evernote – Jupiter Broadcasting https://www.jupiterbroadcasting.com Open Source Entertainment, on Demand. Wed, 23 May 2018 13:57:28 +0000 en-US hourly 1 https://wordpress.org/?v=5.5.3 https://original.jupiterbroadcasting.net/wp-content/uploads/2019/04/cropped-favicon-32x32.png evernote – Jupiter Broadcasting https://www.jupiterbroadcasting.com 32 32 Only The Best | LINUX Unplugged 250 https://original.jupiterbroadcasting.net/125021/only-the-best-lup-250/ Wed, 23 May 2018 05:57:28 +0000 https://original.jupiterbroadcasting.net/?p=125021 Show Notes/Links: linuxunplugged.com/250

The post Only The Best | LINUX Unplugged 250 first appeared on Jupiter Broadcasting.

]]>

Show Notes/Links: linuxunplugged.com/250

The post Only The Best | LINUX Unplugged 250 first appeared on Jupiter Broadcasting.

]]>
It’s All Wimpy’s Fault | LINUX Unplugged 238 https://original.jupiterbroadcasting.net/122797/its-all-wimpys-fault-lup-238/ Tue, 27 Feb 2018 21:18:00 +0000 https://original.jupiterbroadcasting.net/?p=122797 RSS Feeds: MP3 Feed | iTunes Feed | Video Feed | Torrent Feed Become a supporter on Patreon: Show Notes: Chrome OS may soon be able to run Linux applications in a container As mentioned in the comments, and pointed out by Chrome Unboxed, one Chrome OS developer uploaded two screenshots of what the container […]

The post It's All Wimpy's Fault | LINUX Unplugged 238 first appeared on Jupiter Broadcasting.

]]>

RSS Feeds:

MP3 Feed | iTunes Feed | Video Feed | Torrent Feed

Become a supporter on Patreon:

Patreon

Show Notes:

Chrome OS may soon be able to run Linux applications in a container

As mentioned in the comments, and pointed out by Chrome Unboxed, one Chrome OS developer uploaded two screenshots of what the container feature will look like. It shows a popup with the description, “Develop on your Chromebook. You can run your favorite Linux apps and command-line tools seamlessly and securely.”

Tusk Evernote Client Updated, Is Now Available as a Snap

Through the inclusion of optional themes, keyboard shortcuts, custom tweaks, a tray icon, and more, Tusk integrates the Evernote web app with the Linux desktop in ways a regular browser tab can’t.

Changes/ImprovedLaptopBatteryLife – Fedora Project Wiki

Improve Fedora (Workstation) Battery Life by enabling various hardware power-saving features by default.

TING

Ubuntu Software Will Soon Let You Install Beta, Bleeding Edge Snap Apps

Alex over at WOGUE noticed that the latest version of Ubuntu Software in the Bionic Beaver daily builds offers the ability to switch/select Snap channels through a GUI.

Where’s Xfce 4.14? Current Development, Roadmap & Future – FOSS Post

Xfce’s situation is a bit concerning because by the time Xfce 4.14 is out, GTK+ 4 could already be released as stable. Also, Xfce didn’t move a single step in the direction toward Wayland. And with the speed of the current development, the good DE could lack a lot behind.

DigitalOcean

New Kdenlive Beta is Available for Testing

A new public beta release of next-generation Kdenlive is available to for testing.

‘Satoshi’ Craig Wright Is Being Sued For $10 Billion For Stealing His Partner’s Bitcoin

Craig Wright, the nChain chief scientist who previously claimed to be the pseudonymous bitcoin creator Satoshi Nakamoto, is being sued for a whopping $10 billion for stealing $5 billion in bitcoin from a former business partner


Linux Academy

Crankshaft is a turn-key GNU/Linux distribution for the Raspberry Pi that transforms it to an Android Auto headunit. All you need is a RPi3 board and its official 7″ touchscreen.
Driving demo, Features demo.

The post It's All Wimpy's Fault | LINUX Unplugged 238 first appeared on Jupiter Broadcasting.

]]>
Invest In Popcorn | LINUX Unplugged 230 https://original.jupiterbroadcasting.net/121092/invest-in-popcorn-lup-230/ Tue, 02 Jan 2018 23:17:16 +0000 https://original.jupiterbroadcasting.net/?p=121092 RSS Feeds: MP3 Feed | iTunes Feed | Video Feed | Torrent Feed Become a supporter on Patreon: Show Notes: Happy New Year- Welcome to Linux Journal 2.0! Talk about a Happy New Year. The reason: it turns out we’re not dead. In fact, we’re more alive than ever, thanks to a rescue by readers—specifically, […]

The post Invest In Popcorn | LINUX Unplugged 230 first appeared on Jupiter Broadcasting.

]]>
RSS Feeds:

MP3 Feed | iTunes Feed | Video Feed | Torrent Feed

Become a supporter on Patreon:

Patreon

Show Notes:

Happy New Year- Welcome to Linux Journal 2.0!

Talk about a Happy New Year. The reason: it turns out we’re not dead. In fact, we’re more alive than ever, thanks to a rescue by readers—specifically, by the hackers who run Private Internet Access.

This is exactly what we had hoped for in recent years, but hardly expected. Really and truly, I waited to put up our farewell post until all hope was lost. But hey, it turns out you don’t have to believe in miracles to experience one, because that’s exactly what happened here.

Second, they’re eager to support us in building Linux Journal 2.0 around the substantial core of devoted readers we had through the many years of Linux Journal 1.x. And, this means we need to hear from you!

Google’s experimental Fuchsia OS can now run on the Pixelbook

Google’s in-development operating system, Fuchsia, has a new development device: The Google Pixelbook. Google’s $1,000 laptop usually runs Chrome OS, but with the latest Fuchsia builds, you can swap out the browser-based OS for Google’s experimental operating system.

Fuchsia is still incredibly difficult to get running. Along with the Pixelbook, Fuchsia only supports two other obscure pieces of hardware: an Acer Switch Alpha 12 laptop and old Intel NUCs from 2015.

The extreme difficulty in getting Fuchsia to run reinforces the fact that Fuchsia is currently a secret, deep-in-development operating system that Google isn’t really ready to talk about or encourage people to try just yet.

TING

‘Kernel memory leaking’ Intel processor design flaw forces Linux, Windows redesign

A fundamental design flaw in Intel’s processor chips has forced a significant redesign of the Linux and Windows kernels to defang the chip-level security bug.

Crucially, these updates to both Linux and Windows will incur a performance hit on Intel products. The effects are still being benchmarked, however we’re looking at a ballpark figure of five to 30 per cent slow down, depending on the task and the processor model.

Details of the vulnerability within Intel’s silicon are under wraps: an embargo on the specifics is due to lift early this month, perhaps in time for Microsoft’s Patch Tuesday next week. Indeed, patches for the Linux kernel are available for all to see but comments in the source code have been redacted to obfuscate the issue.

AMD processors are not subject to the types of attacks that the kernel page table isolation feature protects against.

DigitalOcean

An introduction to Joplin, an open source Evernote alternative

Joplin is an open source cross-platform note-taking and to-do application. It can handle a large number of notes, organized into notebooks, and can synchronize them across multiple devices.The notes can be edited in Markdown, either from within the app or with your own text editor, and each application has an option to render Markdown with formatting, images, URLs, and more.

As such, its synchronization is designed without any hard dependency to any particular service. Most of the synchronization process is done at an abstract level, and access to external services, such as OneDrive or Dropbox, is done via lightweight drivers.

Joplin was designed as a replacement for Evernote, so it can import complete Evernote notebooks, as well as notes, tags, resources (attached files), and note metadata (such as author, geolocation, etc.) via ENEX files.

Valve: Linux Catbot VAC ban claims were hoaxed by hackers to ‘sow distrust among anti-cheat systems’

initially wrote that Valve was banning Linux users with Linux usernames that included the word ‘catbot’, but Valve has said those claims were a “tactic employed by cheaters to try and sow discord and distrust among anticheat systems”.

“Linux historically hasn’t been a problem for cheating–the base rate of cheating is significantly lower on Linux than it is on Windows. Unfortunately, a ‘healthy’ community of cheaters grew up around catbot on linux and their impact on TF became large enough that they simply could no longer be ignored. Those banned users are very annoyed that VAC has dropped the hammer on them.”

Linux Academy

2017 Best Practices

Bad predictions and plans for maintenance

All the Annoying Tech Chores You Need to Do When You Have Time

Like your car, or your kitchen, your tech devices will run best when they’re maintained properly—and that means finding time to do all those low-level maintenance tasks that aren’t much fun, but can keep everything stable and smooth, and avoid problems in the future.

  • Update your Software
  • Go through old files and free up some space
  • Monitor for problems
  • Get Organized
  • Update router and other firmware
  • Move to the cloud?

Linux resolutions for 2018

It’s always a good idea to start a new year with renewed intentions to be even better users and administrators of our Linux systems.

  • Automate the boring stuff
  • Learn a new language
  • Try a new OS
  • Focus on Security
  • Restore those backups!
  • Document, Document, Document
  • Most importantly, have some fun!

The post Invest In Popcorn | LINUX Unplugged 230 first appeared on Jupiter Broadcasting.

]]>
All By My SELF | LAS 424 https://original.jupiterbroadcasting.net/100881/all-by-my-self-las-424/ Sun, 03 Jul 2016 20:13:49 +0000 https://original.jupiterbroadcasting.net/?p=100881 We go back in time and take a look at what you missed at SELF 2016. Plus we’re 1% closer to the Linux Desktop, why Evernote sucks & more! Thanks to: Get Paid to Write for DigitalOcean Direct Download: HD Video | Mobile Video | WebM Torrent | MP3 Audio | OGG Audio | YouTube […]

The post All By My SELF | LAS 424 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

We go back in time and take a look at what you missed at SELF 2016. Plus we’re 1% closer to the Linux Desktop, why Evernote sucks & more!

Thanks to:


DigitalOcean


Ting


Linux Academy

Direct Download:

HD Video | Mobile Video | WebM Torrent | MP3 Audio | OGG Audio | YouTube | HD Torrent

RSS Feeds:

HD Video Feed | Large Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feed | Torrent Feed

Become a supporter on Patreon:

Patreon

— Show Notes: —


System76

Brought to you by: Linux Academy

— PICKS —

Runs Linux

Fireworks RUNS LINUX

A test of the Raspberry Pi sprinkler controller which I’m working on. I’m borrowing it to use as a fireworks controller since it’s just a relay controller.

I’m using a 12V SLA battery to power everything. Battery goes into switch box so that fireworks has a master control safety switch. A cheap switching power supply is used to step down the 12V to 5V for the Pi. The relay boards are controlled by three 74hc595 shift registers.

Desktop App Pick

rambox.pro

Free and Open Source messaging and emailing app that combines common web applications into one.

  • Notifications
  • Sync Services
  • Lock
  • Don’t Disturb
  • Add Custom Services
  • Reorder and grouping
  • Badges
  • System Tray

Spotlight

K3b -Disk Burning

K3b is a full-featured, easy to use CD and DVD burner, copier, ripper and more.


— NEWS —

End of 32bit machines?

Linux Reaches 2%

Infinity:One is OLPC XO’s bigger, more responsible sibling

Evernote limits free tier to two devices, raises prices 40%

SELF 2016 coverage

Mail Bag

  • https://slexy.org/view/s2y1aGapyF
  • https://slexy.org/view/s20lJgvN10
  • https://slexy.org/view/s2BDxIvbpj

Call Box

Catch the show LIVE SUNDAY:

— CHRIS’ STASH —

Chris’s Twitter account has changed, you’ll need to follow!

Chris Fisher (@ChrisLAS) | Twitter

Hang in our chat room:

irc.geekshed.net #jupiterbroadcasting

— NOAH’S STASH —

Noah’s Day Job

Altispeed Technologies

Contact Noah

noah [at] jupiterbroadcasting.com

Find us on Google+

Find us on Twitter

Follow us on Facebook

The post All By My SELF | LAS 424 first appeared on Jupiter Broadcasting.

]]>
Floating on ownCloud 9 | LAS 410 https://original.jupiterbroadcasting.net/98121/floating-on-owncloud-9-las-410/ Sun, 27 Mar 2016 17:46:24 +0000 https://original.jupiterbroadcasting.net/?p=98121 We risk it all and toss our data into the new ownCloud 9 to give you our review. Find out about using ownCloud as an Evernote killer, Federated servers & the long-term commitment you’re making as an ownCloud user. Plus Red Hat’s big news, the new Gnome & things go to the next level in […]

The post Floating on ownCloud 9 | LAS 410 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

We risk it all and toss our data into the new ownCloud 9 to give you our review. Find out about using ownCloud as an Evernote killer, Federated servers & the long-term commitment you’re making as an ownCloud user.

Plus Red Hat’s big news, the new Gnome & things go to the next level in our upcoming switch competition.

Thanks to:


DigitalOcean


Ting


Linux Academy

Direct Download:

HD Video | Mobile Video | WebM Torrent | MP3 Audio | OGG Audio | YouTube | HD Torrent

RSS Feeds:

HD Video Feed | Large Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feed | Torrent Feed

Become a supporter on Patreon:

Patreon

— Show Notes: —


System76

Brought to you by: Linux Academy

ownCloud 9 Review

Federated Sharing – What’s new in ownCloud 9.0

With ownCloud 9.0 we made it even easier to exchange the Federated Cloud IDs. Below you can see the administrator setting for the new Federation App, which will be enabled by default.

federation

The option “Add server automatically once a federated share was created successfully” is enabled by default. This means, that as soon as a user creates a federated share with another ownCloud, either as a recipient or as a sender, ownCloud will add the remote server to the list of trusted ownClouds. Additionally you can predefined a list of trusted ownClouds. While technically it is possible to use plain http I want to point out that I really recommend to use https for all federated share operations to secure your users and their data.

What does it mean that two ownClouds trust each other? ownCloud 9.0 automatically creates a internal address book which contains all users accounts. If two ownClouds trust each other they will start to synchronize their system address books. In order to synchronize the system address books and to keep them up-to-date we use the well known and widespread CardDAV protocol. After the synchronization was successful ownCloud will know all users from the trusted remote servers, including their Federated Cloud ID and their display name. The share dialog will use this information for auto-completion. This allows you to share files across friendly ownClouds without knowing more than the users name. ownCloud will automatically find the corresponding Federated Cloud ID and will suggest the user as a recipient of your share.

Time to Upgrade to ownCloud 9.0!
Why Should I Upgrade?
  1. ownCloud usage grew last year from 2.4 to 8 million so newer releases have far more users
  2. Testing improves, benefiting newer releases more than older, in part because
  3. Backporting is limited to security fixes for releases older than Latest-1
  4. Clients take advantage of features only in newer server versions
  5. We introduce features which improve reliability

— PICKS —

Runs Linux

Maple Runs Linux

Dear Chris, I am writing to reply to your question in LAS episode 404 that Maine does in fact have WiFi. I have been working on a project at a local Sugar House to bring remote monitoring of a maple syrup operation run as a small family business.

I enjoy a lot of the content at Jupiter Broadcasting and now that I am deriving billable value from your content, I will be becoming a patron over at patreon.com. I also checked out teespring.com and found a JB polo, but unfortunately it is out of stock. If I were to find a JB, LAS, Tech SNAP, Tech Talk Today, BSD Now, or Linux Unplugged polo over there in the future, I would be sure to pick one up. Thanks for the great programming, please keep it up.

Desktop App Pick

QOwnNotes – cross-platform open source plain-text file notepad

QOwnNotes

QOwnNotes is the open source (GPL) plain-text file notepad with markdown support and todo list manager for GNU/Linux, Mac OS X and Windows, that (optionally) works together with the notes application of ownCloud.

Weekly Spotlight

Newsbeuter

Newsbeuter Screenshot

Newsbeuter is an open-source RSS/Atom feed reader for text terminals. It
runs on Linux, FreeBSD, Mac OS X and other Unix-like operating systems.
Newsbeuter’s great configurability and vast number of features make it a
perfect choice for people that need a slick and fast feed reader that can
be completely controlled via keyboard.

A summary of some of its features:

  • Subscribe to RSS 0.9x, 1.0, 2.0 and Atom feeds
  • Download podcasts
  • Freely configure your keyboard shortcuts
  • Search through all downloaded articles
  • Categorize and query your subscriptions with a flexible tag system
  • Integrate any data source through a flexible filter and plugin system
  • Automatically remove unwanted articles through a “killfile”
  • Define “meta feeds” using a powerful query language
  • Synchronize newsbeuter with your bloglines.com account
  • Import and exporting your subscriptions with the widely used OPML format
  • Freely define newsbeuter’s look’n’feel through free color configurability and format strings
  • Keep all your feeds in sync with Google Reader
  • Newsbeuter is the Mutt of RSS feed readers.
  • Not convinced? See for yourself.

— NEWS —

​Red Hat becomes first $2b open-source company

Imgur

Just think: Some people still don’t believe that you can make money from Linux and open-source software. Fools! Red Hat just became the first open-source company to make a cool 2 billion bucks.

GNOME 3.20 Release Notes

GNOME 3.20 is the latest version of GNOME 3, and is the result
of 6 months’ hard work by the GNOME community. It contains major new
features, as well as many smaller improvements and bug fixes. In total, the
release incorporates 28933 changes, made by approximately 837
contributors.

11 Neat New Features in GNOME 3.20

To celebrate this milestone we’ve scoured the change-logs to pull out 11 GNOME 3.20 features we think you’re going to love…

Feedback:


System76

Brought to you by: System76

Mail Bag

Noah v. Emma: Switching People to Linux

Noah vs Emma

  • Noah vs Emma Card
  • Can not already be running Linux.
  • Must agree to install Linux, or have Linux installed
  • Will take place Sat during Linux Fest NW (Location TBD)
  • Come find Noah let him switch you to Linux and get a free SSD installed.

Call Box

Catch the show LIVE SUNDAY:

— CHRIS’ STASH —

Chris’s Twitter account has changed, you’ll need to follow!

Chris Fisher (@ChrisLAS) | Twitter

Hang in our chat room:

irc.geekshed.net #jupiterbroadcasting

— NOAH’S STASH —

Noah’s Day Job

Altispeed Technologies

Contact Noah

noah [at] jupiterbroadcasting.com

Find us on Google+

Find us on Twitter

Follow us on Facebook

The post Floating on ownCloud 9 | LAS 410 first appeared on Jupiter Broadcasting.

]]>
Demilitarized Tone | TechSNAP 166 https://original.jupiterbroadcasting.net/59832/demilitarized-tone-techsnap-166/ Thu, 12 Jun 2014 16:57:23 +0000 https://original.jupiterbroadcasting.net/?p=59832 Researchers develop an ultrasonic mesh network to extract data from computer networks, Feedly and Evernote get attacked, and something is amiss with Windows 7. Then its a great batch of your feedback, our answers, and much much more! Thanks to: Direct Download: HD Video | Mobile Video | MP3 Audio | Ogg Audio | YouTube […]

The post Demilitarized Tone | TechSNAP 166 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

Researchers develop an ultrasonic mesh network to extract data from computer networks, Feedly and Evernote get attacked, and something is amiss with Windows 7.

Then its a great batch of your feedback, our answers, and much much more!

Thanks to:


DigitalOcean


Ting


iXsystems

Direct Download:

HD Video | Mobile Video | MP3 Audio | Ogg Audio | YouTube | HD Torrent | Mobile Torrent

RSS Feeds:

HD Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feeds | Torrent Feed

— Show Notes: —

Exfiltrating data using an ultrasonic mesh network

  • Researchers at the Fraunhofer institute in Germany have developed a protocol based on an underwater communications protocol, to pass messages between laptops using their speakers
  • Fraunhofer Institute is famous for having invented the MP3 audio codec and being a significant contributor to the H.264/MPEG-4 AVC video codec.
  • The paper describes a ‘Covert Channel’ that can be used to circumvent firewalls and intrusion detection systems
  • The system uses ultrasonic sound, emitted by laptop speakers and received by laptop microphones
  • The range is about 20 meters and the provides about 20 bits/second of bandwidth
  • The general principle is to create a mesh network of laptops in order to exfiltrate data from a protected network or location
  • The proof of concept was created by installing a keylogger on a laptop, which would then send the data back to the attacker by emitting the ultrasonic (inaudible to the human ear) sounds, which would then be picked up by another infected machine and repeated, extending the transmission range
  • Eventually the signal may be able to reach a machine outside of the protected area or network, and be received by the attack, or re-transmitted by regular means
  • As a countermeasure, they suggest possibly disabling the speakers/microphone entirely
  • As a more useful countermeasure, they suggest a low-pass filter that would either remove the ultrasonic frequencies from the output, or shift them down to audible range so they can be detected by humans
  • The paper also discusses a host-based intrusion detection system that analyzes audio input and output for suspect signals
  • Full PDF

Feedly And Evernote Go Down As Attackers Demand Ransom

  • After restoring its services after Wednesday’s attack, the Feedly team reported in a blog post Thursday morning that it had been hit by a second DoS attack. As of late Thursday morning, Feedly is down again.
  • On Thursday June 12th Feedly Posted to their Blog: “2:04am PST – Criminals are attacking feedly with a distributed denial of service attack (DDoS). The attacker is trying to extort us for money to make it stop. We refused to give in and are working with our network providers to mitigate the attack as best as we can.”
  • In Evernote’s case, the company noted yesterday evening that it was unavailable, and that it was working to neutralize a denial of service attack. A few hours later, a message on Evernote’s Twitter account said its service was restored – but it’s not out of the woods yet. “There may be a hiccup or two for the next 24 hours,” the tweet warned.
  • At least in Feedly’s case the attackers demanded a ransom to stop the attack.
  • It’s unknown as of now if the hackers are demanding ransom from Feedly on day two of the attack. The company has not responded to a request for comment.
  • Denial of service attack [Neutralized] – Feedly Blog
  • Feedly, Evernote And Others Become Latest Victims Of DDoS Attacks
  • BBC News – Feedly and Evernote struck by denial of service cyber-attacks
  • EuroBSDCon 2013 — Allan Jude — Mitigating DDoS Attacks at Layer 7

Microsoft patching flaws in Windows 8, but not Windows 7?

  • Researchers found the gaps after they scanned 900 Windows libraries and uncovered a variety of security functions that were updated in Windows 8 but not in 7. They said the shortcoming could lead to the discovery of zero day vulnerabilities.
  • The missing safe functions were part of Microsoft’s dedicated libraries intsafe.h and strsafe.h that help developers combat various attacks.
  • Researcher Moti Joseph and malware analyst Marion Marschalek (@pinkflawd) developed a capable diffing (comparison) tool dubbed DiffRay which would compare Windows 8 with 7, and log any safe functions absent in the older platform.
  • In a demonstration of DiffRay, the researchers found four missing safe functions in Windows 7 that were present in 8.
  • Including:
    • bcrypt.dll!ConvertRsaPrivateBlobToFullRsa
    • netlogon.dll!NlpAddResourceGroupsToSamInfo
    • twext.dll!EscapeField (possible unpatched interger overflow in Windows 7, fixed in 8)
  • Slides
  • Video – What happens in Windows 7, stays in Windows 7

Feedback:


Round Up:


The post Demilitarized Tone | TechSNAP 166 first appeared on Jupiter Broadcasting.

]]>
100% Uptime | TechSNAP 100 https://original.jupiterbroadcasting.net/33126/100-uptime-techsnap-100/ Thu, 07 Mar 2013 17:20:39 +0000 https://original.jupiterbroadcasting.net/?p=33126 We’ve warned against it for nearly 100 episodes, this week we’ll share the fallout from NBC.com getting hacked, and more.

The post 100% Uptime | TechSNAP 100 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

We’ve warned against it for nearly 100 episodes, this week we’ll share the fallout from NBC.com getting hacked, Bit9’s whitelist technology is use against them and their customers.

Plus the bad news for Java users, a batch of your questions, and some big surprises.

Thanks to:

Use our code hostdeal4 to score economy hosting for $1 a month, for one year.

35% off your ENTIRE order just use our code go35off4 until the end of the month!

 

Visit techsnap.ting.com to save $25 off your device or service credits.

 

Direct Download:

HD Video | Mobile Video | MP3 Audio | Ogg Audio | YouTube | HD Torrent | Mobile Torrent

RSS Feeds:

HD Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feeds | Torrent Feed

 

Support the Show:

   

Show Notes:

Get TechSNAP on your Android:

Browser Affiliate Extension:

  • Jupiter Broadcasting Affiliate Extensions for Chrome and Firefox
  • NBC website compromised, malicious code injected

    • The official website of US broadcasting and media giant NBC was found to contain a malicious iframe pointing visitors to the RedKit Exploit Kit
    • The exploit kit used one of the vulnerabilities patched in Java 7u11 (released January 13th, although the issue was not fully fixed until Java 7 u13 on February 1st), as well as a .PDF exploit to drop the Citadel banking Trojan, a variant of the Zeus botnet only ever sold to the russian underground, to prevent infiltration by authorities and security companies
    • This attack could have been much worse if it has used one of the newer vulnerabilities that had not been patched until u15 (February 19th) or u17 (March 4th)
    • Many users are likely still using somewhat outdated versions of java due to the rapid release and the inefficacy of the java updater, and the addition of the .PDF exploit ensured a wider vulnerability
    • The attackers likely had ongoing access for a time, as the URL target of the iframe changed rapidly to avoid blocking of the delivery sites
    • One of the domains used in the iframe was an internationalized domain name, which translated from russian to my-new-sploit.com
    • The version of the Citadel trojan used in the exploit was only recognized by 3 of the 46 virus scanners on virustotal.com on the date of the attack
    • The infection was also detected on other NBC sites such as latenightwithjimmyfallon.com and jeylenosgarage.com, so it was likely an exploit against the CMS
    • These trusted sites are especially valuable as attack vectors for malware authors, because of their huge traffic volumes and the fact that users expect the large trusted sites to be free of malware or other risk
    • Facebook’s malware scanner detected something was wrong (since iframes of .jar and .pdf files are usually only seen in attacks), and blocked users from posting links to NBC.com (We have discussed Facebook malware scan that is part of their spider that fetches the preview images)
    • The malware was first detected by researchers at 16:43 CET on the 21st, it is unclear how long the injection was on the site before it was discovered
    • The malware was removed from the site by 21:28 CET
    • Researchers Post
    • Additional Coverage

    Bit9’s cloud security app compromised, 32 pieces of malware whitelisted

    • Bit9 is a security company whose main product is an application control software, which basically monitors all of the applications and processes running on a server or end-user device, and reports any unusual activity (applications not on the cloud maintained whitelist)
    • Customers of Bit9 include the US government, banks, oil and energy companies, defence contractors and 30 companies from the Fortune 100 list
    • Attackers managed to compromise one or more virtual machines at the company and gained access to a code signing certificate, subsequently using it to sign 32 pieces of malware, effectively whitelisting them
    • It turns out, due to an “operational oversight” a “handful” of computers at Bit9 did not run Bit9’s own software, so the intrusion was not detected or prevented
    • As such, Bit9 claims that the compromise was not due to a problem with their software
    • Bit9’s investigation suggests that only three of their customers were affected by the illegitimately signed malware
    • Bit9 revoked the certificate that was used to sign the malware (and probably all previously whitelisted binaries, Bit9 claims it was no longer actively using the stolen certificate, but that it was still valid), got a new certificate and resigned the whitelisted apps, and patched their software to blacklist anything signed with the revoked certificate
    • It is interesting to note that the most often touted features of the Bit9 system is that it stops new and unknown malware, because it only allows approved applications to run, the opposite of traditional anti-virus applications, which rely on a blacklist of known malware. In this case, it might have been that the compromised caused Bit9 to allow known malware that would have been stopped by traditional anti-virus to run on the target systems
    • Bit9 is not saying which of its customers were targeted, but based on other information and the list of industries Bit9 said were not targeted, it appears to have been a defence contractor
    • Official Update Announcement
    • Bit9 says the attackers originally compromised their systems in July of 2012 view an SQL injection flaw in software that was running on an internet accessible web server
    • From the web server, the attackers were able to compromise two legitimate user accounts, and eventually use those to access a virtual machine that contains the private keys for the code-signing certificate
    • The virtual machine that was compromised was shut down a few days later, the compromise undetected
    • In January that virtual machine was started again, and the compromise was eventually detected
    • Bit9 says evidence suggests that they were not the ultimate target of the attack, but rather just a stepping stone to eventually compromise one of their customers
    • Bit9’s audit showed that the source code for their software was not accessed or modified
    • The attackers later executed a watering hole attack (similar to the mobile developer forum attack that compromised twitter, facebook, apple and microsoft) against the 3 target Bit9 customers
    • The attack used a java vulnerability to execute the HiKit and Unixhome backdoors, two of the binaries that had been signed with the stolen Bit9 certificate. Rather than these being blocked by Bit9 as intended, because they had been signed by Bit9, they were whitelisted and allowed to run in the highly secured network of the defense contractors
    • Krebs on Security Coverage – Part 1 Part 2
    • Security Ledger coverage

    Oracle issues another emergency Java patch after McRAT exploits new 0-day in the wild

    • The fix covers CVE–2013–1493 and CVE–2013–0809
    • The latter vulnerability is in the colour management system of Java 2D and allows an attack to use a specially crafted image file to execute a memory corruption attack. The attack targets the JVM’s internal data structures and overwrites the areas of memory that control whether the security manager to enabled or not
    • The exploit has been seen in the wild, successful exploited to drop the McRAT trojan
    • The security company that discovered the exploit reported that the McRAT trojan was communicating with the same Command and Control server that was used in an earlier attack against security company Bit9
    • FireEye blog post
    • Additional Coverage
    • The issue was originally reported on February 1st, Oracle claimed that was too late to be included in the February 19th patch. Oracle planned to sit on the update until the next scheduled update in April, but once it was being exploited in the wild they were forced to release this update
    • Java Security bulletin
    • Security Explorations has reported 7 more java vulnerabilities since February 25th
    • Oracle has rejected issue #54 claiming it is not a vulnerability, but the polish firm and US-CERT disagree, Security Explorations has sent additional details and proof of concept to help Oracle understand the vulnerability
    • Oracle has issued tracking numbers for issues #56–60 but clarifies that the issues are not ‘confirmed’ yet
    • This seems to signal an increasing resistance from Oracle and acknowledge and fix the bugs that researchers report, until it is too late and they are being actively exploited

    Feedback

    Round Up:

    The post 100% Uptime | TechSNAP 100 first appeared on Jupiter Broadcasting.

    ]]> Ubuntu & Kubuntu 11.10 Review | LAS | s19e01 https://original.jupiterbroadcasting.net/12858/ubuntu-kubuntu-11-10-review-las-s19e01/ Sun, 16 Oct 2011 14:04:27 +0000 https://original.jupiterbroadcasting.net/?p=12858 Fresh off the mirrors we load up Ubuntu and Kubuntu 11.1 and give you our review for both in this ACTION packed episode!

    The post Ubuntu & Kubuntu 11.10 Review | LAS | s19e01 first appeared on Jupiter Broadcasting.

    ]]>

    post thumbnail

    Fresh off the mirrors we load up Ubuntu and Kubuntu 11.1 and give you our review for both in this ACTION packed episode!

    Plus – We observe the passing of a industry legend, help boost your memory, and give you our take on Richard Stallman’s Steve Jobs comments!

    All this week on, The Linux Action Show!

    Thanks to:

    GoDaddy.com Use our codes LINUX to save 10% at checkout, or LINUX20 to save 20% on hosting!

    Direct Episode Download Links:

    HD Video | Large Video | Mobile Video | MP3 | OGG Audio | OGG Video | WebM Video | YouTube



    [ad#shownotes]

    Show Notes:

    Runs Linux:

    HP’s new Cloud Service, runs Linux!

    Android Pick:

    Universal Pick:

    Picks so far. Thanks to Madjo!

    Linux Action Show Subreddit

    News:
    Kubuntu & Ubuntu 11.10 Review:
    • Ubuntu 11.10 Finds it self in a hard spot. The steady, and very needed improvements in Unity cost them in overall “on the box” bullet points for Ubuntu. Overall, the end result of this release is something that feels much better built than 11.04 did, but there’s no buzz term for you to hang that hat on.
    • Chris suspects this could be an ongoing perception issue for Ubuntu. They have additional work to do on Unity, and that will undoubtly take a great deal of their developer focus. This meas other fancy buzz features might get missed.
    • Perhaps Ubuntu could name, Unity releases. “Ubuntu 12.04 featuring Unity 3”. Then they could focus on all the improvements in that version of Unity that ships with that Ubuntu release.
    • Linux 3.0
    • Gnome 3.2

    Ubuntu 11.10

    Kubuntu 11.10

    Find us on Google+

    Find us on Twitter:

    Follow the network on Facebook:

    Catch the show LIVE Sunday 10am PDT:

    The post Ubuntu & Kubuntu 11.10 Review | LAS | s19e01 first appeared on Jupiter Broadcasting.

    ]]> Digital Brain Upgrade | Jupiter@Nite | 8.31.10 https://original.jupiterbroadcasting.net/2714/digital-brain-upgrade-jupiternite-83110/ Tue, 31 Aug 2010 21:55:58 +0000 https://original.jupiterbroadcasting.net/?p=2714 For the past two weeks Chris and Jeremy have been attempting to use digital storage devices and services to supplement our sometimes spotty memories. Tonight we cover our results!

    The post Digital Brain Upgrade | Jupiter@Nite | 8.31.10 first appeared on Jupiter Broadcasting.

    ]]>

    post thumbnail

    Jeremy have been attempting to use digital storage devices and services to supplement our sometimes spotty memories. Services like Evernote brand themselves as easy-to-use digital memory… but are they really helping?

    We’ll throw down our opinions on the subject, and give you our honest reactions to the experiment. Along the way, we’ll also share some tidbits about how memory works, or doesn’t work, and share some other tips for enhancing your own.

    Show Feeds:

    Tonight’s Show Notes & Download Below:

    Evernote:
    Free iPhone and Android app.  There is also a paid version with more features.
    Can store text notes, pictures, video and audio clips.  For subscribers, you get the ability to search the text within pictures (business cards, for example), and other features.
    Chris’ thoughts:
    • He forgot to update the show notes.

    Jeremy’s thoughts:

    • I’ve already used it for a couple things that I KNOW I never would have remembered to follow up on:
      • Example 1:  A private message from a chatter during a previous show that contained a link.  Instead of asking him to email it to me (like I always do) I just took a picture of the screen and sent it to Evernote.  Done.
      • Example 2:  Angela played an audio clip on a previous FauxShow and I wanted to know the artist cuz it was a good one.  Put it in a text note in Evernote.  Done.
    • Also was a good starting point for remembering some of my article ideas for TenTonHammer.  While putting together my ‘scratch doc’ where I dumped all my ideas, I was able to go back thru my previous audio notes and transcribe many of them directly from my Evernote memory.
    • The audio note is easily my favorite feature, but the iPhone app doesn’t let you append anything to them at a later time.  You can only do that with text.  Some sort of audio-to-text translation would be nice to have.  (in the pay version?)
    • My iPhone also doesn’t successfully play back audio notes, so I have to use the web client.  Dunno what that’s about.
    • Pics taken using the Evernote app don’t turn up in your phone’s photoroll.  For better or worse.
    • You can email notes into your own memory AND OTHER PEOPLEs’, if you know their Evernote email.  So keep yours private, unless you want people inside your brain.
    • A lot of things that I uploaded to Evernote, I would’ve remembered anyway.  Especially by the act of taking the time to upload them.  That tiny extra bit of effort caused the ‘memory’ to leave a stronger impression.
    • It’s not a complete solution.  I still find myself forgetting things that I need to do.  Like make new business cards for PAX.  That keeps slipping my mind.  If I never upload a reminder, I’ll never receive the reminder.
    • Also, you have to remember to go check your storage on occasion in order to see what you thought you should remember.

    Dial2Do — a speech-to-command plugin that works with Evernote (Blackberry/Android only)

    ReQall (video)
    Another free app.  This one specializes in speech-to-text translation.  You call in your reminder, and the service parses it into a To-Do List type of arrangement.

    • If you include a time, it will schedule it to your Calendar.
    • If you include “buy” it sets it up as a shopping list.
    • If you say “tell” or “remind” you can have your notes sent to other people (probably only if they use the service, too).
    • You can also sign up for the premium service (~$50/yr) to send you reminders via text message.

    Bacopa herbal extract

    Download:

    The post Digital Brain Upgrade | Jupiter@Nite | 8.31.10 first appeared on Jupiter Broadcasting.

    ]]>