In association with heise online

    Top News

    LinuxTag: LiMux firmly established in Munich

    LiMux logo At the LinuxTag conference, the leader of Munich's Linux migration project, Peter Hofmann, emphasised that the City of Munich has no intentions to switch its Linux desktops to Windows more »

    Top Feature

    Continuous database migration with Liquibase and Flyway

    Continuous database migration with Liquibase and Flyway An application's version-controlled source code is stored in the repository. Why not that of the database? To reproduce arbitrary database states in development, test or production environments, two powerful Java libraries are at hand that can be seamlessly integrated into a build for an agile Continuous Delivery more »

    Top Open News

    Fedora Raspberry Pi remix reborn as Pidora

    Pidora logo Seneca College has released Pidora 18, its Fedora remix optimised for the Raspberry Pi mini-computer. It features a special headless mode that makes it easy to install the distribution over the network more »

    Top Open Feature

    Location, location, location

    Location, location, location The rapid rise in the number of mobile devices has led to a concomitant rise in the amount of location data available. Proprietary services are emerging to take advantage of that data, but open source has a strong foothold in the form of OpenStreetMap more »

    Top Security News

    Twitter implements two-factor authentication

    Twitter logo A code sent by SMS, in addition to the standard password, will improve security for Twitter accounts - not a bad idea, after recent problems with hacked accounts sending out false reports more »

    Top Security Feature

    Skype's ominous link checking: Facts and speculation

    Skype Listening In icon Our associate's discovery that URLs sent through Skype are then visited by Microsoft has caused quite a stir. A little more information has now emerged and leads to even more questions more »

    Top Developer News

    SQLite gets memory-mapped I/O

    SQLite icon The memory-mapped I/O can potentially double the performance of the embeddable SQL engine but care needs to be taken with its use. Other enhancements make SQLite databases easier to identify and improve error reporting more »

    Top Developer Feature

    Continuous database migration with Liquibase and Flyway

    Continuous database migration with Liquibase and Flyway An application's version-controlled source code is stored in the repository. Why not that of the database? To reproduce arbitrary database states in development, test or production environments, two powerful Java libraries are at hand that can be seamlessly integrated into a build for an agile Continuous Delivery more »

    Security news and features

    News & Features

    Thursday, 23 May 2013

    Apple closes QuickTime vulnerabilities on Windows

    Apple patch icon Apple has released QuickTime 7.7.4, fixing 12 critical security holes causing memory corruption and buffer overflows when processing a number of media formats more »

    Wednesday, 22 May 2013

    Chrome 27 comes with better load speeds and security fixes

    Google Chrome logo Chrome 27.0.1453.93 closes 17 security vulnerabilities for which Google has paid out almost $15,000. The newest version of the browser also improves page load speed for pages with many assets more »

    Report: DDoS service as a legitimate, FBI-approved business

    DDOS icon Unscrupulous profiteers are openly offering DDoS attacks as a service. They have no fear of being prosecuted - according to a reputable US blogger, the prosecutors themselves might be on board more »

    Bitdefender Clueful exposes Android spies

    BitDefender Clueful icon Available free of charge, the Clueful app exposes Android programs that don't take users' privacy seriously enough, for example by sending personal information to advertising networks more »

    Google: US counterintelligence service was targeted by Chinese hackers

    Spying icon The hacker attacks on Google in late 2009 may have had a greater impact than previously thought. The attackers reportedly had access to information on foreign agents collected by the US counterintelligence service more »

    Tuesday, 21 May 2013

    Yahoo Japan suspects 22 million user IDs exposed

    Yahoo logo Alerted by the levels of outgoing traffic, Yahoo Japan believes that 22 million user IDs were leaked from their systems but it is confident that no password or other verification data was involved in the exfiltration more »

    Chinese APT1 hacker group ends its spring break

    Network globe icon Back in February, a report by cybersecurity firm Mandiant exposed a Chinese military unit that targeted companies and media in the US. When the New York Times ran a feature on the APT1 group, things went quiet around the group. Now, APT1 has resumed operation more »

    Tails 0.18 can install packages on the fly

    Tails logo The latest version of the live Debian Linux distribution for anonymity and privacy especially in repressive environments is now available with on the fly package updating and support for the latest obfuscation bridges more »

    Monday, 20 May 2013

    NetBSD 6.1 and 6.0.2 released

    NetBSD logo Among the enhancements in NetBSD 6.1 is support for the Raspberry Pi's USB and onboard Ethernet, along with security and bug fixes. The same fixes are also in the newly released 6.0.2 more »

    Search engine available for Internet Census 2012 data

    Network globe icon A convenient online search facility is now available for the enormous amount of data that was accumulated during a port scan of the entire internet more »

    Saturday, 18 May 2013

    The H Roundup - Skype surveillance, Linux exploit & Android Studio

    The H Roundup logo In the week ending 18 May – Microsoft is reading what you type in Skype's chat, an exploit for the Linux kernel is discovered, Google unveils its new IDE for developing Android applications, and the International Space Station is using more Linux more »

    Friday, 17 May 2013

    Lost+Found: Hacking Smart TVs, scammer hotlines and Vaccination

    Lost+Found icon On The H's radar over the last seven days: Samsung's Smart TV software, phone scammers with their own hotline, tricking malware with Vaccination, Qualcomm is pre-installing Kaspersky on Android phones and Twitter account security more »

    Mac spyware takes screenshots

    Gatekeeper icon A newly found item of Mac malware appears to have been signed by its creator but is apparently unable to deliver its cache of screenshots to the two command and control servers it is meant to connect to more »

    Alert!ownCloud fixes critical security vulnerabilities

    OwnCloud logo The ownCloud developers have released versions 5.0.6, 4.0.15, and 4.5.11 to fix a number of serious vulnerabilities in their software including SQL injection, code execution and privilege escalation problems more »

    Thursday, 16 May 2013

    LulzSec trial: sentence handed down for UK hackers

    LulzEnd icon Four hackers from the infamous group LulzSec were sentenced in the UK today. Three of them are facing prison, while the fourth got a suspended sentence more »

    Catching hackers with virtual industrial plants

    SCADA icon What is someone scanning the internet for easily accessible industrial plants actually up to? The SCADA honeypot Conpot can help supply answers to that question more »

    zPanel hacked after support team member insults forum user

    **** The zPanel server is unavailable at the moment, most likely as a result of a hacker attack brought on by a member of the support team who swore at a forum user more »

    RIPE: Attacks on domain name systems are on the increase

    RIPE 66 logo At the meeting of the RIPE IP address registry, discussions revolved around how to get black sheep to implement overdue security measures more »

    Fraunhofer FOKUS institute releases Fuzzino fuzzing library

    FOKUS logo To avoid the need to develop new fuzz testing tools, researchers at Fraunhofer FOKUS institute have created the Fuzzino open source fuzzing library that can be used to add fuzzing features to existing test tools more »

    Wednesday, 15 May 2013

    Exploit for local Linux kernel bug in circulation - Update

    Tux icon A bug that was fixed in the development branch of the kernel back in April was not identified as being security relevant and can therefore still be exploited on many systems more »

    New Yorker opens Strongbox - a Tor-based anonymous drop site

    Strongbox logo The magazine's anonymous drop site is based on DeadDrop, developed by the late Aaron Swartz. Anonymity is in part ensured by only accepting connections via the Tor project's network more »

    Alert!Mozilla's Firefox update fixes three critical holes

    Mozilla icon Critical holes are also closed in Mozilla's Firefox ESR, Thunderbird and Thunderbird ESR, along with fixes for high severity issues; one of the high severity issues is a local privilege escalation through Mozilla's Maintenance Service more »

    Oracle to change Java version numbers

    Java Security icon With an increase in security updates and a need to schedule non-security changes predictably, Oracle has decided to rework how Java updates get a version number more »

    Alert!Microsoft closes 33 security holes in May

    Microsoft patch logo The company has fixed a critical hole in Internet Explorer that is already being exploited by attackers, and patched vulnerabilities in all versions of Windows, in Office, in Windows Essentials, and in other components more »

    Alert!Urgent security patches for ColdFusion, Adobe Reader, Acrobat and Flash

    Adobe patch day Adobe's May Patch Tuesday brings a flurry of security updates that close various critical security holes. Administrators who manage ColdFusion servers should act immediately; the remaining updates should also be installed as soon as possible more »

    Got news? Let us know!


    • May's Community Calendar






    The H Open

    The H Security

    The H Developer

    The H Internet Toolkit