Reminds me of the '90s when WinNuke and Smurf attacks ran wild. Remember one attack that caused our Linux boxes to panic, but I can't remember what it was called. It's not surprising that we're seeing stuff like this in v6. IPv4 has had the bugs hammered out from years of attacks, v6 not so much.
> Remember one attack that caused our Linux boxes to panic, but I can't remember what it was called.
Reminds me of the '90s when WinNuke and Smurf attacks ran wild. Remember one attack that caused our Linux boxes to panic, but I can't remember what it was called. It's not surprising that we're seeing stuff like this in v6. IPv4 has had the bugs hammered out from years of attacks, v6 not so much.
Does anyone know how long it took for operating systems to implement ipv4 in a secure and stable manner?
I take it 12/11/12 is a December date, not the November one that it is by convention here... I missed that and assumed a month had been given, as screen grabs show November dates.
I dream (awake!) of The World seeing that date, thinking something along the lines of "but hey, that's annoying, I'm not sure which date that refers to!" and then just adopting ISO 8601 immediately.
Sometimes I'm really baffled by the dominance of American date formats instead of clear, natural and sortable ISO 8601.
When I discovered a vulnerability in Mac OS X that would allow a unprivileged user to keylog every user on the system (CVE-2007-0724), I let Apple know, then kept quiet until they fixed the issue. It took them 11 and a half months to fix. They thanked me in the security update note, and I now how a CVE on my resume. Was silence the most morally correct action? To this day, I am still unsure.
I've never thought to put CVE-IDs I'm credited for reporting on my resume. Is that...a thing? Do tech employers (outside of security consultancies) even know what a CVE-ID is?
I'm at Basho (we make the Riak database) in a non-security role, and I pay attention to CVE-IDs. They'll stick with me and make me remember a resume better, and improve somebody's chances of advancing to an interview, and give me something to ask about during an interview.
I dream (awake!) of The World seeing that date, thinking something along the lines of "but hey, that's annoying, I'm not sure which date that refers to!" and then just adopting ISO 8601 immediately.
Sometimes I'm really baffled by the dominance of American date formats instead of clear, natural and sortable ISO 8601. YYYY-MM-DD HH:MM:SS.ffffff+ZZZZ
I used to think the same way until I moved to the UK and people expressed the opinion that YYYY-MM-DD is still an American format.
I guess because for them the day always comes before month.
Nevertheless, ISO 8601 is clearly the ideal format for its sortability and consistency, cultural imperialism be damned!
Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…
I'm not sure why the page states Apple was notified 12/11/12 but this attack has been known (by me and sec folks) a little while now, and I found out about it from an Apple engineer that works in this area. So they've been aware of it a while. It also affects iOS.
Maybe Sam Bowne (the author) didn't formally notify Apple until he had more solid details, but he certainly made the issue publicly-known before this. It wasn't a surprise attack on anyone.
Sometimes I'm really baffled by the dominance of American date formats instead of clear, natural and sortable ISO 8601. YYYY-MM-DD HH:MM:SS.ffffff+ZZZZ
I used to think the same way until I moved to the UK and people expressed the opinion that YYYY-MM-DD is still an American format. I guess because for them the day always comes before month. Nevertheless, ISO 8601 is clearly the ideal format for its sortability and consistency, cultural imperialism be damned!
Well, in Poland we do use D.[M]M.[YY]YY too, which is unfortunately quite popular, as a short version of the format with verbal month "D MMMMM YYYY r." (r. stands for "rok[u]", i.e. year). This long version is predominantly used in lots of official forms and letters here.
That depends on the vendor. Some vendors are slow, some vendors are fast. It is wrong to say that no vendor even fixes bugs unless they are publicly disclosed, it is not what responsible disclosure means.
When I say "in general" that means not so for every vendor. That said, Apple's track record on this topic is not exactly stellar.
Apple rolls out security updates infrequently, but it seems that every time they do, I see fixes for issues I'd never heard of before. Now, I don't exactly seek out vulnerability reports, but they certainly seem to be fixing things that didn't get high-profile articles on social news sites.
When I discovered a vulnerability in Mac OS X that would allow a unprivileged user to keylog every user on the system (CVE-2007-0724), I let Apple know, then kept quiet until they fixed the issue. It took them 11 and a half months to fix. They thanked me in the security update note, and I now how a CVE on my resume. Was silence the most morally correct action? To this day, I am still unsure.
I've never thought to put CVE-IDs I'm credited for reporting on my resume. Is that...a thing? Do tech employers (outside of security consultancies) even know what a CVE-ID is?
If your resume has them, the others don't, and the boss is knowledgeable or curious ... then it could help you stand out. I would think it would look very good for a developer position, especially at a place that makes high reliability and/or network facing products.