<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Phocean.net &#187; Defense</title>
	<atom:link href="http://www.phocean.net/category/security/defense/feed" rel="self" type="application/rss+xml" />
	<link>http://www.phocean.net</link>
	<description>Crusing for Knowledge, Drifting towards Security</description>
	<lastBuildDate>Thu, 02 Sep 2010 13:57:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Books review</title>
		<link>http://www.phocean.net/2010/05/16/books-review.html</link>
		<comments>http://www.phocean.net/2010/05/16/books-review.html#comments</comments>
		<pubDate>Sun, 16 May 2010 16:16:46 +0000</pubDate>
		<dc:creator>JC</dc:creator>
				<category><![CDATA[Defense]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Book]]></category>
		<category><![CDATA[Review]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=862</guid>
		<description><![CDATA[I just finished reading two electronic books I bought from O&#8217;reilly. Here is a short review on them. Hacking: the next generation The purpose of this book is to give to the readers an overview of the most common attacks nowadays. It covers all fields : social engineering, web attacks, networking, etc. It was easy [...]]]></description>
			<content:encoded><![CDATA[<p>I just finished reading two electronic books I bought from O&#8217;reilly. Here is a short review on them.</p>
<h4>Hacking: the next generation</h4>
<p><a title="Hacking: the next generation" href="http://oreilly.com/catalog/9780596154585/" target="_blank"><img class="aligncenter size-full wp-image-863" title="hacking_next_gen" src="http://www.phocean.net/wp-content/uploads/2010/05/hacking_next_gen.gif" alt="" width="180" height="236" /></a></p>
<p>The purpose of this book is to give to the readers an overview of the most common attacks nowadays. It covers all fields : social engineering, web attacks, networking, etc.<br />
It was easy to read : the authors are straight to the point and their sentences are clear.</p>
<p>I especially appreciated their state of art about XSS and CSRF attacks. It is certainly the best I have read so far, greatly illustrated with exciting and real case studies.</p>
<p>On the other hand,  I quickly passed over the networking stuff (both wired and wireless). It was too basic and didn&#8217;t show anything new &#8211; maybe it is because I specialize in those fields.</p>
<p>Anyway, globally, I strongly recommend this book. It is worth while your money if you want to know more on web attacks or to have a good overview of modern threats.</p>
<h4>Beautiful Security</h4>
<p><a title="Beautiful Security" href="http://oreilly.com/catalog/9780596527488/" target="_blank"><img class="aligncenter size-full wp-image-864" title="beautiful_sec" src="http://www.phocean.net/wp-content/uploads/2010/05/beautiful_sec.gif" alt="" width="180" height="236" /></a></p>
<p>This is a collection of essays by some of the best security experts and hackers.</p>
<p>Well, I won&#8217;t go around, I have been quite disappointed by this book. The overall lacks coherence and after a while you start wondering what this book is trying to demonstrate. At the end, there is a crual lack of connection between the essays and it globally makes it appear very confusing.</p>
<p>It also sometimes lacks technical references and the writing style is too verbose, too literal for a technical book to be attractive.</p>
<p>There are however some good essays, like one about PGP (by Philip Zimmermann himself, though). It is hard to find some good and complete documentation about it, and this essay is definitely a good one, which I will probably read again when I feel the need of it.</p>
<p>But I wouldn&#8217;t recommend this book only for this short piece of writing. Lack of cohesion, too much litterature and not enough technical stuff actually bored me, though that&#8217;s just my personal taste.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2010/05/16/books-review.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Simulated massive cyber attack filmed by CNN</title>
		<link>http://www.phocean.net/2010/02/18/simulated-massive-cyber-attack-filmed-by-cnn.html</link>
		<comments>http://www.phocean.net/2010/02/18/simulated-massive-cyber-attack-filmed-by-cnn.html#comments</comments>
		<pubDate>Thu, 18 Feb 2010 07:32:10 +0000</pubDate>
		<dc:creator>JC</dc:creator>
				<category><![CDATA[Defense]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Attack]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=719</guid>
		<description><![CDATA[This video, while &#8220;amusing&#8221;, is quite interesting : Though not many details are given, I am quite skeptical about the possibility of such a massive attack. However, it shows well that security is not just a technical matter. It has many implications in law, politics, economics, and a whole information system must be prepared to [...]]]></description>
			<content:encoded><![CDATA[<p>This video, while &#8220;amusing&#8221;, is quite interesting :</p>
<p style="text-align: center;"><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://www.youtube.com/v/PJ0_Km7_s8I&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;hl=en_US&amp;feature=player_embedded&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/PJ0_Km7_s8I&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;hl=en_US&amp;feature=player_embedded&amp;fs=1" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>Though not many details are given, I am quite skeptical about the possibility of such a massive attack.</p>
<p>However, it shows well that security is not just a technical matter. It has many implications in law, politics, economics, and a whole information system must be prepared to that, starting with our leaders.</p>
<p>That would be a HUGE effort for our politicians here in France &#8211; if they ever care&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2010/02/18/simulated-massive-cyber-attack-filmed-by-cnn.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Netios 0.73</title>
		<link>http://www.phocean.net/2010/02/10/netios-0-73.html</link>
		<comments>http://www.phocean.net/2010/02/10/netios-0-73.html#comments</comments>
		<pubDate>Wed, 10 Feb 2010 14:51:59 +0000</pubDate>
		<dc:creator>JC</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Defense]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[Scripts, Programs]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[netios]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=710</guid>
		<description><![CDATA[Netios 0.73 fixes some bugs and Complete changelog : 2010-02-10  (0.73) Jean-Christophe Baptiste &#60;jc@phocean.net&#62; * remove useless options * fix various bugs Check there (tools page) for more details and a download link.]]></description>
			<content:encoded><![CDATA[<p>Netios 0.73 fixes some bugs and</p>
<p>Complete changelog :</p>
<blockquote><p>2010-02-10  (0.73) Jean-Christophe Baptiste &lt;jc@phocean.net&gt;</p>
<p>* remove useless options<br />
* fix various bugs</p></blockquote>
<p><a title="Netios" href="http://www.phocean.net/tools/netios">Check there</a> (tools  page) for more details and a download link.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2010/02/10/netios-0-73.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Netios 0.72</title>
		<link>http://www.phocean.net/2010/01/15/netios-0-72.html</link>
		<comments>http://www.phocean.net/2010/01/15/netios-0-72.html#comments</comments>
		<pubDate>Fri, 15 Jan 2010 10:20:55 +0000</pubDate>
		<dc:creator>JC</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Defense]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[Scripts, Programs]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[netios]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=683</guid>
		<description><![CDATA[Netios 0.72 fixes some bugs with the show_run mode and large config files. I also found some issues concerning the prompt detection, so it should be fixed now. Complete changelog : 2010-01-14  (0.72) Jean-Christophe Baptiste &#60;jc@phocean.net&#62; * ciscoclass.py : forgot to remove a debug print * ciscoclass.py : finish and fix a bunch of bugs [...]]]></description>
			<content:encoded><![CDATA[<p>Netios 0.72 fixes some bugs with the show_run mode and large config files. I also found some issues concerning the prompt detection, so it should be fixed now.</p>
<p>Complete changelog :</p>
<blockquote><p>2010-01-14  (0.72) Jean-Christophe Baptiste &lt;jc@phocean.net&gt;</p>
<p>* ciscoclass.py : forgot to remove a debug print<br />
* ciscoclass.py : finish and fix a bunch of bugs in the show run function, format the config file properly<br />
* ciscoclass.py : fix the prompt regex</p></blockquote>
<p><a title="Netios" href="http://www.phocean.net/tools/netios">Check there</a> (tools page) for more details and a download link.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2010/01/15/netios-0-72.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Netios 0.71</title>
		<link>http://www.phocean.net/2009/12/20/netios-0-71.html</link>
		<comments>http://www.phocean.net/2009/12/20/netios-0-71.html#comments</comments>
		<pubDate>Sun, 20 Dec 2009 16:34:37 +0000</pubDate>
		<dc:creator>JC</dc:creator>
				<category><![CDATA[Admin]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Defense]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[Scripts, Programs]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[System]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[netios]]></category>
		<category><![CDATA[password]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=578</guid>
		<description><![CDATA[I release a new version of Netios : 0.71. There are a lot of changes, starting with cosmetics, but the biggest one is the support of multiprocessing. It is now able to process several routers at the same time, so using it on a large list of machines results in a big speed up. A [...]]]></description>
			<content:encoded><![CDATA[<p>I release a new version of Netios : 0.71.</p>
<p>There are a lot of changes, starting with cosmetics, but the biggest one is the support of multiprocessing.</p>
<p>It is now able to process several routers at the same time, so using it on a large list of machines results in a big speed up.</p>
<p>A downside is that it now requires at least Python 2.6, as multiprocessing started to be supported with this version only. Most Linux distributions now include Python 2.6, but still not all. Anyway it will be more and more the case. If you can&#8217;t uprade your distribution, you can stick with 0.60 which still do most of the work fine.</p>
<p>It is also now able to fetch a configuration file remotly, but it requires more testing before I feel confident in the way it works.</p>
<p>The complete changelog :</p>
<blockquote><p>2009-12-20  (0.71) Jean-Christophe Baptiste <jc@phocean.net>;</p>
<p>* ciscoclass.py : handle correctly the cisco pager &#8212; More &#8212; so that &#8220;show run&#8221; mode should work even with large config files<br />
* sshclass.py : allow to override terminal size system settings (make use of the cisco pager to avoid filling the buffer)</p>
<p>2009-11-16  (0.70) Jean-Christophe Baptiste <jc@phocean.net> (private release)</p>
<p>* implement multiprocessing<br />
* improve code documentation<br />
* clean up UI<br />
* reduce useless logging<br />
* netios.py : bug : missing startTime parameter in f_skip_error and f_command functions</p></blockquote>
<p>I cross my fingers so that there are not too many bugs, but if so, please don&#8217;t forget to report it to me.</p>
<p><a title="Netios" href="http://www.phocean.net/tools/netios">Check there</a> (tools page) for more details and a download link.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2009/12/20/netios-0-71.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ModSecurity 2.5 review</title>
		<link>http://www.phocean.net/2009/12/10/modsecurity-2-5-review.html</link>
		<comments>http://www.phocean.net/2009/12/10/modsecurity-2-5-review.html#comments</comments>
		<pubDate>Thu, 10 Dec 2009 14:12:56 +0000</pubDate>
		<dc:creator>JC</dc:creator>
				<category><![CDATA[Defense]]></category>
		<category><![CDATA[Firewalling]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[IDS / IPS]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[System]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[openSUSE]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[ModSecurity]]></category>
		<category><![CDATA[Regex]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=555</guid>
		<description><![CDATA[I finished reading the ModSecurity 2.5 book, written by Magnus Mischell and published by Packt Publishing. I found a lot of interest reading it as I was already using ModSecurity &#8211; and I think anyone exposing an Apache web server should. I was actually using it partially. It is not trivial to secure a web [...]]]></description>
			<content:encoded><![CDATA[<p>I finished reading the <strong>ModSecurity 2.5</strong> book, written by <strong>Magnus Mischell</strong> and published by <strong>Packt Publishing</strong>.</p>
<p style="text-align: center;"><a title="Modsecurity 2.5" href="http://www.packtpub.com/modsecurity-2-5/book" target="_blank"><img class="size-full wp-image-521  aligncenter" title="ModSecurity 2.5" src="http://www.phocean.net/wp-content/uploads/2009/11/1847194745.jpg" alt="ModSecurity 2.5" width="200" height="247" /></a></p>
<p>I found a lot of interest reading it as I was already using ModSecurity &#8211; and I think anyone exposing an Apache web server should.<br />
I was actually using it partially. It is not trivial to secure a web application, and the rule engine of ModSecurity is very powerful but it is also quite complex.</p>
<p>So this book was a good opportunity for me to dig into it further.</p>
<p>The book covers all topics : from the set-up to a real use-case.<br />
The author explains how to write rules, how to deal with the performance impact, logging and gives us a range of various core rules to implement to get a good security basis.</p>
<p>The difficulty goes up progressively and the author doesn&#8217;t forget the beginners.<br />
The set-up of the module is precisely described. All requirements are also explained and there are some good recalls about regular expressions, common attacks on systems, server and client sides, and other stuff like that.</p>
<p>After reading the book, I could harden my rules, reorganize and optimize them for better performance &#8211; something I hadn&#8217;t cared about before.</p>
<p>So I have nothing else to say but to recommend this book.<br />
It is definitely <strong>a great handbook about ModSecurity</strong> that&#8217;s worth having next to you. The variety of configuration patterns makes it a reference.</p>
<p>Check it <a title="Modsecurity 2.5" href="http://www.packtpub.com/modsecurity-2-5/book" target="_blank">there</a>. I also appreciated the availability of PDF version, so that I can carry it everywhere with my laptop and index it with Beagle.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2009/12/10/modsecurity-2-5-review.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New book about ModSecurity</title>
		<link>http://www.phocean.net/2009/11/15/new-book-about-modsecurity.html</link>
		<comments>http://www.phocean.net/2009/11/15/new-book-about-modsecurity.html#comments</comments>
		<pubDate>Sun, 15 Nov 2009 13:49:48 +0000</pubDate>
		<dc:creator>JC</dc:creator>
				<category><![CDATA[Defense]]></category>
		<category><![CDATA[Firewalling]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[mod-security]]></category>
		<category><![CDATA[ModSecurity]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=520</guid>
		<description><![CDATA[There will be a new book about mod-security coming out :  ModSecurity 2.5. ModSecurity is essential when it comes to secure any web site. It will make the work of the attacker much harder and  it may save you even if your favorite dynamic pages have a security hole. However, it must be configured wisely [...]]]></description>
			<content:encoded><![CDATA[<p>There will be a new book about mod-security coming out :  <a title="Modsecurity 2.5" href="http://www.packtpub.com/modsecurity-2-5/book" target="_blank">ModSecurity 2.5</a>.</p>
<p style="text-align: center;"><a href="http://www.phocean.net/wp-content/uploads/2009/11/1847194745.jpg"><img class="size-full wp-image-521 aligncenter" title="1847194745" src="http://www.phocean.net/wp-content/uploads/2009/11/1847194745.jpg" alt="1847194745" width="200" height="247" /></a></p>
<p>ModSecurity is essential when it comes to secure any web site.</p>
<p>It will make the work of the attacker much harder and  it may save you even if your favorite dynamic pages have a security hole.<br />
However, it must be configured wisely to be efficient. It is just a firewall that works at the application layer : you need to know the attacker point of view and the basics before writing any mod-security rules, otherwise at best it will useless (and at worst, it will kick legitimate traffic off).</p>
<p>So, stay tuned :  I will talk more about the ModSecurity stuff and publish a review about this book soon.</p>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">http://www.packtpub.com/modsecurity-2-5/book</div>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2009/11/15/new-book-about-modsecurity.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Netios</title>
		<link>http://www.phocean.net/2009/11/07/netios.html</link>
		<comments>http://www.phocean.net/2009/11/07/netios.html#comments</comments>
		<pubDate>Sat, 07 Nov 2009 15:53:30 +0000</pubDate>
		<dc:creator>JC</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Defense]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[Scripts, Programs]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[netios]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[SSH]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=516</guid>
		<description><![CDATA[I just released an alpha release of a little tool that may help network administrators with a large park of Cisco routers or switches : Netios is a little tool aimed to help network administrators to administrate a large number of Cisco network devices. Providing it with a list of equipments, it connects within SSH [...]]]></description>
			<content:encoded><![CDATA[<p>I just released an alpha release of a little tool that may help network administrators with a large park of Cisco routers or switches :</p>
<blockquote><p><strong>Netios</strong> is a little tool aimed to help network administrators to administrate a large number of Cisco network devices.<br />
Providing it with a list of equipments, it connects within SSH to remotly apply IOS commands.</p>
<p>It can automatically :</p>
<ul>
<li> retrieve and export in a CSV file the list of local users</li>
<li> update the local user, the enable password</li>
<li> change NTP settings</li>
<li> execute a file of customed IOS commands</li>
<li> retrieve configuration files</li>
</ul>
<p>It can read the targets from the command line or from a text file.</p></blockquote>
<p>Its primary goal is to improve the security by making it easier to renew regularly the local password of these equipments, but it can do more convenient things (and I will continue to work to add more of them).</p>
<p><a title="Netios" href="http://www.phocean.net/tools/netios">Check there</a> (tools page) for more details and a download link.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2009/11/07/netios.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IPv6 tunneling and security</title>
		<link>http://www.phocean.net/2009/11/04/ipv6-tunneling-and-security.html</link>
		<comments>http://www.phocean.net/2009/11/04/ipv6-tunneling-and-security.html#comments</comments>
		<pubDate>Wed, 04 Nov 2009 10:11:41 +0000</pubDate>
		<dc:creator>JC</dc:creator>
				<category><![CDATA[Defense]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Protocols]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[6to4]]></category>
		<category><![CDATA[IPv6]]></category>
		<category><![CDATA[Teredo]]></category>
		<category><![CDATA[tunneling]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=492</guid>
		<description><![CDATA[Interesting article to read about IPv6 tunneling and security aspects. The commends are worth reading too. Follow this link.]]></description>
			<content:encoded><![CDATA[<p>Interesting article to read about IPv6 tunneling and security aspects. The commends are worth reading too.</p>
<p>Follow <a title="IPv6 tunneling and security" href="http://blog.trendmicro.com/ipv6-tunneling-protocols-good-for-adoption-not-so-hot-for-security/">this link</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2009/11/04/ipv6-tunneling-and-security.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>openSUSE kernel sources : patching against sock_sendpage() NULL Pointer Dereference vulnerability</title>
		<link>http://www.phocean.net/2009/08/17/opensuse-kernel-sources-patching-against-sock_sendpage-null-pointer-dereference-vulnerability.html</link>
		<comments>http://www.phocean.net/2009/08/17/opensuse-kernel-sources-patching-against-sock_sendpage-null-pointer-dereference-vulnerability.html#comments</comments>
		<pubDate>Mon, 17 Aug 2009 12:47:34 +0000</pubDate>
		<dc:creator>JC</dc:creator>
				<category><![CDATA[Defense]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[System]]></category>
		<category><![CDATA[openSUSE]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[socket]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=405</guid>
		<description><![CDATA[I am using the 2.6.30 kernel sources from Kernel:linux-next and noticed that it has not yet been patched against the ’sock_sendpage()’ NULL Pointer Dereference vulnerability. The threat is serious as it could allow a local user to gain root privileges. Those who compile their own 2.6.x kernel should apply this patch (from Linus, check there [...]]]></description>
			<content:encoded><![CDATA[<p>I am using the 2.6.30 kernel sources from Kernel:linux-next and noticed that it has not yet been patched against the <a title="Null pointer deference" href="http://www.securitytracker.com/alerts/2009/Aug/1022732.html" target="_blank"><strong>’sock_sendpage()’ NULL Pointer Dereference</strong></a> vulnerability.</p>
<p>The threat is serious as it could allow a local user to gain root privileges.</p>
<p>Those who compile their own <strong>2.6.x kernel</strong> should apply <a href="http://www.phocean.net/wp-content/uploads/2009/08/sock_sendpage.patch">this patch</a> (from Linus, check <a href="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=e694958388c50148389b0e9b9e9e8945cf0f1b98">there</a> for more info) .</p>
<p>Within your kernel source folder :</p>
<pre class="brush: bash;">$ patch -u -p0 &lt; sock_sendpage.patch</pre>
<p>I hope an official patch will be released soon for all kernels. I did not check if the 11.1 kernel has already been patched or not.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2009/08/17/opensuse-kernel-sources-patching-against-sock_sendpage-null-pointer-dereference-vulnerability.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
