3 de septiembre de 2011

Kernel.org Hackeada totalmente

  • Security breach on kernel.org


    Earlier this month, a number of servers in the kernel.org infrastructure were compromised. We discovered this August 28th. While we currently believe that the source code repositories were unaffected, we are in the process of verifying this and taking steps to enhance security across the kernel.org infrastructure.


    What happened?


    • Intruders gained root access on the server Hera. We believe they may have gained this access via a compromised user credential; how they managed to exploit that to root access is currently unknown and is being investigated.
    • Files belonging to ssh (openssh, openssh-server and openssh-clients) were modified and running live.
    • A trojan startup file was added to the system start up scripts
    • User interactions were logged, as well as some exploit code. We have retained this for now.
    • Trojan initially discovered due to the Xnest /dev/mem error message w/o Xnest installed; have been seen on other systems. It is unclear if systems that exhibit this message are susceptible, compromised or not. If developers see this, and you don't have Xnest installed, please investigate.
    • It *appears* that 3.1-rc2 might have blocked the exploit injector, we don't know if this is intentional or a side affect of another bugfix or change.


    What Has Been Done so far:


    • We have currently taken boxes off line to do a backup and are in the process of doing complete reinstalls.
    • We have notified authorities in the United States and in Europe to assist with the investigation
    • We will be doing a full reinstall on all boxes on kernel.org
    • We are in the process of doing an analysis on the code within git, and the tarballs to confirm that nothing has been modified


    The Linux community and kernel.org take the security of the kernel.org domain extremely seriously, and are pursuing all avenues to investigate this attack and prevent future ones.


    However, it's also useful to note that the potential damage of cracking kernel.org is far less than typical software repositories. That's because kernel development takes place using the git distributed revision control system, designed by Linus Torvalds. For each of the nearly 40,000 files in the Linux kernel, a cryptographically secure SHA-1 hash is calculated to uniquely define the exact contents of that file. Git is designed so that the name of each version of the kernel depends upon the complete development history leading up to that version. Once it is published, it is not possible to change the old versions without it being noticed.


    Those files and the corresponding hashes exist not just on the kernel.org machine and its mirrors, but on the hard drives of each several thousand kernel developers, distribution maintainers, and other users of kernel.org. Any tampering with any file in the kernel.org repository would immediately be noticed by each developer as they updated their personal repository, which most do daily.


    We are currently working with the 448 users of kernel.org to change their credentials and change their SSH keys.


    We are also currently auditing all security policies to make kernel.org more secure, but are confident that our systems, specifically git, have excellent design to prevent real damage from these types of attacks.


O lo que es lo mismo, les han entrado hasta la cocina y se han comidos sus helados

Fuente:
https://www.kernel.org/

27 de agosto de 2011

¡¡¡ ¿ Dos cazas escoltando a un OVNI !!! ?

Tiene todos los números para ser un Fake, pero la verdad es que está muy bien hecho. Faltarían saber más datos sobre el que ha grabado y saber que se supone que hacía grabando el suelo.

Via:

Don Ramon y Perchita en lanzanos.com

Parece que el bueno de Niko quiere recuperar unos de sus mejores personajes. Don Ramon y Perchita, ya sabéis esos que se parecen tanto a Doraimon y Nobita pero que uno es rosa y el otro Yonki.

Si no lo recordáis en 2008 ya os lo comentábamos: Don Ramon y Perchita

Pues para volver a la carga, ya que parece que ya se ha gastado los millones, está pidiendo ayuda / patrocinadores para la nueva serie.

Si queréis ayudar:


26 de agosto de 2011

Wormed! iPhone Game almost ready to go



Puedes ver mas sobre iPhoneGamesDev.com en iPad,iPhone,iPod touch, Mac, windows and linux Games

Nota, el vídeo fué eliminado así que hemos puesto el último vídeo.

25 de agosto de 2011

¿Que harías por 5 dolares?

Curioso sitio web donde todo el mundo se vende por solo 5 $

21 de agosto de 2011

Como conseguir un millón de visitas en tu web?

Es la pregunta que todo el mundo se hace, y parece que alguien tiene la respuesta, con un sistema aparentemente eficiente. Veremos que tal funciona.





P.D. Yo no garantizo que tengas un millón de visitas, ya que no lo he provado aún.

18 de agosto de 2011

juego curiosos del día

Al estilo defend the tower de plants vs zombies, nos llega este juego en html5, muy entretenido.

15 de agosto de 2011

Ya disponibles las betas de los juegos para Mac

Pues eso que ya se pueden descargar las betas que estaban para windows pero ahora para Mac.

10 de agosto de 2011

50 € en adsense, si lo activas en menos de 15 dias

Código promocional de adsense 50€, prueba con este código. 6GJ8-H87H-JZF5-GMZ9-GV82

No se si funcionará, pero pruebalo por si acaso.