Author: Yuri Gagarin

The second beta version of the Vivaldi browser for Android has been released.

Hello everyone! Today, the second beta version of the Chromium-based mobile browser Vivaldi for the Android platform has been released. The list of main changes includes: Closing tabs with a swipe, Enabling scrolling on internal pages, Improved cell sorting, Drag-and-drop for the Speed Dial, Ability to create a new folder directly on the Speed Dial, Editing and deleting Speed Dial cells, Clearing the trash with one button, Option for permanent loading of the desktop […]

High Load Architect. A new course from OTUS

Attention! This article is not technical and is intended for readers looking for Best Practices in High Load and fault tolerance for web applications. Likely, if you are not interested in learning, this material will not be of interest to you. Imagine a situation: you've launched a promotion with discounts for some online store, and like millions of others, you decided to buy something very important […]

How attackers can read your messages in Telegram. And how to prevent this

At the end of 2019, several Russian entrepreneurs approached the cybercrime investigation department of Group-IB with a problem regarding unauthorized access by unknown individuals to their messages in the Telegram messenger. Incidents occurred on iOS and Android devices, regardless of which federal mobile operator the affected person was using. The attack started with a message arriving in the Telegram messenger […]

How we at CIAN tamed terabytes of logs

Hi everyone, my name is Alexander, I work at CIAN as an engineer and I'm involved in system administration and the automation of infrastructure processes. In the comments to one of our previous articles, we were asked to explain where we get 4 TB of logs per day and what we do with them. Yes, we have a lot of logs, and a separate infrastructure cluster has been created for their processing, which […]

Debugging software deployment with strace

My main job mostly consists of software system deployment, which means I spend a lot of time trying to answer questions like: The developer says this software works, but it doesn't for me. Why? Yesterday this software worked for me, but today it doesn't. Why? This is a kind of debugging that's a bit different from regular software debugging. […]

Vulnerabilities in OpenBSD that allow privilege escalation and authentication bypass in smtpd, ldapd, and radiusd

Qualys identified four vulnerabilities in OpenBSD, one of which allows remote access without authentication to certain network services, while the other three enable privilege escalation. The report notes the quick response of OpenBSD developers — all issues were addressed in OpenBSD 6.5 and OpenBSD 6.6 within 40 hours after private notification. The remotely exploitable […]

An attack on HackerOne that allowed access to confidential vulnerability reports

The HackerOne platform, which enables security researchers to inform developers about detected vulnerabilities and receive rewards for them, has reported an incident of its own hacking. One of the researchers was able to access the account of a security analyst at HackerOne, who had the ability to view confidential materials, including information about vulnerabilities that have not yet been resolved. Since the platform's inception, […]

Release of the Elementary OS 5.1 "Hera" distribution

The release of the Elementary OS 5.1 "Hera" distribution has been announced, positioned as a fast, open, and privacy-respecting alternative to Windows and macOS. The project focuses on quality design aimed at creating a user-friendly system that consumes minimal resources while providing high boot speed. Users are offered the custom Pantheon desktop environment. Bootable ISO images (1.47 GB) are prepared for download, […]

Multiple vulnerabilities in OpenBSD

Experts from Qualys Labs discovered several security issues related to the possibility of fooling the programs responsible for password verification mechanisms used in BSD (similar to PAM). The trick lies in passing the username "-schallenge" or "-schallenge:passwd", which is then interpreted not as a username but as an option. After that, the system accepts any password. Vulnerable, i.e., ultimately allowing unauthorized access, […]

Review of ONYX BOOX Max 3: A Reader with the Largest Screen

Table of Contents 1. Technical Specifications 2. Hardware and Software 3. Reading Books and Documents 4. Additional Features 5. Autonomy 6. Conclusions and Summaries What is the most important for e-books (readers) with production-technical application? Perhaps, the processor power, memory size, screen resolution? All of this is certainly important; but the most crucial factor is the physical screen size: the larger it is […]

The Truth About Train Brakes: Part 4 — Passenger-Type Braking Devices

Next time you find yourself at the station, take a moment to focus on the inscription right in the middle at the bottom of the train car that will take you away on another long-awaited vacation. This inscription is not there by chance; it tells us the mysterious, conditional number of the brake air distributor that is installed on this car. The inscription is visible even if the train is stopped […]

SCADA on Raspberry: myth or reality?

Winter Is Coming. Programmable Logic Controllers (PLCs) are gradually being replaced by embedded personal computers. This is due to the fact that the computing power allows a single device to encompass the functions of a programmable controller, server, and (if the device has an HDMI output) an automated workstation for the operator. In total: a web server, OPC component, database, and automated workstation in a single case, and […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster