RAR – Jupiter Broadcasting https://www.jupiterbroadcasting.com Open Source Entertainment, on Demand. Mon, 22 Feb 2016 02:47:03 +0000 en-US hourly 1 https://wordpress.org/?v=5.5.3 https://original.jupiterbroadcasting.net/wp-content/uploads/2019/04/cropped-favicon-32x32.png RAR – Jupiter Broadcasting https://www.jupiterbroadcasting.com 32 32 SSH Authentication with YubiKey | LAS 373 https://original.jupiterbroadcasting.net/85062/ssh-authentication-with-yubikey-las-373/ Sun, 12 Jul 2015 17:33:29 +0000 https://original.jupiterbroadcasting.net/?p=85062 Take your Linux logins up to the next level with YubiKey. YubiKeys support one-time passcode, smart card & more – enabling one security key to an unlimited number of applications. Today we’ll show you how to make it work with SSH under Linux. Plus our thoughts on the NSA using Red Hat, the big changes […]

The post SSH Authentication with YubiKey | LAS 373 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

Take your Linux logins up to the next level with YubiKey. YubiKeys support one-time passcode, smart card & more – enabling one security key to an unlimited number of applications. Today we’ll show you how to make it work with SSH under Linux.

Plus our thoughts on the NSA using Red Hat, the big changes coming to openSUSE, our picks & more!

Thanks to:


\"DigitalOcean\"


\"Ting\"

Direct Download:

HD Video | Mobile Video | WebM Torrent | MP3 Audio | OGG Audio | YouTube | HD Torrent

RSS Feeds:

HD Video Feed | Large Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feed | Torrent Feed

Become a supporter on Patreon:

\"Foo\"

— Show Notes: —

Setting up a Yubikey with Linux


\"OSCON\"

Brought to you by: O’REILLY OSCON

Getting started with Yubikey

Introducing the YubiKey Nano – YouTube

Install Yubikey Support in Linux

sudo apt-get install opensc

sudo apt-add-repository ppa:yubico/stable

sudo apt-get install yubico-piv-tool

yubico-piv-tool -s 9a -a generate -o public.pem

yubico-piv-tool -a verify-pin -P 123456 -a selfsign-certificate -s 9a
-S \"/CN=SSH key/\" -i public.pem -o cert.pem

yubico-piv-tool -a import-certificate -s 9a -i cert.pem

ssh-keygen -D $OPENSC_LIBS/opensc-pkcs11.so

ssh -I $OPENSC_LIBS/opensc-pkcs11.so user@remote.example.com

Change Pin

yubico-piv-tool -a change-pin -P 123456 -N TheNewPinHere

yubico-piv-tool -a change-puk -P 12345678 -N TheNewPinHere

Edit SSH Client to look for Yubikey

vi /etc/ssh/ssh_config

Append the line For Ubuntu

PKCS11Provider /usr/lib/x86_64-linux-gnu/opensc-pkcs11.so

Get Key

ssh-keygen -D /usr/lib/x86_64-linux-gnu/opensc-pkcs11.so

For Ubuntu 32bit

PKCS11Provider /usr/lib/i386-linux-gnu/opensc-pkcs11.so

For Arch

PKCS11Provider /usr/lib/opensc-pkcs11.so

For Fedora

PCKS11Provider /usr/lib64/opensc-pkcs11.so

— PICKS —

Runs Linux

Vizzy will be a personal assistant robot, designed to teach exercise routines and provide physical therapy support, while also ensuring proper exercise form and monitoring physiological responses. So, much like human personal trainers, Vizzy will encourage users to keep exercising, even when they say they are tired.

Portuguese Robotics research is poised to become a reference in the field with the creations like Vizzy, a personal training robot created in the scope of one of the Entrepreneurial Research Initiatives of the Carnegie Mellon Portugal Program.
Vizzy will be a personal assistant robot, designed to teach exercise routines and provide physical therapy support, while also ensuring proper exercise form and monitoring physiological responses. This will be accomplished with its motion detectors that, much like the technology currently present in gaming consoles, is able to read the user’s body positioning. But Vizzy will also be able to detect other responses, such as body temperature and breathing pattern to gauge the user\’s physical reaction to the routine and adjusting it accordingly. So, much like human personal trainers, Vizzy will encourage users to keep exercising, even when they say they are tired.

Vizzy is under development within the “AHA – Augmented Human Assistance” project, lead by Profs. Alexandre Bernardino (IST) and Daniel P. Siewiorek (CMU). AHA is one of the six selected proposals of the CMU Portugal Program Entrepreneurial Research Initiative in 2014.

Desktop App Pick

PeaZip is a sleek open source file and archive manager that supports a wide array of compression and encryption standards. It provides many helpful security features such as two-factor authentication, secure deletion, checksum and hash verification and WinZip\’s, PKZip\’s and 7\’s AES256 encryption, to name a few. PeaZip is a simple, sleek feature packed archive manager I recommend for any desktop.

Weekly Spotlight

  • Hydrogen Rythem Sequencer

  • Pattern-based sequencer, with unlimited number of patterns and ability to chain patterns into a song.

  • Up to 192 ticks per pattern with individual level per event and variable pattern length.
  • Unlimited instrument tracks with volume, mute, solo, pan capabilities.
  • Multi layer support for instruments (up to 16 samples for each instrument).
  • Sample Editor, with basic cut and loop functions. (NEW)
  • Time-stretch and pitch functions via rubberband cli. Require the rubberband-cli package. (NEW)
  • Play-lists with scripting function. (NEW)
  • Advanced tab-tempo. (NEW)
  • Director Window with a visual metronome and song position tags. (NEW)
  • Time-line with variable tempo. (NEW)
  • Single and stacked pattern mode. (NEW)
  • Export/Import single patterns into song projects. (NEW)
  • Midi learning via Shift+MouseClick on many gui-cotrollers combined with a midi settings editor. *(NEW)
  • Ability to import/export song files.
  • Unique human velocity, human time, pitch and swing functions.
  • Multiple patterns playing at once.

— NEWS —

RedHat used by NSA Spies

Rebasing openSUSE

  • openSUSE Stuck in the middle: https://youtu.be/BH99TSrfvq0?t=6m33s

  • OBS is getting SLE Sources, and MX fixed: https://youtu.be/BH99TSrfvq0?t=11m6s

Canonical partners with Lenovo to launch Ubuntu-powered ThinkPad L450 laptops in India

As for the specs of the ThinkPad L450 series, users have the choice of Intel Core i3 and i5 processors, paired with AMD Radeon R5 M240 2GB VRAM Intel HD 5500 GPU, 4GB of RAM, and 500GB hard drives. The laptops sport a 14-inch display with HD (1,280 x 720) screen resolution.

VirtualBox 5.0 final available

2 Months after the Beta 3 release Oracle has announced that Oracle VM VirtualBox 5.0 is available today. The guest OS performance has been improved by leveraging built-in virtualization support.

Feedback:

Linux Academy

Chris’s Twitter account has changed, you’ll need to follow!

Chris Fisher (@ChrisLAS) | Twitter

— CHRIS\’ STASH —

Hang in our chat room:

irc.geekshed.net #jupiterbroadcasting

— NOAH\’S STASH —

Noah\’s Day Job

Altispeed Technologies

Contact Noah

noah [at] jupiterbroadcasting.com

Find us on Google+

Find us on Twitter

Follow us on Facebook

Catch the show LIVE Sunday 10am Pacific / 1pm Eastern / 6pm UTC:

The post SSH Authentication with YubiKey | LAS 373 first appeared on Jupiter Broadcasting.

]]>
Faster GPU Cracking | TechSNAP 65 https://original.jupiterbroadcasting.net/21306/faster-gpu-cracking-techsnap-65/ Thu, 05 Jul 2012 16:45:55 +0000 https://original.jupiterbroadcasting.net/?p=21306 Everyone's beloved password cracker has a major update, you won’t believe what it can do now! Plus we share some infrastructure wisdom.

The post Faster GPU Cracking | TechSNAP 65 first appeared on Jupiter Broadcasting.

]]>

post thumbnail

Everyone’s beloved password cracker has had a major update, and you won’t believe what it can do now!

The Aerospace industry has a new Advanced Persistent Threat, and a major Microsoft XML flaw already being exploited.

Plus we share some infrastructure wisdom in today’s feedback segment.

All that and more, on this week’s TechSNAP!

Thanks to:

Use our codes TechSNAP10 to save 10% at checkout, or TechSNAP20 to save 20% on hosting!

Limited time offers:

$1.99/mo economy hosting for 3 months – special offer!
Code:  199tech
Expires:  June 30, 2012

$3.99 .US domain!
Code:  399us4

Direct Download:

HD Video | Mobile Video | MP3 Audio | Ogg Audio | YouTube | HD Torrent | Mobile Torrent

RSS Feeds:

HD Video Feed | Mobile Video Feed | MP3 Audio Feed | Ogg Audio Feed | iTunes Feeds | Torrent Feed

 

Support the Show:

   

Show Notes:

New version of John the Ripper targets slow hashes with GPUs

  • The new version focuses on adding GPU support, both CUDA (for nVidia) and OpenCL (for AMD and other cards)
  • Other interesting new additions:
  • Non-hash cracking support for:
    • Mac OS X keychains
    • KeePass 1.x files
    • ODF and MS Office 2007/2010 files
    • Mozilla Firefox/Thunderbird/etc master password files
    • RAR -p and -hp encryption modes
    • WPA-PSK
    • VNC Challenge/response auth
    • SIP challenge/response auth
    • HMAC-SHA1/224/256/384/512
  • New hashes supported:
  • sha256crypt (CPU or CUDA)
  • sha512crypt (CPU/CUDA/OpenCL)
  • DragonFly BSD SHA256/512
  • Drupal 7 custom PHP SHA–256 hashes
  • Raw-SHA1-LinkedIn
  • Interestingly, bcrypt (OpenBSDs implementation of blowfish as a password hashing algorithm), even on an AMD 7970, is slower on a GPU than a CPU due to the nature of the algorithm
  • Full Release Announcement

Unpatched Microsoft XML exploit added to Blackhole toolkit

  • An exploit for the unpatched vulnerability is now included in recent versions of the blackhole exploit kit, sold to cyber criminals and installed on infected and compromised websites across the internet
  • Numerous attack vectors have been used to exploit this flaw in the Microsoft XML engine, including MS Office documents, Flash, and Internet Explorer it self
  • The flaw is present in versions 3, 4 and 6 of MS XML Core Services, and exploitable on all supported versions of windows (XP/Vista/7, 2003/2008/R2 Server)
  • Microsoft published the advisory about the flaw on June 12th, after it was already actively being exploited in the wild
  • At this time, there is still not a fix for ‘Microsoft XML Core Services’, however Microsoft offers a ‘Fix-It’ that is supposed to mitigate the flaw, but suggests that this may cause application compatibility issues
  • The Microsoft EMET Toolkit may prevent the exploitation of this vulnerability, but as discussed previously, is incompatible with AMD Video Drivers
  • CVE–2012–1889
  • Official Microsoft Announcement

New version of trojan used in highly targetted attack

  • The Sykipot trojan is not new, however the latest version is being used more successfully than before
  • Phishing emails and targeted web advertisements are being used to drive users to sites where they are infected by drive-by-downloading of the trojan using the MS XML exploit
  • This requires zero user interaction in order to become infected
  • Previous versions of Sykipot have relied on file format exploits (MS Office files, PDFs)
  • The latest attack seems to be targeting attendees to the IEEE’s Aerospace Conference (the International Conference for Aerospace Experts, Academics, Military Personnel, and Industry Leaders)
  • Researchers have found a Sykipot variant that was programmed to steal credentials from systems using ‘ActivIdentity’s ActivClient’, the smart card application used by the U.S. Department of Defense’s Common Access Card (CAC)
  • This could result in the compromise of such smart cards, allowing the attack to gain access to highly sensitive materials

A third of top UK Univerisities use weak SSL configurations

  • TechWeek Europe used the SSL Labs tool to test the SSL implementations used at the top Univertisities in the UK
  • Many of the schools received grades of C or D instead of the expected A
  • Such weakness in the implementation of SSL could allow an attacker to inject data into encrypted packets, in order to exploit the user’s machine while they are visiting a trusted site, or to hijack the session or compromise other private data
  • Many of the schools responded quickly with configuration changes to upgrade their scores, while others were hesitant to make configuration changes for fear of affecting accessibility for users
  • SSL Best Practices Guide
  • ScaleEngine.com ‘s Results

Feedback:

Round Up:

The post Faster GPU Cracking | TechSNAP 65 first appeared on Jupiter Broadcasting.

]]>