoft Slugs Mac Users With Vista Tax 661

An anonymous reader writes "Mac users wanting to run Vista on their Macintosh, alongside Mac OS X programs, will have to buy an expensive version of Vista if they want to legally install it on their systems. The end-user license agreement for the cheaper versions of Vista (Home Basic and Home Premium) explicitly forbids the use of those versions on virtual machines (i.e., Macs pretending to be PCs)." Update: 02/08 17:50 GMT by KD : A number of readers have pointed out that the Vista EULA does not forbid installing it via Apple's Bootcamp; that is, the "tax" only applies to running Vista under virtualization.
Security

MySpace and GoDaddy Shut Down Security Site 344

Several readers wrote in with a CNET report that raises novel free-speech questions. MySpace asked GoDaddy to pull the plug on Seclists.org, a site run by Fyodor Vaskovich, the father of nmap. The site hosts a quarter million pages of mailing-list archives and the like. MySpace did not obtain a court order or, apparently, compose a DMCA takedown notice: it simply asked GoDaddy to remove a site that happened to archive a list of thousands of MySpace usernames and passwords, and GoDaddy complied. Fyodor says the takedown happened without prior notice. The site was unavailable for about seven hours until he found out what was happening and removed the offending posting. The CNET article concludes: "When asked if GoDaddy would remove the registration for a news site like CNET News.com, if a reader posted illegal information in a discussion forum and editors could not be immediately reached over a holiday, Jones replied: 'I don't know... It's a case-by-case basis.'"

Slashdot Top Deals

Time to take stock. Go home with some office supplies.

Working...