Re: [PLUG] Vulnerable Hardware

2015-03-09 Thread Fred James
Paul Heinlein wrote: > On Mon, 9 Mar 2015, Tim wrote: > >> Here's a related issue, but far far worse than Seagate/TLS issues: >> >> http://googleprojectzero.blogspot.com/2015/03/exploiting-dram-rowhammer-bug-to-gain.html >> >> >> >> Thanks hardware companies for making it impossible to provide

Re: [PLUG] Vulnerable Hardware (was: Internet of Exploitable Things (was Seagate NAS))

2015-03-09 Thread Tim
> So all you need to do is carry around an ECC-equipped desktop or server > (along with cables, monitor, keyboard, pointing device) and you're secure. > Simple fix! =) Well... Not quite. ECC helps, for sure. But if you read the first security-oriented paper on row hammer (linked to in the on

Re: [PLUG] Vulnerable Hardware (was: Internet of Exploitable Things (was Seagate NAS))

2015-03-09 Thread Paul Heinlein
On Mon, 9 Mar 2015, Tim wrote: Here's a related issue, but far far worse than Seagate/TLS issues: http://googleprojectzero.blogspot.com/2015/03/exploiting-dram-rowhammer-bug-to-gain.html Thanks hardware companies for making it impossible to provide local security on any PC with any OS! TFA

[PLUG] Vulnerable Hardware (was: Internet of Exploitable Things (was Seagate NAS))

2015-03-09 Thread Tim
Here's a related issue, but far far worse than Seagate/TLS issues: http://googleprojectzero.blogspot.com/2015/03/exploiting-dram-rowhammer-bug-to-gain.html Thanks hardware companies for making it impossible to provide local security on any PC with any OS! tim _

Re: [PLUG] denyhosts not blocking some IPs with failed ssh root logins

2015-03-09 Thread Galen Seitz
On 01/15/15 13:32, Paul Heinlein wrote: > On Wed, 14 Jan 2015, Galen Seitz wrote: > >> Hi, >> >> Is anyone else seeing problems with denyhosts not blocking some failed >> logins? This popped up in last night's logwatch: > > Galen, > > I've largely ditched DenyHosts for Fail2ban, but I saw similar