Getting a Linux box corralled into a DDoS botnet is easier than many think

Enlarge (credit: Aurich Lawson and Getty) Getting a Linux server hacked and made part of a botnet is easier than some people may think. As two unrelated blog posts published in the past week demonstrate, running a vulnerable piece of software is often all that’s required. Witness, for example, a critical vulnerability disclosed earlier this year in Elasticsearch , an open source server application for searching large amounts of data. In February, the company that maintains it warned it contained a vulnerability that allowed hackers to execute commands on the server running it. Within a month, a hacking forum catering to Chinese speakers provided all the source code and tutorials needed for people with only moderate technical skills to fully identify and exploit susceptible servers. A post published Tuesday by security firm Recorded Future deconstructs that hacker forum from last March. It showed how to scan search services such as Shodan and ZoomEye to find vulnerable machines. It includes an attack script written in Python that was used to exploit one of them and a separate Perl script used to make the newly compromised machine part of a botnet of other zombie servers. It also included screenshots showing the script being used against the server. The tutorial underscores the growing ease of hacking production servers and the risk of being complacent about patching. Read 5 remaining paragraphs | Comments

See the article here:
Getting a Linux box corralled into a DDoS botnet is easier than many think

FDA Approves Device That Can Plug Gunshot Wounds in 15 Seconds 

The U.S. Food and Drug Administration has cleared the use of the XSTAT 30—an innovative sponge-filled gunshot wound dressing device—for use in the general population. Approved last year for battlefield use, the device can plug a gunshot wound in just 15 seconds. Read more…

Read More:
FDA Approves Device That Can Plug Gunshot Wounds in 15 Seconds 

Apple pushed an update for the new Apple TV today that finally lets you use the Remote app to contro

Apple pushed an update for the new Apple TV today that finally lets you use the Remote app to control the device. Additionally, Apple Music gets Siri support so get ready to sing into your remote. Or something . Read more…

See more here:
Apple pushed an update for the new Apple TV today that finally lets you use the Remote app to contro

Google Finds D-Wave Machine To Be 10^8 Times Faster Than Simulated Annealing

An anonymous reader sends this report form the Google Research blog on the effectiveness of D-Wave’s 2X quantum computer: We found that for problem instances involving nearly 1000 binary variables, quantum annealing significantly outperforms its classical counterpart, simulated annealing. It is more than 10^8 times faster than simulated annealing running on a single core. We also compared the quantum hardware to another algorithm called Quantum Monte Carlo. This is a method designed to emulate the behavior of quantum systems, but it runs on conventional processors. While the scaling with size between these two methods is comparable, they are again separated by a large factor sometimes as high as 10^8. A more detailed paper is available at the arXiv. Read more of this story at Slashdot.

Read the original:
Google Finds D-Wave Machine To Be 10^8 Times Faster Than Simulated Annealing

PlayStation Now offers 12 months of game streaming for $100

For a game streaming service to succeed, it needs three components: a decent library, competitive pricing and reliable, silky-smooth performance. PlayStation Now struggles on all three fronts, but slowly those shortcomings are being rectified. For instance, there’s now a better value subscription plan — $99.99 will net you 12 months of access, which works out at just over $8 per month. Compared with Sony’s existing one-month ($19.99, or $240 per year) and three-month ($44.99, or $180 per year) plans, it’s a steal. Via: Polygon Source: PlayStation Now

See the article here:
PlayStation Now offers 12 months of game streaming for $100

Apple increases iCloud Music Library limit to 100,000 tracks

Apple has made good on its promise to increase the iCloud Music Library limit to 100, 000 tracks. This was previously set at 25, 000, so the change increases the cap threefold. The move was first teased in June , with Eddy Cue, the company’s SVP of Internet Software and Services, promising it would arrive before the year’s end. Via: The Verge Source: MacRumors

Link:
Apple increases iCloud Music Library limit to 100,000 tracks

French Legislation Would Block Tor and Restrict Free Wi-Fi

Several readers sent word that French newspaper Le Monde got its hands on documents showing the French government is debating two new pieces of legislation that are unfriendly to internet users. The first would ban people from sharing Wi-Fi connections during a state of emergency. “This comes from a police opinion included in the document: the reason being that it is apparently difficult to track individuals who use public Wi-Fi networks.” The second would forbid the use of Tor within France’s borders. “The main problem with such a ban on Tor is that it wouldn’t achieve a whole lot. Would-be terrorists could still access Tor from outside the country, and if they did manage to access Tor from within France I doubt they’re concerned about being arrested for illegal use of the network.” Read more of this story at Slashdot.

See the original post:
French Legislation Would Block Tor and Restrict Free Wi-Fi

You Can Now Buy a Self-Drying Jacket to Go With Your Power Lace Sneakers

A few months ago, Nike made every Back to the Future fan’s dream come true by finally releasing sneakers with fully-functional power laces. And now, just weeks before 2015 draws to a close, it looks like Marty’s self-drying jacket from BTTF2 could also become a reality. Read more…

Visit link:
You Can Now Buy a Self-Drying Jacket to Go With Your Power Lace Sneakers

A Sunken Spanish Galleon Worth Billions Has Been Discovered Off the Coast of Colombia

A Spanish galleon sunk in the Caribbean 300 years ago with an exceptionally valuable cargo has been discovered near the port city of Cartagena, Colombia. Called the San Jose , the ship is rumored to contain gold, silver, and jewellery worth an estimated $4 to $17 billion. Read more…

View article:
A Sunken Spanish Galleon Worth Billions Has Been Discovered Off the Coast of Colombia

“Nemesis” malware hijacks PC’s boot process to gain stealth, persistence

Malware targeting banks, payment card processors, and other financial services has found an effective way to remain largely undetected as it plucks sensitive card data out of computer memory. It hijacks the computer’s boot-up routine in a way that allows highly intrusive code to run even before the Windows operating system loads. The so-called bootkit has been in operation since early this year and is part of “Nemesis,” a suite of malware that includes programs for transferring files, capturing screens logging keystrokes, injecting processes, and carrying out other malicious actions on an infected computer. Its ability to modify the legitimate volume boot record makes it possible for the Nemesis components to load before Windows starts. That makes the malware hard to detect and remove using traditional security approaches. Because the infection lives in such a low-level portion of a hard drive, it can also survive when the operating system is completely reinstalled. “The use of malware that persists outside of the operating system requires a different approach to detection and eradication,” researchers from security firm FireEye’s Mandiant Consulting wrote in a blog post published Monday . “Malware with bootkit functionality can be installed and executed almost completely independent of the Windows operating system. As a result, incident responders will need tools that can access and search raw disks at scale for evidence of bootkits.” Read 5 remaining paragraphs | Comments

Follow this link:
“Nemesis” malware hijacks PC’s boot process to gain stealth, persistence