4476
Seems like a big stretch there.-Renegade (November 25, 2012, 06:54 AM)

MS wants the average user to forget about traditional computing and desktop apps - they want users to get used to the new WinRT interface - that is where they see their profit both on hardware and in the cloud.-Carol Haynes (November 25, 2012, 06:59 AM)
I am seeing a lot of businesses looking at Microsoft suspiciously and wondering if there is longer term security with Apple.-Carol Haynes (November 25, 2012, 06:59 AM)

Why I Use Generic Computers and Open Source Software
posted by Howard Fosdick on Sat 24th Nov 2012 17:52 UTC
IconDo you depend on your computer for your living? If so, I'm sure you've thought long and hard about which hardware and software to use. I'd like to explain why I use generic "white boxes" running open source software. These give me a platform I rely on for 100% availability. They also provide a low-cost solution with excellent security and privacy.
People's requirements vary, so what I use may not be the best choice for you. I'm a support person for databases and operating systems. I also do consulting that involves research, presenting, and writing. I use my own computers and work from home. This article is about desktops and laptops, not handheld devices.
.
.
.

Heh. Finally the year of the linux desktop, eh?
Don't kind yourselves that linux hasn't been massively exploited before, it has - the really juicy exploits are kept pretty private, though, since it's just so much more valuable being able to penetrate select targets rather than getting a (very) few zombie nodes...-f0dder (November 24, 2012, 03:23 PM)

It will be dealt with.-40hz (November 24, 2012, 12:18 PM)
As long as it's not dealt with by "Symantec Norton Security Suite for Linux".
Please?-mwb1100 (November 24, 2012, 01:11 PM)



Conclusion
Considering that this rootkit was used to non-selectively inject iframes into nginx webserver responses, it seems likely that this rootkit is part of a generic cyber crime operation and not a targeted attack. However, a Waterhole attack, where a site mostly visited from a certain target audience is infected, would also be plausible. Since no identifying strings yielded results in an Internet search (except for the ksocket library), it appears that this is not a modification of a publicly available rootkit. Rather, it seems that this is contract work of an intermediate programmer with no extensive kernel experience, later customized beyond repair by the buyer.
Although the code quality would be unsatisfying for a serious targeted attack, it is interesting to see the cyber-crime-oriented developers, who have partially shown great skill at developing Windows rootkits, move into the Linux rootkit direction. The lack of any obfuscation and proper HTTP response parsing, which ultimately also led to discovery of this rootkit, is a further indicator that this is not part of a sophisticated, targeted attack.
Based on the Tools, Techniques, and Procedures employed and some background information we cannot publicly disclose, a Russia-based attacker is likely. It remains an open question regarding how the attackers have gained the root privileges to install the rootkit. However, considering the code quality, a custom privilege escalation exploit seems very unlikely.
What I think is the most important is the fourth one: To revive disappearing expertise.+1-40hz (November 24, 2012, 08:16 AM)
But wouldn't it be mandatory to have at least 1 team-member under the age of 50
If only to motivate potential students, for not having to work with people as old as their grandparents(though nothing is wrong with that, IMHO)
-Ath (November 24, 2012, 08:50 AM)
Good point!


I guess I'm just too lazy for all this stuff. I'll just buy a new keyboard every six years...
Given my lack of mechanical intuition for me the loss of time plus frustration and risk of mistakes outweighs 30 bucks every half decade.-TaoPhoenix (November 23, 2012, 05:13 PM)



I don't really think it's ever going to be the bonanza some are expecting it to be.-40hz (November 23, 2012, 10:54 AM)
I thought the bonanza was going to come from businesses upgrading to Win7: "Microsoft aims to herd 70% of enterprise onto Windows 7 by mid-2013"-dr_andus (November 23, 2012, 12:53 PM)

my company's IT people are calling it 'job security' for the next two years.-Gwen7 (November 23, 2012, 10:33 AM)

scattered across several car hoods-Stoic Joker (November 23, 2012, 08:39 AM)


Yeah, the first time I tried it, I don't think it even ran. The last time, it ran, but with a few caveats. I'm chewing turkey at the in-laws for the nonce, so can't say what at the moment, though my foggy memory recalls it something to do with 32-bit, and I see they have a 64 bit build available now.-Edvard (November 22, 2012, 12:05 PM)

I think we need a link to it here.-Stoic Joker (November 22, 2012, 08:51 AM)

)

And regarding the Windows 8 is poised at the brink of enslaving us in a gilded cage which will turn us all into palpitating porridge based eye puppets crap ... Can we at least try to keep in mind that this is totally conjecture. Nothing is or has been proven or verified as fact. No internal secret memos have been exposed substantiating any of these claims ... It's total assumption pure and simple.-Stoic Joker (November 21, 2012, 01:38 PM)

Nah, because that's not as much fun as visiting Iraq and Afghanistan claiming to look for a guy being actively protected by the Pakistani Government. (Isn't it amazing how fast THAT became old news, after years of "Staying the Course?")-TaoPhoenix (November 21, 2012, 08:34 AM)