Episode 379: SegmentSmack is Whack




TechSNAP show

Summary: <p>Take down a Linux or FreeBSD box with just 2kpps of traffic, own Homebrew in 30 minutes, and infiltrate an entire network via the Inkjet printers. </p> <p>It’s a busy TechSNAP week.</p><p>Sponsored By:</p><ul> <li> <a rel="nofollow" href="http://techsnap.ting.com">Ting</a>: <a rel="nofollow" href="http://techsnap.ting.com">Save $25 off a device, or get $25 in service credits!</a> Promo Code: Visit techsnap.ting.com</li> <li> <a rel="nofollow" href="http://ixsystems.com/techsnap">iXSystems</a>: <a rel="nofollow" href="http://ixsystems.com/techsnap">Get a system purpose built for you.</a> Promo Code: Tell them we sent you!</li> <li> <a rel="nofollow" href="https://do.co/snap">Digital Ocean</a>: <a rel="nofollow" href="https://do.co/snap">Apply our promo snapocean after you create your account, and get a $10 credit.</a> Promo Code: snapocean</li> </ul><p>Links:</p><ul> <li><a title="HP Inkjet Printers Buffer Overflows in Processing Files Let Remote Users Execute Arbitrary Code" rel="nofollow" href="https://securitytracker.com/id/1041415">HP Inkjet Printers Buffer Overflows in Processing Files Let Remote Users Execute Arbitrary Code</a></li> <li><a title="Black Hat 2018: Update Mechanisms Allow Remote Attacks on UEFI Firmware | The first stop for security news" rel="nofollow" href="https://threatpost.com/update-mechanism-flaws-allow-remote-attacks-on-uefi-firmware/134785/">Black Hat 2018: Update Mechanisms Allow Remote Attacks on UEFI Firmware | The first stop for security news</a></li> <li><a title="How I gained commit access to Homebrew in 30 minutes" rel="nofollow" href="https://medium.com/@vesirin/how-i-gained-commit-access-to-homebrew-in-30-minutes-2ae314df03ab">How I gained commit access to Homebrew in 30 minutes</a></li> <li><a title="Reconnaissance tool for GitHub organizations" rel="nofollow" href="https://github.com/michenriksen/gitrob">Reconnaissance tool for GitHub organizations</a></li> <li><a title="TruffleHog: Searches through git repositories for high entropy strings and secrets, digging deep into commit history" rel="nofollow" href="https://github.com/dxa4481/truffleHog">TruffleHog: Searches through git repositories for high entropy strings and secrets, digging deep into commit history</a></li> <li><a title="BFG Repo-Cleaner by rtyley" rel="nofollow" href="https://rtyley.github.io/bfg-repo-cleaner/">BFG Repo-Cleaner by rtyley</a></li> <li><a title="TCP implementations vulnerable to Denial of Service" rel="nofollow" href="https://www.kb.cert.org/vuls/id/962459">TCP implementations vulnerable to Denial of Service</a></li> <li><a title="SegmentSmack: kernel: tcp segments with random offsets may cause a remote denial of service [CVE-2018-5390]" rel="nofollow" href="https://access.redhat.com/articles/3553061">SegmentSmack: kernel: tcp segments with random offsets may cause a remote denial of service [CVE-2018-5390]</a></li> <li><a title="Merge branch 'tcp-robust-ooo' · torvalds/linux" rel="nofollow" href="https://github.com/torvalds/linux/commit/1a4f14bab1868b443f0dd3c55b689a478f82e72e">Merge branch 'tcp-robust-ooo' · torvalds/linux</a></li> <li><a title="New Sysadmin dealing with stress." rel="nofollow" href="https://www.reddit.com/r/sysadmin/comments/95od7h/new_sysadmin_dealing_with_stress/">New Sysadmin dealing with stress.</a></li> <li><a title="Microsoft’s undersea data center now has a webcam with fish swimming past 27.6 petabytes of data" rel="nofollow" href="https://www.theverge.com/tldr/2018/8/9/17669936/microsoft-undersea-datacenter-webcam">Microsoft’s undersea data center now has a webcam with fish swimming past 27.6 petabytes of data</a></li> </ul>