Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dolfje
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
dolfje
11y ago
Yes, that is a problem. 'Hardened' configurations cannot be checked. But there are a lot of non-hardened configuration. Actually there are more that returns there version than not.
62.
▲
by
dolfje
11y ago
You can check your server easily without doing the real attack. Because that would result into a denial of service. You just check the version of BIND in the linux terminal: dig @google.com version.bind chaos txt If that is one of the follo
63.
▲
by
dolfje
11y ago
Stats of 45min, still 17% are vulnerable for the BIND vulnerability, 5 days after the disclosure.
64.
▲
DDR3 Bitflipping exploit using only JavaScript
(arstechnica.co.uk)
2 points
by
dolfje
11y ago
|
0 comments
65.
▲
Remote denial of service vulnerability exposes BIND servers
(zdnet.com)
2 points
by
dolfje
11y ago
|
0 comments
66.
▲
by
dolfje
11y ago
Small stat: At the moment we are scanning at an average rate of 2000 sites / hour. So average of 0.03s for each site. Making the stats page has definitely helped us to test/increase our performance.
67.
▲
by
dolfje
11y ago
Be aware that this statistics is only about the top 40.000, if you extrapolate the graph, you see 50% outdated software for the top 10 million. As this takes a lot of resources, do you find it usefull? Or do you think the 40.000 is already
68.
▲
NASA is Crash-testing Planes (videos)
(arstechnica.co.uk)
1 points
by
dolfje
11y ago
|
0 comments
69.
▲
Xiaomi overtakes Apple as number one smartphone vendor in China
(arstechnica.co.uk)
2 points
by
dolfje
11y ago
|
0 comments
70.
▲
They grow up fast: Apple quietly bulks up Swift and Xcode in year two
(arstechnica.co.uk)
1 points
by
dolfje
11y ago
|
0 comments
71.
▲
by
dolfje
11y ago
PatrolServer - Software Engineer - http://patrolserver.com Responsibilities: Creating advanced fingerprinting tools to check server software version and exploits If you are interested please mail info@patrolserver.com
72.
▲
Still valuable: a student's guide to startups (9 okt 06)
(paulgraham.com)
1 points
by
dolfje
11y ago
|
0 comments
73.
▲
Cotard delusion: Being alive, but thinking otherwise
(blogs.scientificamerican.com)
1 points
by
dolfje
11y ago
|
0 comments
74.
▲
In the land of XSS ‘possibly safe’ means ‘exploitable’
(h4writer.com)
2 points
by
dolfje
11y ago
|
0 comments
75.
▲
The audiophile’s dilemma: strangers can’t identify $340 cables, either
(arstechnica.com)
1 points
by
dolfje
11y ago
|
1 comments
76.
▲
SpaceShipTwo crash: human error that could be avoided
(arstechnica.com)
2 points
by
dolfje
11y ago
|
0 comments
77.
▲
by
dolfje
11y ago
Glad to see you fixed the issues, I absolutely love it that you acted to fast. You have been removed from the list.
78.
▲
by
dolfje
11y ago
By using multiple versions of multiple software, you can determine the false positives. There are little servers that deliberately fuzz external in a consistent way of all software found. Mostly they only do PHP or Apache, but forget OpenSS
79.
▲
by
dolfje
11y ago
It is definitely not the only measure. There are many more aspects of security. But a hacker only needs to find one gap. So the security is not the average of all aspects, but the minimum. So finding hosters that fail one aspect (outdated s
80.
▲
by
dolfje
11y ago
It is a strong indication, because we are talking about non-packaged versions. PHP 5.3 is still maintained in Ubuntu, so those hosters aren't on the blame list. Only if PHP 5.3 / 5.2 / 5.1 is used without package manager.
81.
▲
by
dolfje
11y ago
Because PHP au contrary to Apache returns the full packaged version (so PHP packaged version are easier to check out). Also having e.g. OpenSSH ubuntu version strongly suggest you are using PHP ubuntu version. In that way we could cross out
82.
▲
by
dolfje
11y ago
The HackerNews effect, was unfortunately down for 3 min. Should be okay now. Apparently login into Wordpress was a query to much.
83.
▲
by
dolfje
11y ago
Yes and then you are using a packaged version. But those hosters don't use a packaged version. So yum update doesn't work. I would definitely advice everybody to use a package manager, because that helps you keep everything secure
84.
▲
by
dolfje
11y ago
To clarify, when we say outdated PHP 5.3, we only mean the standalone PHP version. When an ubuntu version was detected, it was correctly marked as maintained. So all these hosters use 5.3 without package managers.
85.
▲
by
dolfje
11y ago
That is true, there are many manufacturers that keep up to date and add their own patches. Though for a frontpage, I don't think that is true. It is much easier to update your software, than going through all patches, keeping up to dat
86.
▲
Pro-security? Stay away from these hosters
(blog.patrolserver.com)
16 points
by
dolfje
11y ago
|
25 comments
87.
▲
Microsoft is silently preparing your PC for Windows 10
(theinquirer.net)
2 points
by
dolfje
11y ago
|
1 comments
88.
▲
A public marketplace for hackers – what could possibly go wrong?
(arstechnica.com)
2 points
by
dolfje
11y ago
|
0 comments
89.
▲
by
dolfje
11y ago
Yes, the OnePlus 2 is an allround winner. Just alone the dual sim for that price with that specs
90.
▲
Ready for OnePlus 2: dualsim, 4GB RAM, 3300mAh, still inviteOnly
(arstechnica.com)
3 points
by
dolfje
11y ago
|
1 comments
More ›