<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule"
>

<channel>
	<title>Cyconet Blog &#187; security</title>
	<atom:link href="http://blog.waja.info/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.waja.info</link>
	<description>Just a place to be!</description>
	<lastBuildDate>Wed, 28 Apr 2010 08:22:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license>
		<item>
		<title>Kabel Deutschland breaks DNS System for it&#8217;s customers</title>
		<link>http://blog.waja.info/2008/05/23/kabel-deutschland-breaks-dns-system-for-its-customers/</link>
		<comments>http://blog.waja.info/2008/05/23/kabel-deutschland-breaks-dns-system-for-its-customers/#comments</comments>
		<pubDate>Fri, 23 May 2008 13:59:26 +0000</pubDate>
		<dc:creator>cyco</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[planet]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.waja.info/?p=165</guid>
		<description><![CDATA[Last week I noticed, that Kabel Deutschland, a cable provider in germany, returns for any non existing hosts &#8220;204.9.89.60&#8243;. It seems, thats it is rolled out since last fall. Even for DNSSEC enabled infrastructure it breaks it totally: ; &#60;&#60;&#62;&#62; DiG 9.3.4 &#60;&#60;&#62;&#62; +dnssec web.pixaco.se @83.169.184.161 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, [...]]]></description>
			<content:encoded><![CDATA[<p>Last week I noticed, that <a target="new" href="http://www.kabeldeutschland.de/">Kabel Deutschland</a>, a cable provider in germany, returns for any non existing hosts &#8220;204.9.89.60&#8243;. It seems, thats it is rolled out since last fall. Even for <a target="new" href="http://en.wikipedia.org/wiki/DNSSEC">DNSSEC</a> enabled infrastructure it breaks it totally:</p>
<p class="code">
; &lt;&lt;&gt;&gt; DiG 9.3.4 &lt;&lt;&gt;&gt; +dnssec web.pixaco.se  @83.169.184.161<br />
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1<br />
;; ANSWER SECTION:<br />
web.pixaco.se.          0       IN      A       204.9.89.60
</p>
<p>Beside that, this behavour breaks the whole DNS, since many mechanism rely on a negative answer. The most visible effect for the users is, that when having a typo on surfing, he will forwarded to http://suche.kabeldeutschland.de/de.kde.assist/?domain=&lt;domainyoutypedinyourprompt&gt;. Since 204.9.88.0/21 is located at our transatlantic friends from US, there might be some problem with leaking privacy informations. I don&#8217;t feel happy, if I had a typo in my URL and getting listed for it on any terror list or providing the newest porno links to my american friends inside the organisations with the tree capitals.</p>
<p>All that for getting some extra money, but racing pricedumping for connectivity, this sucks a lot.<br />
If you are a customer and feel pissed, you can send a friendly note to them:</p>
<blockquote><p>Kabel Deutschland Vertrieb und Service GmbH &#038; Co. KG<br />
Beschwerdestelle<br />
99116 Erfurt<br />
kundenservice@kabeldeutschland.de<br />
Fax: 01805299925</p></blockquote>
<p>A quick and dirty workaround for dnsmasq maybe to add &#8220;bogus-nxdomain=204.9.89.60&#8243; to your config file. This doesn&#8217;t fix the DNSSEC problem.<br />
The problem also pops up at <a href="http://lists.oarci.net/pipermail/dns-operations/2008-May/002678.html" target="new">dns-operations</a> and there are traces at <a target="new" href="http://www.google.com/search?q=kabel+deutschland+infospace+dns">google</a> too.</p>
<p>[UPDATE] Over 1 year later zdnet.de <a target="new" href="http://www.zdnet.de/sicherheits_analysen_umsatz_um_jeden_preis_falsche_dns_antworten_der_provider_story-39001544-41524645-4.htm">discoverd</a> the problem. </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.waja.info/2008/05/23/kabel-deutschland-breaks-dns-system-for-its-customers/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license>
	</item>
		<item>
		<title>[security] wordpress 2.5.1 which fixes CVE-2008-1930</title>
		<link>http://blog.waja.info/2008/04/25/wordpress-251-which-fixes-cve-2008-1930/</link>
		<comments>http://blog.waja.info/2008/04/25/wordpress-251-which-fixes-cve-2008-1930/#comments</comments>
		<pubDate>Fri, 25 Apr 2008 18:15:26 +0000</pubDate>
		<dc:creator>cyco</dc:creator>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[backports]]></category>
		<category><![CDATA[Packaging]]></category>
		<category><![CDATA[planet]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[selfnote]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://blog.waja.info/?p=160</guid>
		<description><![CDATA[Cause the subject, I did build a new package which can be installed on etch, lenny and of course sid. You can fetch it from http://ftp.cyconet.org/debian/archive/bpo/wordpress/2.5.1-1~bpo40+1/ or get via deb http://ftp.cyconet.org/debian etch-backports main non-free contrib Selfnote: Dump the wordpress user into separate domU]]></description>
			<content:encoded><![CDATA[<p>Cause the subject, I did build a new package which can be installed on etch, lenny and of course sid. You can fetch it from http://ftp.cyconet.org/debian/archive/bpo/wordpress/2.5.1-1~bpo40+1/ or get via</p>
<p class="code">
deb     http://ftp.cyconet.org/debian etch-backports     main non-free contrib
</p>
<p>Selfnote: Dump the wordpress user into separate domU</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.waja.info/2008/04/25/wordpress-251-which-fixes-cve-2008-1930/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license>
	</item>
		<item>
		<title>[security] policyd-weight 0.1.14-beta-6etch1/0.1.14.15-1</title>
		<link>http://blog.waja.info/2008/03/27/security-policyd-weight-0114-beta-6etch1011415-1/</link>
		<comments>http://blog.waja.info/2008/03/27/security-policyd-weight-0114-beta-6etch1011415-1/#comments</comments>
		<pubDate>Thu, 27 Mar 2008 20:12:21 +0000</pubDate>
		<dc:creator>cyco</dc:creator>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[OpenSource]]></category>
		<category><![CDATA[Packaging]]></category>
		<category><![CDATA[planet]]></category>
		<category><![CDATA[policyd-weight]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.waja.info/2008/03/27/security-policyd-weight-0114-beta-6etch1011415-1/</guid>
		<description><![CDATA[This Tuesday Robert Felber released a new upstream version. It is a (local) security bugfix (and some minor fixes) which was reported on Sunday by Chris Howells to the Debian Security Team (as well as to other vendors). Today DSA-1531 was released. Right from the DSA: &#8220;&#8230; created its socket in an insecure way, which [...]]]></description>
			<content:encoded><![CDATA[<p>This Tuesday Robert Felber <a target="new" href="http://www.mail-archive.com/policyd-weight-list%40ek-muc.de/msg00798.html">released</a> a new upstream version. It is a (local) security bugfix (and some minor fixes) which was reported on Sunday by Chris Howells to the Debian Security Team (as well as to other vendors). Today <a target="new" href="http://www.debian.org/security/2008/dsa-1531">DSA-1531</a> was released.</p>
<p>Right from the DSA:<br />
&#8220;&#8230; created its socket in an insecure way, which may be exploited to overwrite or remove arbitary files from the local system.&#8221;</p>
<p>So please update you systems if you use this package asap.</p>
<p>While we are at policyd-weight&#8230; there is one bug open (<a target="new" href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=471645">#471645</a>) where I&#8217;m unsure if I want to fix it, cause only stable is effected and the problem can be solved by providing a adjusted array of rbl in the config file. Should I ask for inclusion directly into stable? But it&#8217;s a really minor issue. Or try to get 0.1.14.15 uploaded to <a target="new" href="http://volatile.debian.org/">volatile</a>? I&#8217;m really unsure and suggestions are welcome.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.waja.info/2008/03/27/security-policyd-weight-0114-beta-6etch1011415-1/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license>
	</item>
		<item>
		<title>Package updates and others</title>
		<link>http://blog.waja.info/2007/12/07/package-updates-and-others/</link>
		<comments>http://blog.waja.info/2007/12/07/package-updates-and-others/#comments</comments>
		<pubDate>Fri, 07 Dec 2007 11:51:04 +0000</pubDate>
		<dc:creator>cyco</dc:creator>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[backports]]></category>
		<category><![CDATA[bpo]]></category>
		<category><![CDATA[Packaging]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[planet]]></category>
		<category><![CDATA[plugins]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.waja.info/2007/12/07/package-updates-and-others/</guid>
		<description><![CDATA[Since some weeks I&#8217;m really busy, private and at work. It&#8217;s going into the end of the year and everybody is in hurry. There seems also coming some changes for our family down the road in the future, but more maybe later. Additionally one months ago Santiago Ruano RincÃ³n did surprisingly turn up as my [...]]]></description>
			<content:encoded><![CDATA[<p>Since some weeks I&#8217;m really busy, private and at work. It&#8217;s going into the end of the year and everybody is in hurry. There seems also coming some changes for our family down the road in the future, but more maybe later. Additionally one months ago <a href="http://santiago.tortugacha.org/" target="new">Santiago Ruano RincÃ³n</a> did surprisingly turn up as my AM. We started fast, but I got stuck at P&#038;P part 1 with the License comparisons, cause actually I&#8217;m so busy at work and with my family, that I can&#8217;t concentrate enough late at night, when trying to work on the papers. For example the graphviz license is completely overwhelming me. My hope in the last time was some bigger timeslots at the weekends, but they got smashed by my family and/or work issues. I hope Santiago is not getting annoyed by me and I can find hopefully some free time on holidays or in the first weeks next year.</p>
<p>Anyways &#8230; <a href="http://www.perrier.eu.org/weblog" target="new">Christian Perrier</a> started a review and translation process of <a href="http://packages.qs.debian.org/ipplan" target="new">ipplans</a> debconf templates by the <a href="http://i18n.debian.net/wiki" target="new">debian-i18n contributors</a>. The templates was in really bad conditions, most of it was copied over from gallery2 and I did know that they wasn&#8217;t so good. Thanks for all your work, when the process is over I&#8217;m proud to include your really nice work.</p>
<p>Two other packages got updates. <a href="http://packages.qs.debian.org/php-suhosin" target="new">php-suhosin</a> got new upstream release after months which fixes the broken perdir/.htaccess support. Unfortunatly I missed the release (cause there is no announcement list and there was no watch file) unless <a href="http://my.opera.com/atomo64/blog/" target="new">Raphael Geissert</a> did leave a note. I integrated the new VCS and homepage stuff also and <a href="http://www.formorer.de/webwiki//blog/" target="new">formorer</a> did fix some minor issues. So we can hopefully upload now (when it arrives testing) the first package to <a href="http://backports.org" target="new">backport.org</a> and sleep little bit better, when using PHP on stable.<br />
<a href="http://packages.qs.debian.org/nagios-plugins" target="new">nagios-plugins</a> also got updated. Since <a href="http://www.seanius.net/" target="new">Seanius</a> seems really busy (like allways), nobody did really took care of the package. In October it got two CVE which was solved via NMU by the <a href="http://testing-security.debian.net/" target="new">testing-security team</a>, also two new upstream releases where available. So I droped the obsolete patches, integrated new once, did make the new shiny lintian a bit more happy, some minor fixes and queued the package to Seanius. ;)<br />
You can expect both packages on backport.org soon. My other (comaintained) packages will get updated to latest policy and VCS/homepage guidelines in the near future. Actually I&#8217;ve to prioritize what to do with the left time slots. :/</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.waja.info/2007/12/07/package-updates-and-others/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license>
	</item>
		<item>
		<title>Ignoring security (usability)</title>
		<link>http://blog.waja.info/2007/07/07/ignoring-security-usability/</link>
		<comments>http://blog.waja.info/2007/07/07/ignoring-security-usability/#comments</comments>
		<pubDate>Fri, 06 Jul 2007 23:39:18 +0000</pubDate>
		<dc:creator>cyco</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[planet]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[WLan]]></category>

		<guid isPermaLink="false">http://blog.waja.info/2007/07/07/ignoring-security-usability/</guid>
		<description><![CDATA[Since some time, Deutsche Bahn rolled public wireless lan called &#8220;WLAN am Bahnhof&#8221; out at 25 railroad stations, you can choose between 4 providers. Sounds really nice, but beside the economical conditions, there is also at least one security issue. Connecting to the network and opening your favorite browser redirects you to a encrypted portal. [...]]]></description>
			<content:encoded><![CDATA[<p>Since some time, <a target="new" href="http://www.db.de">Deutsche Bahn</a> rolled public wireless lan called &#8220;WLAN am Bahnhof&#8221; out at 25 railroad stations, you can choose between 4 providers. Sounds really nice, but beside the economical conditions, there is also at least one security issue.<br />
Connecting to the network and opening your favorite browser redirects you to a encrypted portal. So far, so good &#8230; the really bad news is, that the certificate expired over 6 years ago.<br />
<img src="http://blog.waja.info/wp-content/photos/zertifikat.png" alt="Broken certificate" /><br />
This seems to be a normal behavior, since it happens often, that invalid certificates are used. This leeds to blunted users, which aren&#8217;t verifying such certificates anymore, even when it&#8217;s important.<br />
Does anybody know a reasonable way to notify anybody who can solve the problem there beside the normal contact forms?</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.waja.info/2007/07/07/ignoring-security-usability/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license>
	</item>
		<item>
		<title>Is DNSSEC ready for wild life?</title>
		<link>http://blog.waja.info/2007/04/20/is-dnssec-ready-for-wild-life/</link>
		<comments>http://blog.waja.info/2007/04/20/is-dnssec-ready-for-wild-life/#comments</comments>
		<pubDate>Fri, 20 Apr 2007 19:57:11 +0000</pubDate>
		<dc:creator>cyco</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[planet]]></category>
		<category><![CDATA[ripe]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.waja.info/2007/04/20/is-dnssec-ready-for-wild-life/</guid>
		<description><![CDATA[Today the RIPE DNS for LIRs Training Course did take place. (some not up to date course material can be found here) Managing some thousands of zones inclusive nameserver infrastructure behind since several years, I thought it would be neat to provide a secure dns chain to our costumers. After going deeper into the material [...]]]></description>
			<content:encoded><![CDATA[<p>Today the <a target="new" href="http://www.ripe.net/training/dns/index.html">RIPE DNS for LIRs Training Course</a> did take place. (some not up to date course material can be found <a target="new" href="http://www.ripe.net/training/dns/material/">here</a>)<br />
Managing some thousands of zones inclusive nameserver infrastructure behind since several years, I thought it would be neat to provide a secure dns chain to our costumers.<br />
After going deeper into the material within the course, I recognized the following impacts:</p>
<ul>
<li>only <a target="new" href="http://www.isc.org/sw/bind/">bind9 (>= 9.3)</a> and <a target="new" href="http://en.wikipedia.org/wiki/NSD">NSD</a> privides support (yet)</li>
<li>bandwidth will be increased 2-3 times with max. key size</li>
<li>increased memory usage depending on your server software</li>
<li>operational costs will increasing dramaticaly due significant higher amount of regular work</li>
<li>more computing power (hardware) needed to generate dnssec ready zones and signing</li>
<li>unknown influence on resolving nameservers (load/memory/bandwidth)</li>
<li><strong>chain of trust</strong> ends at resolving nameserver and <strong>is not provided to enduser</strong></li>
</ul>
<p>Since the last issue isn&#8217;t solved (yet), it doesn&#8217;t make any sence for me to invest resources into setting up DNSSec infrastructur, cause the end user would not recognize if the communication with the resolving nameserver or the resolving nameserver itself is taken over.</p>
<p>Any complaints and/or hint? Did I missed something?</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.waja.info/2007/04/20/is-dnssec-ready-for-wild-life/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license>
	</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->