Server Ransom Attacks Hit CouchDB, Hadoop, and ElasticSearch Servers

An anonymous reader writes: Two weeks after cybercriminal groups started to hijack and hold for ransom MongoDB servers, similar attacks are now taking place against CouchDB, Hadoop, and ElasticSearch servers. According to the latest tallies, the number of hijacked MongoDB servers is 34,000 (out of 69,000 available on Shodan), 4,600 ElasticSearch clusters (out of 33,000), 124 Hadoop datastores (out of 5,400), and 443 CouchDB databases (out of 4,600).

Furthermore, the group that has hijacked the most MongoDB and ElasticSearch servers, is also selling the scripts it used for the attacks.

Submission + - Ringing in 2017 With 90 Hacker Friendly Single Board Computers (

DeviceGuru writes: HackerBoards has just published its annual New Year's round-up of Linux- and Android-friendly single board computers. This time around, there are 90 boards in the list, all of which are briefly profiled with links to their sources. There's also a big Google Docs spreadsheet that compares the key specs of all 90 boards, which range in price from $5 to $199 for their lowest cost models. "Community backed, open spec single board computers running Linux and Android... play a key role in developing the Internet of Things devices that will increasingly dominate our technology economy in the coming years," says the post.

Submission + - Freeciv WebGL 3D beta-version released (

Andreas(R) writes: A beta of the 3D WebGL version of Freeciv has been released today. Freeciv is the classic open source strategy game, included in most Linux distributions and first released in 1996 by three danish students. Now the developers are working on bringing the game to the modern era with 3D WebGL graphics. The game will work on any device with a browser with HTML5 and WebGL support, and 3GB of RAM. It is a volunteer community development project and anyone is welcome to contribute to the project. Have fun and remember to sleep!

schwit1 writes: For some time, nutritionists have suspected that artificial sweetener — often used as a substitute for sugar in coffee or added as an essential ingredient in diet sodas — does not help people lose weight. However, scientists have struggled to understand why this is the case.

Now, researchers from the Massachusetts General Hospital (MGH) have found a lead. "We found that aspartame blocks a gut enzyme called intestinal alkaline phosphatase (IAP)". IAP is produced in the small intestine. "We previously showed [this enzyme] can prevent obesity, diabetes and metabolic syndrome [a disease characterized by a combination of obesity, high blood pressure, a metabolic disorder and insulin resistence]. So, we think that aspartame might not work because, even as it is substituting for sugar, it blocks the beneficial aspects of IAP."

The researchers confirmed their suspicions via a variety of tests on mice. In one case, they fed IAP directly to mice, who were also on a high-fat diet. It turned out that the IAP could effectively prevent the emergence of the metabolic syndrome. It also helped relieve symptoms in animals that were already suffering from the obesity-related illness.

Submission + - Brain Cancer Patients Live Longer by Sending Electric Fields Through Their Heads (

the_newsbeagle writes: The big problem with treating glioblastoma, the most aggressive type of brain tumor, is that nothing really works. Surgeons cut out the tumor as soon as it's detected and blast left-behind cells with radiation and chemo, but it always comes back. Most glioblastoma patients live only one or two years after diagnosis.

The Optune system, which bathes the brain tumor in an AC electric field, is the first new treatment to come along that seems to extend some patients' lives. New data on survival rates from a major clinical trial showed that 43% of patients who used Optune were still alive at the 2-year mark, compared to 30% of patients on the standard treatment regimen. At the 4-year mark, the survival rates were 17% for Optune patients and 10% for the others.

The catch: Patients have to wear electrodes on their heads around the clock, and they're wired to a bulky generator/battery pack that's carried in a shoulder bag.

Submission + - Groundbreaking Paper on arXiv derives Gravity from Holographic Principle (

vikingpower writes: Dutch prodigy and Amsterdam University Professor Erik Verlinde published a paper on arXiv, yesterday November 7, titled "Emergent Gravity and the Dark Universe". In the paper, Verlinde derives gravity from the so-called Holographic Principle, which — simply put — states that gravity emerges from the interplay between and entropy re-arrangement of sub-atomic "strings" that live in a negatively curved space-time. At that level, "...spacetime and gravity are emergent from an underlying microscopic description in which they have no a priori meaning" . Most importantly, Verlinde's paper has as a consequence that Dark Matter, nemesis of many an astronomer, is nothing more than an illusion. Verlinde, who was awarded the Dutch national Spinoza science prize in the recent past, already completed the tour de force of deriving Newtonian gravity from the same principles in a 2010 paper, also on arXiv. We are probably looking at Nobel-prize material here, as Verlinde is acknowledged by his peers to "go one better than Einstein's General Theory of Relativity".

Submission + - A solution for DDOS packet flooding attacks (

dgallard writes: On October 21, 2016, a DDOS attack crippled access to major Web sites including Amazon and Netflix.

PEIP (Path Enhanced IP) extends the IP protocol to enable determining the router path of packets sent to a target host. Currently, there is no information to indicate which routers a packet traversed on its way to a destination (DDOS target) enabling use of forged source IP addresses to attack the target via packet flooding.

PEIP changes all that. Rather than attempting to prevent attack packets, instead, PEIP provides a way to rate-limit all packets based on their router path to a destination. In this way, DDOS attacks can be thwarted be simply only allowing them a limited amount of bandwith.

Submission + - Cells can choose burning fat over burning glucose when sick (

Beeftopia writes: A recent paper published in the journal Cell finds cells can preferentially choose burning either fat or glucose depending on the nature of the infection (viral or bacterial). This seems to have implications for obesity research, if cells can be chemically prodded into preferentially burning fat.

The saying, "Feed a cold, starve a fever" was somewhat borne out by this study. The article states, "mice with bacterial infections that were fed glucose died. But infected mice fed a version of glucose that they could not metabolise lived. Again, those results were nearly reversed in mice suffering from a viral infection... [In bacterial infection] burning fat protected infected mice... Most animals instinctively respond to infection by cutting back on food."

Submission + - Verizon workers can now be fired if they fix copper phone lines (

Swave An deBwoner writes: Verizon doesn't like providing access to their copper lines to competitors, as required by law. So ...

Verizon has told its field technicians in Pennsylvania that they can be fired if they try to fix broken copper phone lines. Instead, employees must try to replace copper lines with a device that connects to Verizon Wireless’s cell phone network.

Submission + - Amazon Bans Incentivized Reviews Tied To Free or Discounted Products (

An anonymous reader writes: Amazon is making a significant change to its Community Guidelines, announced today, which will eliminate any incentivized reviews, except for those that emerge from within its own Amazon Vine program. This program allows Amazon – not the seller or vendor – to identify trusted reviewers, and has a number of controls in place in order to keep bias out of the review process. Amazon has historically prohibited compensation for reviews – even going so far as to sue those businesses who pay for fake reviews, as well as the individuals who write them, in an effort to make its review and rating system fairer and more helpful to online shoppers. However, it has allowed businesses to offer products to customers in exchange for their “honest” review. The only condition was that those reviewers would have to disclose their affiliation with the business in question in the text of their review. Reviewers were generally offered the product for free or at a discounted price, in exchange for their review. Although, in theory, these reviewers could write their true opinion on the product – positive or negative – these incentivized reviews have tended to be overwhelmingly biased in favor of the product being rated. Amazon says that, going forward, the only incentivized reviews will be those from Amazon Vine. These don’t work the same way, however. For starters, Amazon selects who will be allowed to review products, and it does so mainly to boost the review count on new or pre-release products that haven’t yet generated enough sales to have a large number of organic reviews. Vine reviewers are invited to join the program only after having written a number of reviews voted as “helpful” by other customers, and tend to have expertise in a specific product category. In addition, vendors don’t have any contact with Vine reviewers, nor do they get to influence which reviewers will receive their products, which are submitted directly to Amazon for distribution. These changes will apply to all product categories other than books, as Amazon has always allowed advance copies of books to be distributed, the retailer notes.

Submission + - Multiple Linux Distributions Affected by Crippling Bug in systemd ( 1

An anonymous reader writes: System administrator Andrew Ayer has discovered a potentially critical bug in systemd which can bring a vulnerable Linux server to its knees with one command. "After running this command, PID 1 is hung in the pause system call. You can no longer start and stop daemons. inetd-style services no longer accept connections. You cannot cleanly reboot the system." According to the bug report, Debian, Ubuntu, and CentOS are among the distros susceptible to various levels of resource exhaustion. The bug, which has existed for more than two years, does not require root access to exploit.

Submission + - New formula massively reduces prime number memory requirements.

grcumb writes: Peruvian mathematician Harald Helfgott made his mark on the history of mathematics by solving Goldbach's Weak Conjecture, which every odd number greater than 5 can be expressed as the sum of three prime numbers. Now, according to Scientific American, he's found a better solution to the Sieve of Erasthones:

In order to determine with this sieve all primes between 1 and 100, for example, one has to write down the list of numbers in numerical order and start crossing them out in a certain order: first, the multiples of 2 (except the 2); then, the multiples of 3, except the 3; and so on, starting by the next number that had not been crossed out. The numbers that survive this procedure will be the primes. The method can be formulated as an algorithm.

But now, Helfgott has found a method to drastically reduce the amount of RAM required to run the algorithm:

Helfgott was able to modify the sieve of Eratosthenes to work with less physical memory space. In mathematical terms: instead of needing a space N, now it is enough to have the cube root of N.

So what will be the impact of this? Will we see cheaper, lower-power encryption devices? Or maybe quicker cracking times in brute force attacks?

Submission + - Vim 8.0 released! (

MrKaos writes: The venerable and essential vim has had it's first major release in 10 years. Lots of new and interesting features including, vim script improvements, JSON support, messages exchange with background processes, a test framework and a bunch of Windows DirectX compatibility improvements.
A package manager has been added to handle the ever-growing plug-in library, start-up changes and support for a lot of old platforms has been dropped.

Many Vimprovements!

Submission + - "HP pre-programmed failure date of non-HP ink cartridges in its printers" (

An anonymous reader writes: HP has programmed a failure date for non-HP / private label ink cartridges in its printers. Users around the world started to complain on the 13th of September this year that their printer rejected their non-HP cartridges. HP claimed that a firmware update was the culprit, but also printers who never received an update since they were unpacked rejected the cartridges starting at that particular date.

Submission + - Oldest-ever proteins extracted from 3.8-million-year-old ostrich shells (

sciencehabit writes: Scientists have smashed through another time barrier in their search for ancient proteins from fossilized teeth and bones, adding to growing excitement about the promise of using proteins to study extinct animals and humans that lived more than 1 million years ago. Until now, the oldest sequenced proteins are largely acknowledged to come from a 700,000-year-old horse in Canada’s Yukon territory, despite claims of extraction from much older dinosaurs. Now geneticists report that they have extracted proteins from 3.8-million-year-old ostrich egg shells in Laetoli, Tanzania, and from the 1.7-million-year-old tooth enamel of several extinct animals in Dmanisi, Georgia. The teeth, buried at the fossil site that houses the earliest hominin remains outside Africa, came from extinct horses, rhinos, and deer. One team has also extracted proteins from 3.8-million-year-old ostrich eggshells from the site of some of the world’s earliest human footprints.

