Syndicate

Syndicate content

Flattr


Flattr this

If you like this, you can use flattr. ;)

Imprint

About
eMail: wishinet at gmail . com
PGP ID: 0xCCCA5E74

Jabber: wishi@jabber.ccc.de

Linux

low footprint/hardware assisted virtualization with Linux and GrSec

In short

I used

  1. a 2.6.32.12 Linux Kernel (newly introduced: Kernel Samepage Merging can lower a virtualization solution's memory consumption)
  2. patched it with the Linux-VServer grsec patch
  3. applied the standard Ubuntu 10.4 Lucid Server configuration
  4. applied grsec "High" preference and customized it (details are in the Kernel config section)
  5. optimized it for KVM, VMware (software binary translation gets switched on by internal heuristics - chpax is still necessary if you want that feature and that is intended that way), and of course Vserver (just works). KVM Qemu works due KVM works.

Postfix troubleshooting - a security nightmare

Why to hate typical Unix mailserver setups

I hate that stuff - and it's not that Postfix in particular sucks. But integrating with Postfix is absurd. Surely it works, and as long as it works nobody changes that stuff on how it's designed.


Ohne Titel.png

Even deploying an SSL/TLS setup is challenging. But no, you also need to install proper authentication. Locally, Postfix (for unknown reasons) is chrooted. People think that this is a security feature.

A practically secure mail setup - counter spammers with Linux mail-servers

Who needs this?

Bild 1.JPG
Yay, free mails in a sustaining setup!

This is a tutorial on how to practically setup a relatively secure mail-server.

It's supposed to be as minimal as reasonable nowadays, and for a small amount of users (standard root server, max. ~20 mail-users at once). Without a real DB backend. It doesn't scale business-needs, however it's supposed to be extendable.

The reference system this setup works with is a Debian GNU Linux with:

  • Maildrop - instead of Procmail for more flexible filter rulesets
  • Postfix and Postfix-pcre ~ 2.7

Building a cheap home-hacking lab

wishi's Fuzz-Box

1358588557_ce4ea79d16.jpg

A Fuzz-Box for me is a standalone machine. It has to:

  • host multiple virtual machines at once (max 2 in my case)
  • effectively manage ~4 GB RAM
  • be Linux compatible with, stable clean device drivers
  • energy efficient and ergonomically able to run 24h/day 7d/week...

Scaling Hardware?

You don't want a performance monster. - Or a gaming machine. And you do not want trash, because you're going to spend valuable time with it.

Best of securitytube for RE and security

A collection of tutorials, videos and fun

I think it's an amazing site. There're many video tutorial sites these days. However the quality differs a lot. In the following I listed stuff I like so far. Feel invited to watch everything:

Programming

Python programming course from MIT - the advanced stuff may be of some interest, however it starts of with fairly trivial and introductorily mentioned stuff.

Stack is protected: so we don't need secure coding?

Do anti-exploitation strategies displace secure programming?


Rumors say you were able to change the color from blue to red.

Get grsecurity for Debian now

Setting up the server

If you do this, you want three things:

  • a clean and secure setup, that ensures your availability - even if you're working on a remote-server
  • easy steps
  • drinking a coke or a coffee during this setup. No beer. Because kernel-upgrades and beer don't work together

Okay, what's grsecurity and why do I need it

Easily said: it's doing everything to prevent successful exploitation, like we recently saw happening on Linux through SCTP, ptrace or UDEV.

Save the nature. Don't print this!


I provide textual exports for every blog entry. However let's save the nature together. The nature is everything around us. Every being should be respected. Save the nature - don't print too much.


Die Umgehung dieser Ausdrucksperre ist nach § 95a UrhG verboten!
Inhaltlich Verantwortlicher gemäß § 10 Absatz 3 MDStV: Marius Ciepluch - Anschrift via eMail. Die eMail Adresse entnehmen sie dem Impresseum dieser englischsprachigen Seite.
Aus Datenschutzgründen habe ich weder offiziellen noch behördlichen Schriftverkehr via eMail. Dazu ist die postalische, beim Dienstleister hinterlegte, Anschrift zu verwenden.

Datenerfassung

Es werden keine personenbezogenen Daten erfasst. Logdaten werden anonymisiert.