‘Unauthorized Code’ In Juniper Firewalls Could Decrypt VPN Traffic

m2pc writes: Ars Technica reports that Juniper Networks firewalls have been discovered to include “unauthorized code” inserted into their ScreenOS software. Juniper has has published an advisory addressing the matter, with instructions to patch the affected devices. From the Ars article: “NetScreen firewalls using ScreenOS 6.2.0r15 through 6.2.0r18 and 6.3.0r12 through 6.3.0r20 are affected and require immediate patching. Release notes published by Juniper suggest the earliest vulnerable versions date back to at least 2012 and possibly earlier. … The first flaw allows unauthorized remote administrative access to an affected device over SSH or telnet. Exploits can lead to complete compromise. ‘The second issue may allow a knowledgeable attacker who can monitor VPN traffic to decrypt that traffic, ‘ the advisory said.” The rogue code was discovered during a recent internal source code review conducted by Juniper. Read more of this story at Slashdot.

View original post here:
‘Unauthorized Code’ In Juniper Firewalls Could Decrypt VPN Traffic

Developer Claims ‘PS4 Officially Jailbroken’

colinneagle sends word that a developer has claimed to have achieved a jailbreak of the PlayStation 4. Networkworld reports: “If you have a PS4 and want to run homebrew content, then you might be happy to know developer CTurt claimed, “PS4 is now officially jailbroken.” Over the weekend, CTurt took to Twitter to make the announcement. He did not use a jail vulnerability, he explained in a tweet. Instead, he used a FreeBSD kernel exploit. Besides posting “an open source PlayStation 4 SDK” on GitHub, CTurt analyzed PS4’s security twice and explained PS4 hacking. CTurt updated the open source PS4 SDK yesterday; he previously explained that Sony’s proprietary Orbis OS is based on FREEBSD. In the past he released the PS4-playground, which included PS4 tools and experiments using the Webkit exploit for PS4 firmware version 1.76. To put that in context, Sony released version 3.0 in September. However, CTurt claimed the hack could be made to work on newer firmware versions. Other PS4 hackers are reportedly also working on a kernel exploit, yet as Wololo pointed out, it is unlikely there might be more than proof-of-concept videos as the developers continue to tweak the exploit. Otherwise, Sony will do as it has in the past and release a new firmware version. In October 2014, developers nas and Proxima studied the PSVita Webkit exploit, applied it to the PS4, and then released the PS4 proof-of-concept. Shortly thereafter. Sony pushed out new firmware as a patch.” Read more of this story at Slashdot.

More:
Developer Claims ‘PS4 Officially Jailbroken’

MST3K Breaks Kickstarter Record

the_Bionic_lemming writes: Raising over 6.3 million dollars in just one month MST3K fans helped push the new 14 episode series past the Official Kickstarter Veronica Mars total of $5, 702, 153 by raising $5, 764, 229 On Kickstarter. $600, 000 + Was added to the total from the Add on store at MST3K.com . And what’s more, they did it with only 48, 270 backers compared to 91, 585 Veronica Mars backers. Read more of this story at Slashdot.

Visit site:
MST3K Breaks Kickstarter Record

DHS Deployed Plane Above San Bernardino To Scoop Up All Phone Calls After Attack

schwit1 writes: Federal investigators looking into the San Bernardino massacre deployed a spy plane overhead after the attacks in an apparent attempt to find additional suspects. The Department of Homeland Security is said to have put up the single engine craft over the California city and ordered it to make repeated circles overhead. The craft would likely have been equipped with Dirtbox technology which can scan tens of thousands of phones in one go to identify suspects. The report adds to the intrigue about whether or not there were accomplices in the San Bernardino attacks, which took place last Wednesday and were the worst terrorist attack on American soil since 9/11. Read more of this story at Slashdot.

See the article here:
DHS Deployed Plane Above San Bernardino To Scoop Up All Phone Calls After Attack

Locked Intel Skylake CPUs Can Be Overclocked After BIOS Update

jjslash writes: For a few years now, Intel CPU overclocking has been limited to more expensive Core i5 and Core i7 ‘K’ processors. Skylake launched this year with the rumor of strong non-K processor overclocking through an adjustable base clock, but that never eventuated… until now. In overclocking circles it was rumored that BCLK (base clock) overclocking might become a possibility in Skylake processors, but it would be up to motherboard manufacturers to circumvent Intel’s restrictions. Asrock, Asus and a few other motherboard manufacturers are said to be issuing a BIOS update soon that will unlock base clock overclocking on Z170 motherboards. TechSpot has got an early look, overclocking a locked Core i3-6100 to 4.7GHz on air cooling. Read more of this story at Slashdot.

Excerpt from:
Locked Intel Skylake CPUs Can Be Overclocked After BIOS Update

Faraday Future Selects Las Vegas As Home For $1B Electric Car Factory

An anonymous reader writes: Faraday Future, the newest and most unknown player in the electric car game, has selected North Las Vegas as the home for their billion dollar factory. The 3 million square foot factory will be built on 900 acres and create 4, 500 jobs. Faraday Future will release more information on their Tesla fighter, a 100% electric car, at CES in January. Autoblog reports: “Nevada topped finalists California, Georgia and Louisiana in the race to land the 2.5 million square foot plant. It’s expected to sit on 600 acres in North Las Vegas’s Apex Industrial Park and bring 4, 500 jobs to Nevada. Mayor John Lee called the site choice ‘a transformational opportunity’ for his city of about 220, 000 residents. North Las Vegas boomed as the nation’s fastest-growing city in the early 2000s and nearly busted when the recession hit and pushed it close to insolvency.” Read more of this story at Slashdot.

More:
Faraday Future Selects Las Vegas As Home For $1B Electric Car Factory

AVG, McAfee, Kaspersky Antiviruses All Had a Common Bug

An anonymous reader writes: Basic ASLR was not implemented in 3 major antivirus makers, allowing attackers to use the antivirus itself towards attacking Windows PCs. The bug, in layman terms, is: the antivirus would select the same memory address space every time it would run. If attackers found out the memory space’s address, they could tell their malicious code to execute in the same space, at the same time, and have it execute with root privileges, which most antivirus have on Windows PCs. It’s a basic requirement these days for software programmers to use ASLR (Address Space Layout Randomization) to prevent their code from executing in predictable locations. Affected products: AVG, McAfee, Kaspersky. All “quietly” issued fixes. Read more of this story at Slashdot.

Continue Reading:
AVG, McAfee, Kaspersky Antiviruses All Had a Common Bug

Germany Fires Up Bizarre New Fusion Reactor

New submitter insitus writes: On 10 December, Germany’s new Wendelstein 7-X stellarator was fired up for the first time, rounding off a construction effort that took nearly 2 decades and cost €1 billion. Initially and for the first couple of months, the reactor will be filled with helium—an unreactive gas—so that operators can make sure that they can control and heat the gas effectively. At the end of January, experiments will begin with hydrogen in an effort to show that fusing hydrogen isotopes can be a viable source of clean and virtually limitless energy. Read more of this story at Slashdot.

Continue Reading:
Germany Fires Up Bizarre New Fusion Reactor

Microsoft Open Sources and Forks Windows Live Writer Into Open Live Writer

SmartAboutThings writes: Windows Live Writer is a blogging tool that Microsoft originally released back in 2006, and it still remains popular today, which has prompted Microsoft to promise that it will make it open source earlier this year. Now the company has officially open-sourced and forked Windows Live Writer into Open Live Writer, having put its repositories on GitHub already. Read more of this story at Slashdot.

More:
Microsoft Open Sources and Forks Windows Live Writer Into Open Live Writer

French Legislation Would Block Tor and Restrict Free Wi-Fi

Several readers sent word that French newspaper Le Monde got its hands on documents showing the French government is debating two new pieces of legislation that are unfriendly to internet users. The first would ban people from sharing Wi-Fi connections during a state of emergency. “This comes from a police opinion included in the document: the reason being that it is apparently difficult to track individuals who use public Wi-Fi networks.” The second would forbid the use of Tor within France’s borders. “The main problem with such a ban on Tor is that it wouldn’t achieve a whole lot. Would-be terrorists could still access Tor from outside the country, and if they did manage to access Tor from within France I doubt they’re concerned about being arrested for illegal use of the network.” Read more of this story at Slashdot.

See the original post:
French Legislation Would Block Tor and Restrict Free Wi-Fi