heartbeat – Jupiter Broadcasting https://www.jupiterbroadcasting.com Open Source Entertainment, on Demand. Mon, 22 Feb 2016 02:45:37 +0000 en-US hourly 1 https://wordpress.org/?v=5.5.3 https://original.jupiterbroadcasting.net/wp-content/uploads/2019/04/cropped-favicon-32x32.png heartbeat – Jupiter Broadcasting https://www.jupiterbroadcasting.com 32 32 Priyanka Sharma | WTR 11 https://original.jupiterbroadcasting.net/76357/priyanka-sharma-wtr-11/ Wed, 28 Jan 2015 03:21:00 +0000 https://original.jupiterbroadcasting.net/?p=76357 Priyanka is a cofounder of Wakatime, a fully automatic time tracking service for programmers! Thanks to: Direct Download: MP3 Audio | OGG Audio | Video | HD Video | YouTube RSS Feeds: MP3 Feed | OGG Feed | iTunes Feed | Video Feed Become a supporter on Patreon: Show Notes: WakaTime is fully automatic time […]

The post Priyanka Sharma | WTR 11 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

Priyanka is a cofounder of Wakatime, a fully automatic time tracking service for programmers!

Thanks to:

Linux Academy

Direct Download:

MP3 Audio | OGG Audio | Video | HD Video | YouTube

RSS Feeds:

MP3 Feed | OGG Feed | iTunes Feed | Video Feed

Become a supporter on Patreon:

Foo

Show Notes:

The post Priyanka Sharma | WTR 11 first appeared on Jupiter Broadcasting.

]]>
Belkin Heartbeat Stops | TechSNAP 183 https://original.jupiterbroadcasting.net/68917/belkin-heartbeat-stops-techsnap-183/ Thu, 09 Oct 2014 18:05:41 +0000 https://original.jupiterbroadcasting.net/?p=68917 The Belkin router apocalypse takes users offline all over the world, Infected ATMs spit out money on cue, plus isolating your network, a great batch of your questions & much, much more! Thanks to: Get Paid to Write for DigitalOcean Direct Download: HD Video | Mobile Video | MP3 Audio | Ogg Audio | YouTube […]

The post Belkin Heartbeat Stops | TechSNAP 183 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

The Belkin router apocalypse takes users offline all over the world, Infected ATMs spit out money on cue, plus isolating your network, a great batch of your questions & much, much more!

Thanks to:


DigitalOcean


Ting


iXsystems

Direct Download:

HD Video | Mobile Video | MP3 Audio | Ogg Audio | YouTube | HD Torrent | Mobile Torrent

RSS Feeds:

HD Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feeds | Torrent Feed

Become a supporter on Patreon:

Foo

— Show Notes: —

Belkin router apocolypse, world wide outage of almost all Belkin routers

  • “Starting approximately midnight on October 7, Belkin began experiencing an issue with a service configured in certain Belkin router models that causes a failure when it checks for general network connectivity by pinging a site hosted by Belkin.”
  • It seems Belkin routers check to see if “the internet is up” by pinging or connecting to heartbeat.belkin.com. When this service went down, all of those routers decided the internet was ‘down’, and stopped letting customers use the Internet, despite the fact that the rest of the Internet was fine
  • “One of our cloud services associated with maintaining router operations was negatively impacted by a change made in our data center that caused a false denial of service. Normal operations were restored by 3PM PST, but some users might still need to reset their router and/or cable modem to regain connectivity. Moving forward, we will continue to monitor, improve and validate the system to ensure our routers continue to work properly in the event connectivity to our cloud environment is not available. “
  • The fact that the routers rely on only a single signal, a response from heartbeat.belkin.com, to determine if the internet is working, seems wrong.
  • Even so, it doesn’t explain why the routers ‘give up’ and stops users accessing the Internet
  • It appears this has to do with the DNS Resolver in the Router, which stops attempting to resolve addresses when it cannot reach the Belkin site. Users to manually change their DNS servers to Google Public DNS or OpenDNS had their service restored
  • What if the Belkin site goes down? (Like it did). What if there is a routing or transit issue? What if access to the Belkin site is blocked in your country?
  • “If your service has not yet been restored, please unplug your router and plug it back in after waiting 1 minute. Wait 5 more minutes and the router should reconnect.”
  • There were rumours that this issue was caused by a firmware update. Belkin denies this, although it is not clear if they had pushed a firmware update around the same time or not
  • Interesting: Apparently Belkin’s call center got a high volume of calls. How many users call their Router manufacturer when they have an issue, rather than their ISP? My Cisco router/modem only had my ISPs phone number on it.
  • Belkin Status Page
  • Belkin Community Forums
  • Additional Coverage: Internet Storm Center

Infected ATMs spit out money on queue, without debiting anyones bank account

  • “What do you need in order to withdraw cash from an ATM?”
  • First, you need to have a debit or credit card, which acts as a key to your bank account
  • Second, you must know the PIN code associated with the card; otherwise, the bank wouldn’t approve the transaction.
  • Finally, you need to have some money in your account that you can withdraw.
  • Or, you just need a bootable CD
  • “However, hackers do things differently: they don’t need cards, PIN codes or bank accounts to get money. In reality, all they need is an ATM with some cash in it and a special piece of software.”
  • “criminals were somehow able to physically access the ATMs so that they could install the malware via a bootable CD on an embedded Windows machine”
  • “The trojan that was used had complex abilities. First, when activated inside of the ATM, it had the ability to turn off the McAfee Solidcare AV software so that it could do its job with ease”
  • “Second, to avoid accidental detection, Tyupkin trojan had the ability to stay in a standby mode for an entire week and activate only Sunday and Monday nights.”
  • “Third, it had the ability to disable the local network in the case of an emergency, so that the bank could not remotely connect to the ATM to check on what was happening with it.”
  • “All an attacker has to do is merely approach an infected ATM and enter a special PIN code in order to access the secret menu that will allow him to make cash withdrawals or control the trojan (for example, to delete it).”
  • “To make a withdrawal the person has to know the appropriate commands, as well as a special formula that will calculate a session key — some kind of a two-factor authentication. If both codes are correct, then a second menu will appear that allows the criminal to choose the cassette number and make a withdrawal.”
  • “Although one can only dispense 40 banknotes per transaction, it’s possible to dispense any amount of money by simply performing the actions several times over.”

Pair arrested for exploiting flaw in Casino slot machines

  • John Kane, a gambling addict, and an accomplice, Andre Nestor, exploited a bug in Game King video poker slot machines
  • “It turned out the Game King’s endless versatility was also its fatal flaw. In addition to different game variants, the machine lets you choose the base level of your wagers: At the low-limit Fremont machines, you could select six different denomination levels, from 1 cent to 50 cents a credit”
  • “The key to the glitch was that under just the right circumstances, you could switch denomination levels retroactively. That meant you could play at 1 cent per credit for hours, losing pocket change, until you finally got a good hand—like four aces or a royal flush. Then you could change to 50 cents a credit and fool the machine into re-awarding your payout at the new, higher denomination. “
  • “Performing that trick consistently wasn’t easy—it involved a complicated misdirection that left the Game King’s internal variables in a state of confusion. But after seven hours rooted to their seats, Kane and Nestor boiled it down to a step-by-step recipe that would work every time. “
  • It turns out John Kane was very familiar with the slot machine in question:
  • “he blew half a million dollars in 2006 alone—a pace that earned him enough Player’s Club points to pay for his own Game King to play at his home on the outskirts of Vegas, along with technicians to service it. (The machine was just for fun—it didn’t pay jackpots.)“ He’s played more than anyone else in the United States, says his lawyer, Andrew Leavitt. I’m not exaggerating or embellishing. It’s an addiction.”
  • Game King 5.0 was released in 2002, however it contained a series of subtle errors in program number G0001640 that evaded laboratory testing and source code review.
  • “The bug survived like a cockroach for the next seven years. It passed into new revisions, one after another, ultimately infecting 99 different programs installed in thousands of IGT machines around the world. As far as anyone knows, it went completely undetected until late April 2009, when John Kane was playing at a row of four low-limit Game Kings outside the entrance to a Chinese fast food joint”
  • “Kane had some idea of how the glitch operated but hadn’t been able to reliably reproduce it. Working together, the two men began trying different combinations of play, game types, and bet levels, sounding out the bug like bats in the dark.”
  • The pair eventually sorted out the details, and managed to get more than $750,000 out of various slot machines before being arrested

Feedback:


Round up:


The post Belkin Heartbeat Stops | TechSNAP 183 first appeared on Jupiter Broadcasting.

]]>
Certified Package Delivery | BSD Now 33 https://original.jupiterbroadcasting.net/55382/certified-package-delivery-bsd-now-33/ Thu, 17 Apr 2014 18:59:10 +0000 https://original.jupiterbroadcasting.net/?p=55382 We sit down with Jim Brown from the BSD Certification group to talk about the BSD exams. Following that, we\’ll be showing you how to build OpenBSD binary packages in bulk, a la poudriere. There\’s a boatload of news and we\’ve got answers to your questions, coming up on BSD Now – the place to […]

The post Certified Package Delivery | BSD Now 33 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

We sit down with Jim Brown from the BSD Certification group to talk about the BSD exams. Following that, we\’ll be showing you how to build OpenBSD binary packages in bulk, a la poudriere. There\’s a boatload of news and we\’ve got answers to your questions, coming up on BSD Now – the place to B.. SD.

Thanks to:


\"iXsystems\"

Direct Download:

Video | HD Video | MP3 Audio | OGG Audio | Torrent | YouTube

RSS Feeds:

MP3 Feed | OGG Feed | iTunes Feed | Video Feed | HD Vid Feed | HD Torrent Feed

– Show Notes: –

Headlines

BSDCan schedule, speakers and talks

  • This year\’s BSDCan will kick off on May 14th in Ottawa
  • The list of speakers is also out
  • And finally the talks everyone\’s looking forward to
  • Lots of great tutorials and talks, spanning a wide range of topics of interest
  • Be sure to come by so you can and meet Allan and Kris in person and get BSDCan shirts

NYCBSDCon talks uploaded

  • The BSD TV YouTube channel has been uploading recordings from the 2014 NYCBSDCon
  • Jeff Rizzo\’s talk, \”Releasing NetBSD: So Many Targets, So Little Time\”
  • Dru Lavigne\’s talk, \”ZFS Management Tools in FreeNAS and PC-BSD\”
  • Scott Long\’s talk, \”Serving one third of the Internet via FreeBSD\”
  • Michael W. Lucas\’ talk, \”BSD Breaking Barriers\”

FreeBSD Journal, issue 2

  • The bi-monthly FreeBSD journal\’s second issue is out
  • Topics in this issue include pkg, poudriere, the PBI format, hwpmc and journaled soft-updates
  • In less than two months, they\’ve already gotten over 1000 subscribers! It\’s available on Google Play, iTunes, Amazon, etc
  • \”We are also working on a dynamic version of the magazine that can be read in many web browsers, including those that run on FreeBSD\”
  • Check our interview with GNN for more information about the journal

OpenSSL, more like OpenSS-Hell

  • We mentioned this huge OpenSSL bug last week during all the chaos, but the aftermath is just as messy
  • There\’s been a pretty vicious response from security experts all across the internet and in all of the BSD projects – and rightfully so
  • We finally have a timeline of events
  • Reactions from ISC, PCBSD, Tarsnap, the Tor project, FreeBSD, NetBSD, oss-sec, PHK, Varnish and Akamai
  • pfSense released a new version to fix it
  • OpenBSD disabled heartbeat entirely and is very unforgiving of the IETF
  • Ted Unangst has two good write-ups about the issue and how horrible the OpenSSL codebase is
  • A nice quote from one of the OpenBSD lists: \”Given how trivial one-liner fixes such as #2569 have remained unfixed for 2.5+ years, one can only assume that OpenSSL\’s bug tracker is only used to park bugs, not fix them\”
  • Sounds like someone else was having fun with the bug for a while too
  • There\’s also another OpenSSL bug that\’s possibly worse that OpenBSD patched – it allows an attacker to inject data from one connection into another
  • OpenBSD has also imported the most current version of OpenSSL and are ripping it apart from the inside out – we\’re seeing a fork in real time (over 55000 lines of code removed as of yesterday evening)

Interview – Jim Brown – info@bsdcertification.org

The BSD Certification exams


Tutorial

Building OpenBSD binary packages in bulk


News Roundup

Portable signify

  • Back in episode 23 we talked with Ted Unangst about the new \”signify\” tool in OpenBSD
  • Now there\’s a (completely unofficial) portable version of it on github
  • If you want to verify your OpenBSD sets ahead of time on another OS, this tool should let you do it
  • Maybe other BSD projects can adopt it as a replacement for gpg and incorporate it into their base systems

Foundation goals and updates

  • The OpenBSD foundation has reached their 2014 goal of $150,000
  • You can check their activities and goals to see where the money is going
  • Remember that funding also goes to OpenSSH, which EVERY system uses and relies on everyday to protect their data
  • The FreeBSD foundation has kicked off their spring fundraising campaign
  • There\’s also a list of their activities and goals available to read through
  • Be sure to support your favorite BSD, whichever one, so they can continue to make and improve great software that powers the whole internet

PCBSD weekly digest

  • New PBI runtime that fixes stability issues and decreases load times
  • \”Update Center\” is getting a lot of development and improvements
  • Lots of misc. bug fixes and updates

Feedback/Questions


  • All the tutorials are posted in their entirety at bsdnow.tv – there\’s a couple new ones on the site now that we\’ll be covering in future episodes
  • Send questions, comments, show ideas/topics, or stories you want mentioned on the show to feedback@bsdnow.tv
  • If you\’ve got something cool to talk about and want to come on for an interview, shoot us an email
  • Also if you have any tutorial requests, we\’d be glad to show whatever the viewers want to see
  • If you\’re in or around Colorado in the US, there\’s a brand new BSD users group that was just formed and announced – they\’ll be having meetings and doing tutorials, so check out their site (also, if you have a local BUG, let us know!)
  • Watch live Wednesdays at 2:00PM Eastern (18:00 UTC)

The post Certified Package Delivery | BSD Now 33 first appeared on Jupiter Broadcasting.

]]>