2018年7月7日 星期六

Security concerns of LXC containers

Security Considerations

Containers use the same kernel as the host, so there is a big attack surface for malicious users. You should consider this fact if you provide containers to totally untrusted people. In general, fully virtualized VMs provide better isolation.
The good news is that LXC uses many kernel security features like AppArmor, CGroups and PID and user namespaces, which makes containers usage quite secure.
REF: https://pve.proxmox.com/wiki/Linux_Container

Unprivileged LXC containers

These kind of containers use a new kernel feature called user namespaces. All of the UIDs (user id) and GIDs (group id) are mapped to a different number range than on the host machine, usually root (uid 0) became uid 100000, 1 will be 100001 and so on. This means that most security issues (container escape, resource abuse, …) in those containers will affect a random unprivileged user, even if the container itself would do it as root user, and so would be a generic kernel security bug rather than an LXC issue. The LXC team thinks unprivileged containers are safe by design.
REF: https://pve.proxmox.com/wiki/Unprivileged_LXC_containers

2018年7月6日 星期五

How to defend your encrypted emails against prying eyes

From June 7
In May, a draft technical paper published at efail.de recommended that people stop using GNU Privacy Guard (GPG) plugins to encrypt their email. At the same time, the Electronic Frontier Foundation raised the alarm about seemingly new vulnerabilities in GPG, echoing the paper's cautionary recommendations. Much of this information isn't new. The issue isn't a flaw in GPG, and there is no need to panic or discontinue using GPG, including for signing emails or for encrypting and decrypting files outside of your email client. Here are the facts.

2018年7月5日 星期四

TrendLabs: Malicious Macro Hijacks Desktop Shortcuts to Deliver Backdoor


Figure 1. Malware infection chain
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/malicious-macro-hijacks-desktop-shortcuts-to-deliver-backdoor/

2018年7月4日 星期三

SUSE Sold for $2.5 Billion

What’s different this time is that SUSE is being acquired by an investment firm and not a tech company. SUSE CEO, Nils Brauckmann, sees this as a move towards independence, with the company charting its own course instead of being a business unit of another tech company. “By partnering with EQT, we will become a fully independent business,” said Brauckmann. “Together with EQT, we will benefit both from further investment opportunities and having the continuity of a leadership team focused on securing long-term profitable growth combined with a sharp focus on customer and partner success.”
REF: http://www.admin-magazine.com/News/SUSE-Sold-for-2.5-Billion

2018年7月3日 星期二

Distribution Release: Network Security Toolkit 28-10234

Network Security Toolkit (NST) is a bootable live disc based on the Fedora distribution. The toolkit was designed to provide easy access to best-of-breed open source network security applications. The project has released NST 28-10234 which is based on Fedora 28. The new version includes Bluetooth improvements and proactive security testing and scanning tools. 
REF: https://distrowatch.com/10249

[USN-3695-1] Linux kernel vulnerabilities

---------- Forwarded message ----------
From: Steve Beattie 
Date: 2018-07-03 4:30 GMT+08:00
...
Details:

Wen Xu discovered that the ext4 file system implementation in the Linux
kernel did not properly initialize the crc32c checksum driver. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2018-1094)

It was discovered that the cdrom driver in the Linux kernel contained an
incorrect bounds check. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2018-10940)

Wen Xu discovered that the ext4 file system implementation in the Linux
kernel did not properly validate xattr sizes. A local attacker could use
this to cause a denial of service (system crash). (CVE-2018-1095)

Jann Horn discovered that the 32 bit adjtimex() syscall implementation for
64 bit Linux kernels did not properly initialize memory returned to user
space in some situations. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2018-11508)

It was discovered that an information leak vulnerability existed in the
floppy driver in the Linux kernel. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2018-7755)

...
References:
  https://usn.ubuntu.com/usn/usn-3695-1
  CVE-2018-1094, CVE-2018-10940, CVE-2018-1095, CVE-2018-11508,
  CVE-2018-7755

2018年7月1日 星期日

install Windows 10 cumulative updates

Do a search for the update using the KB number for the update you want. For example, KB3194798.
Click the Download button for the 64-bit or 32-bit version of the update...
REF: https://www.windowscentral.com/how-download-and-install-windows-10-cumulative-updates-manually