Re: on the NTP security issues and fixes

2016-04-28 Thread Daniel Poirot
...see my email from yesterday for details from the Cisco disclosure reports. > On Apr 28, 2016, at 3:43 PM, Mark Atwood wrote: > > Folks, > > Late Tuesday night, NTP.org made a release containing 11 security fixes. Some > of these vulnerabilities were also reported to the NTPsec project, an

on the NTP security issues and fixes

2016-04-28 Thread Mark Atwood
Folks, Late Tuesday night, NTP.org made a release containing 11 security fixes. Some of these vulnerabilities were also reported to the NTPsec project, and we planned for a coordinated release and disclosure. Unfortunately, several others caught us by surprise, and this surprise comes at an inconv

...and Raspberry Pi's are not all Good. Some are Evil...

2016-04-28 Thread Dan Poirot
Malicious twist to the 'Set your iPhone back to 1970' social engineering vuln. See: http://krebsonsecurity.com/2016/04/new-threat-can-auto-brick-apple-devices/ [From the article] EVIL HARDWARE According to Harrigan and Kelley, the hardware needed to execute this attack is little more

Some light reading from Oracle

2016-04-28 Thread Dan Poirot
This just in... http://blog.talosintel.com/2016/04/vulnerability-spotlight-further-ntpd_27.h tml Vulnerability Spotlight: Further NTPD Vulnerabilities As a member of the Linux Foundation ( https://www.coreinfrastructure.org/ ), Cisco is contributing to the CII effort by evaluating the