Kernel.org hacked…


The message from kernel.org is consistent with the message from pretty much everyone that gets hacked. 
  • Don’t worry
  • Be happy
  • We know what we are doing
  • Everything is Ok

I’ll be looking forward to something resembling ‘full disclosure’. It should be an interesting read.

Oracle 11.2.0.n - Sev 1, Sev 1, Sev 1, and Sev 1




One database, four SR’s at Sev one. The oldest one has been a one for 16 days.

Nice, eh?

We’re pretty sure that Oracle 11.2.0.wtf doesn’t play anywhere near as nice with our workload as 10.2.0.[45].

FWIW - The ‘SUN box stuck’ SR is open because a diagnostic script that Oracle had us run deadlocked a DB writer on libaio bug in Solaris 10 (Bug 6994922).

Deprovisioning as a Security Practice II

In Service Deprovisioning as a Security Practice, I asserted that using a structured process for shutting down unused applications, servers & firewall rules was good security practice.

On the more traditional employee/contractor deprovisioning process, I often run into managers who view employee deprovisioning as something that protects the organization from the rogue former employee who creates chaos after they leave. If they feel that the former employee is leaving on good terms and unlikely to ‘go rogue’, they treat account deprovisioning as a background, low priority activity.