Category: Blog

Vulnerabilities in OpenBSD that allow privilege escalation and authentication bypass in smtpd, ldapd, and radiusd

Qualys identified four vulnerabilities in OpenBSD, one of which allows remote access without authentication to certain network services, while the other three enable privilege escalation. The report notes the quick response of OpenBSD developers — all issues were addressed in OpenBSD 6.5 and OpenBSD 6.6 within 40 hours after private notification. The remotely exploitable […]

Debugging software deployment with strace

My main job mostly consists of software system deployment, which means I spend a lot of time trying to answer questions like: The developer says this software works, but it doesn't for me. Why? Yesterday this software worked for me, but today it doesn't. Why? This is a kind of debugging that's a bit different from regular software debugging. […]

How we at CIAN tamed terabytes of logs

Hi everyone, my name is Alexander, I work at CIAN as an engineer and I'm involved in system administration and the automation of infrastructure processes. In the comments to one of our previous articles, we were asked to explain where we get 4 TB of logs per day and what we do with them. Yes, we have a lot of logs, and a separate infrastructure cluster has been created for their processing, which […]

How attackers can read your messages in Telegram. And how to prevent this

At the end of 2019, several Russian entrepreneurs approached the cybercrime investigation department of Group-IB with a problem regarding unauthorized access by unknown individuals to their messages in the Telegram messenger. Incidents occurred on iOS and Android devices, regardless of which federal mobile operator the affected person was using. The attack started with a message arriving in the Telegram messenger […]

High Load Architect. A new course from OTUS

Attention! This article is not technical and is intended for readers looking for Best Practices in High Load and fault tolerance for web applications. Likely, if you are not interested in learning, this material will not be of interest to you. Imagine a situation: you've launched a promotion with discounts for some online store, and like millions of others, you decided to buy something very important […]

The second beta version of the Vivaldi browser for Android has been released.

Hello everyone! Today, the second beta version of the Chromium-based mobile browser Vivaldi for the Android platform has been released. The list of main changes includes: Closing tabs with a swipe, Enabling scrolling on internal pages, Improved cell sorting, Drag-and-drop for the Speed Dial, Ability to create a new folder directly on the Speed Dial, Editing and deleting Speed Dial cells, Clearing the trash with one button, Option for permanent loading of the desktop […]

CAINE 11.0 - a distribution for forensic analysis and hidden information retrieval.

The specialized Linux distribution CAINE 11.0 has been released, designed for forensic analysis and hidden information retrieval. This live build is based on Ubuntu 18.04, supports UEFI Secure Boot, and comes with Linux kernel 5.0. The distribution allows for the analysis of residual information after a breach on Unix and Windows systems. It includes a wide array of utilities for work. Notably, it features a specialized tool […]

Release of the nftables 0.9.3 packet filter.

The release of the nftables 0.9.3 packet filter has been published, evolving as a replacement for iptables, ip6tables, arptables, and ebtables by unifying the packet filtering interfaces for IPv4, IPv6, ARP, and network bridges. The nftables package includes user space components for the packet filter, while the kernel-level operation is provided by the nf_tables subsystem, which is part of the Linux kernel […]

Alpha testing of the Debian 11 "Bullseye" installer has begun

Testing has begun for the first alpha version of the installer for the next major release of Debian — 'Bullseye'. The release is expected in about one and a half to two years. Key changes in the installer include: Mentions of CD and CD-ROM have been replaced with 'installation media'; In apt-setup, the generation of strings in sources.list files for updates related to security issue fixes has been redesigned. The {dist}-updates strings have been renamed to {dist}-security. Separation of blocks in sources.list is allowed […]

Video: the totem, the cursed village, and a lot of shooting in the Witchfire excerpt from the creators of The Vanishing of Ethan Carter

The studio The Astronauts, creators of the adventure game The Vanishing of Ethan Carter, has been working on a new project — Witchfire — for over two years. A year ago, the developers stated that the release of this horror shooter about witch hunting would likely not happen until 2020. In the latest update on the official blog, there is no mention of release dates, but the authors shared gameplay snippets from […]

The new version of the Opera browser for Android may include a dark mode for any website

Technology companies and mobile gadget manufacturers have long been advertising various ways to reduce the negative impact of blue light emitted by device screens on users' eyes and overall well-being. In the new version of the popular browser Opera 55 for the Android platform, an updated dark mode is introduced, which will help reduce eye strain when interacting with the gadget. The main […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster