Tuesday, August 13, 2013

Linux Kernel 3.4.29 LTS Is Available for Download



Linux kernel 3.4.29 introduces a lot of various fixes, as well as driver improvements and improved Arch support.

Greg Kroah-Hartman announced the immediate availability for download of Linux kernel 3.4.29 LTS (long-term support).

Highlights of Linux kernel 3.4.29 LTS:

• Incorrect strncpy() has been fixed in hidp_setup_hid();
• A typo in PCIe adapter NULL check has been fixed;
• DMAR has been disabled for g4x integrated gfx;
• Pass a proper identity mapping in efi_call_phys_prelog;
• A fixup for Packard-Bell desktop with ALC880 has been implemented.

A complete list of changes and fixes can be found in the official mailing list.

“I'm announcing the release of the 3.4.29 kernel. All users of the 3.4 kernel series should upgrade or risk being turned into pumpkins.”

“The updated 3.4.y git tree can be found at: git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git linux-3.4.y and can be browsed at the normal kernel.org git web browser: http://git.kernel.org/?p=linux/kernel/git/stable/linux-stable.git,” said Greg Kroah-Hartman in the email announcement.

Users of the Linux kernel 3.4.x branch are urged to update to the new version as soon as possible.

Download Linux kernel 3.4.29 LTS right now from Softpedia.

Posted by R2blog. R2blog auto post for blogspot. Download at http://R2blogger.blogspot.com


Anonymous Compromises Alabama Government Site, Details of 4,000 Bankers Exposed


Anonymous-Hack
Anonymous hackers continue Operation Last Resort (OpLastResort). In the latest phase of the campaign, the hacktivists have leaked the details of more than 4,000 bank executives.

It’s interesting that the hackers haven’t used Pastebin or other similar websites to publish the data. Instead, they have hacked the website of the Alabama Criminal Justice Information Center (acjic.alabama.gov) and have posted the information in its “documents” folder under the name “oops-we-did-it-again.”

The file published by Anonymous contains names, titles, email addresses, physical addresses, fax numbers, mobile phone numbers, login IDs, IP addresses, password hashes, and other details. The information appears to belong to presidents, vice presidents, managing officers, CEOs, SVPs, and others.

ZDNet has analyzed the list of names and has learned that most of them show up as current employees on the banks’ websites.

Reddit users have also studied the leaked information.

“OK, I called a few of them. What must be so problematic for the Federal Reserve is not the information so much as this file was stolen from their computers at all. The ramifications of that kind of loss of control is severe,” one user noted.

Others, on the other hand, don’t agree with Anonymous.

“#OpLastResort has shown up out of nowhere to leak the have personal information of a lot of innocent people and should not be regarded as part of 'Anonymous'. There is no reason for what they did and they didn't even attempt to justify or even give meaning to their actions. They are simply destructive,” another user argued.

Operation Last Resort, a campaign that comes in response to the suicide of Aaron Swartz, was initiated around one week ago with a hack which targeted the United States Sentencing Commission (USSC).

Posted by R2blog. R2blog auto post for blogspot. Download at http://R2blogger.blogspot.com


Twitter Hacked, 250,000 Email and Password Compromised


If you find that your Twitter password doesn't work the next time you try to login, you won't be alone. The service was busy resetting passwords and revoking cookies on Friday, following an online attack that may have leaked the account data of approximately 250,000 users.

"This week, we detected unusual access patterns that led to us identifying unauthorized access attempts to Twitter user data," Bob Lord, Twitter's director of information security, writes in a blog post.

According to Lord, Twitter was able to shut down the attack within moments of discovering it, but not before the attackers were able to make off with what he calls "limited user information," including usernames, email addresses, session tokens, and the encrypted and salted versions of passwords.

The encryption on such passwords is generally difficult to crack – but it's not impossible, particularly if the attacker is familiar with the algorithm used to encrypt them.

As a precaution, Lord says Twitter has reset the passwords of all 250,000 affected accounts – which, he observes, is just "a small percentage" of the more than 140 million Twitter users worldwide.

If yours is one of the accounts involved, you'll need to enter a new password the next time you login. Lord reminds all Twitter users to choose strong passwords – he recommends 10 or more characters, with a mix of letters, numbers, and symbols – because simpler passwords are easier to guess using brute-force methods. In addition, he recommends against using the same password on multiple sites.

Lord says Twitter's investigation is ongoing, and that it's taking the matter extremely seriously, particularly in light of recent attacks experienced by The New York Times and The Wall Street Journal:
This attack was not the work of amateurs, and we do not believe it was an isolated incident. The attackers were extremely sophisticated, and we believe other companies and organizations have also been recently similarly attacked. For that reason we felt that it was important to publicize this attack while we still gather information, and we are helping government and federal law enforcement in their effort to find and prosecute these attackers to make the Internet safer for all users.
Although the attack took place this week, it seems to have no relationship to the outage that took Twitter offline for several hours on Thursday. On the other hand, however, Lord's post does make rather cryptic mention of the US Department of Homeland Security's recent recommendation that users disable the Java plug-in in their browsers. He mentions Java twice, in fact.

While it's true that the Java plug-in contains multiple known vulnerabilities and that numerous security experts have warned that it should be considered unsafe, the connection between Java and the attack Twitter experienced isn't clear and twitter is yet to respond to our request for clarification.

Posted by R2blog. R2blog auto post for blogspot. Download at http://R2blogger.blogspot.com


Advance DDOS Tools: Encrypted Layer Attacks and Server-Based Botnets


Application security solutions provider Radware has released its 2012 Global Application and Network Security Report. According to the study, distributed denial-of-service (DDOS) attacks are becoming more sophisticated and more severe.

In addition, cybercriminals have started deploying new attack tools, such as server-based botnets and encrypted layer attacks, to make their campaigns more effective.

While server-based botnets make the attacks more powerful, by weaponizing the encryption layer, cybercriminals can ensure that their operations escape detection and remain hidden.

The recent DDOS attacks launched by Izz ad-Din al-Qassam Cyber Fighters against US banks are a perfect example of how efficient these new tools are.

Besides the new attack tools, the report also highlights the fact that the number of DDOS and DOS attacks lasting more than one week doubled in 2012.

On the other hand, organizations are still not investing enough resources to ensure that they’re protected against such attacks.

While it’s becoming more and more difficult for organizations to protect their networks against cyberattacks, cybercriminals can turn to all sorts of relatively cheap services and kits that can help them achieve their goals.

“The Radware ERT sees hundreds of DoS/DDoS attacks each year, and we’ve found attacks lasting more than one week have doubled in frequency during 2012. Through empirical and statistical research coupled with front-line experience, our team identified trends that can help educate the security community,” noted Avi Chesla, chief technology officer at Radware.

“Through highlighting significant trends found in this report, our goal is to provide actionable intelligence to ensure organizations can better detect and mitigate these threats that plague their network infrastructure.”

The complete report is available here.

Posted by R2blog. R2blog auto post for blogspot. Download at http://R2blogger.blogspot.com


Cloud Data Storage Providers that Offers Freemium Service


Probably you've got important documents, videos, music or other stuffs that needs to be shared across multiple devices, using cloud storage technology is for now the easiest option you've got and the number of people it are increasingly by day.

Cloud Storage has come to say and with so many cloud service providers, you may be wondering which one could be right for you. The list below will help you based on general summary of each popular cloud service.

First, let look at what cloud storage is for the benefit of those that don't know what it is. According to wikipedia
Cloud storage is a model of networked online storage where data is stored in virtualized pools of storage which are generally hosted by third parties. Hosting companies operate large data centers, and people who require their data to be hosted buy or lease storage capacity from them. The data center operators, in the background, virtualize the resources according to the requirements of the customer and expose them as storage pools, which the customers can themselves use to store files or data objects. Physically, the resource may span across multiple servers.The safety of the files depends upon the hosting websites.
Cloud storage services may be accessed through a web service application programming interface (API), a cloud storage gateway or through a Web-based user interface.

1. Mega

Mega is a cloud storage provider and successor to Megaupload. The website was launched on 19 January 2013 to coincide with the one-year anniversary of the seizure of Megaupload. After the Gabonese Republic denied the new company the domain name me.ga, Kim Dotcom, the don in-charge announced it would instead be registered in his adopted home of New Zealand under the domain name mega.co.nz.

Currently, free users will get 50 GB of free storage space and total bandwidth will be limited, from 1 to 8 TB per month, for paid accounts. Free account bandwidth is not currently disclosed.

2. SkyDrive

SkyDrive (officially Microsoft SkyDrive, previously Windows Live SkyDrive and Windows Live Folders) is a file hosting service that allows users to upload and sync files to a cloud storage and then access them from a Web browser or their local device. It is part of the Windows Live range of online services and allows users to keep the files private, share them with contacts, or make the files public. Publicly shared files do not require a Microsoft account to access.

The service offers 7 GB of free storage for new users. Additional storage is available for purchase. Users who signed up to SkyDrive prior to April 22, 2012 could opt-in for a limited time offer of 25 GB of free storage upgrade. The service is built using HTML5 technologies, and files up to 300 MB can be uploaded via drag and drop into the web browser, or up to 2 GB via the SkyDrive desktop application for Microsoft Windows and OS X.

3. Google Drive

Google Drive is a file storage and synchronization service by Google that was released on April 24, 2012. Google Drive is now the home of Google Docs, a suite of productivity applications, that offer collaborative editing on documents, spreadsheets, presentations, and more. Rumors about Google Drive began circulating as early as March 2006.

Google Drive gives all users 5 GB of cloud storage to start with. A user can get additional storage, which is shared between Picasa and Google Drive, from 25 GB up to 16 TB through a paid monthly subscription plan ($2.49 US per month for 25 GB).

4. Box

Box Inc. (formerly Box.net) is an online file sharing and Cloud content management service for enterprise companies. The company has adopted a freemium business model, and provides 5 GB of free storage for personal accounts. A mobile version of the service is available for Android, BlackBerry, iPhone, iPad, WebOS, and Windows Phone devices. The company is based in Los Altos, California.

5. MediaFire

MediaFire is a free file and image hosting web site that started in 2005 and is located in Shenandoah, Texas, United States. MediaFire include 50 GB of cloud storage and a limit of 200 MB per file (250 GB of storage and 4GB of file size limit for Pro users and 1000 GB of storage and 10 GB of file size limit for Business users).MediaFire provides users with the ability to create image galleries from folders of images and view and share common document, presentation, and spreadsheet file types inside the web browser. MediaFire's free account service does not require download activity in order to preserve files, and is thus often suitable as a temporary or secondary backup solution although MediaFire does not officially support free data warehousing (long-term storage for inactive accounts).

Posted by R2blog. R2blog auto post for blogspot. Download at http://R2blogger.blogspot.com



  Whenever we create an account on any website or comment on any blog we see scrambled words which we have to type and continue these are CAPTCHAs .  What are CAPTCHAs and what they do? It stands for Completely Automated Public Turing-test to tell Computers and Humans Apart.These tries to test that you are [...]

Posted by R2blog. R2blog auto post for blogspot. Download at http://R2blogger.blogspot.com


Blue FB status


Hello Friends!! This is one of the best FB tricks b’coz it not only change color of  your fb status, but it also turn that into a link which leads to the profile page of the person who clicked it. Just follow the steps:   Step 1) Write the below code in your status field. @@[1:[0:1: [...]

Posted by R2blog. R2blog auto post for blogspot. Download at http://R2blogger.blogspot.com