Category: Blog

I received a check from Knuth for 0x$3.00

Donald Knuth is a computer science scholar who cares so much about the correctness of his books that he offers a hexadecimal dollar ($2.56, 0x$1.00) for any found "mistake," where a mistake is anything that is "technically, historically, typographically, or politically incorrect." I really wanted to receive a check from Knuth, so I decided to look for errors in his outstanding work "The Art of Computer Programming" (TAOCP). I managed to find […]

How to start a DevOps transformation

If you don't understand what DevOps is, here's a brief cheat sheet. DevOps is a set of practices that reduce engineers' fears and decrease the number of failures in software production. Generally, they also shorten the time to market — the period from idea to delivering the final product to customers, allowing for quick business experiments. How to start a DevOps transformation? […]

AMD: the future lies in chiplets, we should not chase nanometers

AMD's CEO Lisa Su stated at the annual shareholders' meeting that advanced packaging solutions, such as the use of 'chiplets', will be one of the foundations of the company's success in the future. Chief Technology Officer Mark Papermaster highlighted current issues facing the semiconductor industry in the latest episode of The Bring Up series created by AMD's press service. Mark stated, […]

19% of the most popular Docker images lack a password for root

Last Saturday, May 18, Jerry Gamblin from Kenna Security checked 1,000 of the most popular images on Docker Hub for the password used for the root user. In 19% of cases, it was empty. Background on Alpine The trigger for this mini-research was the Talos Vulnerability Report (TALOS-2019-0782) that was published earlier this month, which the authors — thanks to the discovery by Peter […]

Nextcloud inside and OpenLiteSpeed outside: setting up reverse proxying

How to configure OpenLiteSpeed for reverse proxying in Nextcloud, which is located on the internal network? Surprisingly, a search on Habr for OpenLiteSpeed yields nothing! I hasten to correct this injustice, as LSWS is a worthy web server. I love it for its speed and stylish web administration interface: Despite being most famous as a 'accelerator' for WordPress, in today's article I […]

19.4% of the 1000 most popular Docker containers have an empty root password

Jerry Gamblin decided to investigate how widespread a recently identified issue is in the Docker images of the Alpine distribution, related to setting an empty password for the root user. Analysis of a thousand of the most popular containers from the Docker Hub catalog showed that in 194 of them (19.4%), the root user has an empty password without the account being locked ("root:::0:::::" instead of "root:!::0:::::"). In case of usage in […]

Principles of modern application development from NGINX. Part 1

Hello, friends. In anticipation of the launch of the course "Backend Developer in PHP", we traditionally share with you a translation of useful material. Software is solving more and more everyday tasks while becoming increasingly complex. As Marc Andreessen once said, it is eating the world. As a result, over the past few years, approaches to application development and delivery have seriously […]

Backup, part 2: Overview and testing of rsync-based backup solutions

This note continues the series on backup. Backup, Part 1: Why Backup is Necessary, Overview of Methods and Technologies; Backup, Part 2: Overview and Testing of rsync-based Backup Solutions; Backup, Part 3: Overview and Testing of duplicity, duplicaty, deja dup; Backup, Part 4: Overview and Testing of zbackup, restic, borgbackup; Backup, Part 5: Testing […]

Continuous Monitoring – Automation of Software Quality Checks in CI/CD Pipeline

Currently, the topic of DevOps is trending. Continuous integration and delivery CI/CD pipelines are being implemented by all who are interested. However, many do not always pay enough attention to ensuring the reliability of information systems at various stages of the CI/CD Pipeline. In this article, I would like to discuss my experience in automating software quality checks and implementing possible scenarios for its "self-recovery." Source […]

Release of Memcached 1.5.15 with support for authentication for the ASCII protocol.

The release of the in-memory data caching system Memcached 1.5.15 has taken place, which operates with data in key/value format and is characterized by its ease of use. Memcached is commonly used as a lightweight solution to speed up the performance of high-load websites by caching access to databases and intermediate data. The code is distributed under the BSD license. The new version features experimental support for authentication with the ASCII protocol. Authentication is enabled […]

AMD announced the safety and invulnerability of its CPUs to new attacks on the eve of the Zen 2 launch.

It has been over a year since the discovery of Spectre and Meltdown, and the processor market has been in turmoil due to the discovery of new vulnerabilities related to speculative execution. The most affected were Intel chips, including the latest ZombieLoad. Of course, AMD seized the opportunity to emphasize the security of its CPUs. On the page dedicated to Spectre-like vulnerabilities, the company proudly stated: “We at AMD […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster