Category Archives: Security

new PGP key

Since I keep forgetting my passwords: My new, one and only PGP key at the moment: key-id: 0x23C1768B fingerprint: 7011 3BD7 9207 32D3 ABBC C64E 90FB BC74 23C1 768B

Upgraded to wordpress 2.6

Out of interest I read the release notes of wordpress 2.6, which didn’t have any interesting features or me, to be informed that 2.5 will not be maintained anymore. Thanks a lot. Fortunately upgrading went very smooth with the subversion.

Weak SSL key vulnerabilities not so funny

Yesterday evening I had the pleasure to pick up the following three security notices: [USN-612-1] OpenSSL vulnerability [USN-612-2] OpenSSH vulnerability [USN-612-3] OpenVPN vulnerability I can tell you these are really not funny. They really generate a lot of work indirectly. Annoying but doable are things like regeneration SSH keys. The PITA situation is with OpenVPN, [...]

WordPress is a pain

I’m happy I hardened my webserver setup a bit and all our blogs are running on a seperate virtual machine but damn, wordpress is a pain to maintain. I updated it less then a year ago and I’m already hopelessly out of date! Also this time there are a whole lot of security updates of [...]

Interesting article about PHP security

Article: http://www.securityfocus.com/columnists/432 Besides some coverage about the common PHP application vulnerabilities it gives a lot of background about the way the PHP project handles security (it sucks balls). Shines a light occurancy of security holes in php itself (so not the application developed in php) and what kind of effects this can have (stealing SSL [...]

WordPress Akismet plugin broken with mod_chroot enabled

Since it was overly simple for Kim Chee to get his akismet thing to work (it kept telling me invalid key) it was probably a difference between webhost. I am a lazy bastard but this had to be simple, after 10 seconds my suspicions were clear. mod_chroot! I absolutely love mod_chroot, I wouldn’t dare to [...]

User data from installation time stored world readable

Apparently the data which is entered during installation is stored in clear text and not removed. https://launchpad.net/distros/ubuntu/+bug/34606/ Time to change my password! I hope you already did since your last installation. On my server only people with shell access would be able to see this file. But even if you don’t give out shell access [...]

Finally started GPG signing keys

I finally started to sign the keys from the What The Hack keysigning party. Obviously a bit late. Some even spammed my mailbox to pressure me, so they got the honour of first signs. I’m halfway there now. Using caff to automate it a bit, but still have to type my ridiculously long passphrase for [...]

Rounding up WTH

13:57h Lots of things are selling out (Jolt, food, t-shirts) and its raining pretty bad all day. Got an OpenBSD 3.6 official CD for free (previous release). Walked around a bit. Myzt found out were on a video shot at the PGP keysigning “party”. Got some penguin caffeinated peppermints for free. I’m leaving to Rotterdam [...]

Fun @ What The Bookstore

Myzt took this picture in What The Bookstore: The book that is sold out is titled: “Girlfriend Hacks, tips and tricks to deal with you beloved one”.