Tusentals hyllade Chavez på årsdag SvD Utrikes(cached at March 5, 2014, 11:33 pm)

Årsdagen av den tidigare presidenten Hugo Chavez död avlöpte på onsdagen lugnt i Venezuela.
Ferocious dino was European giant BBC News | Science/Nature | UK Edition(cached at March 5, 2014, 11:30 pm)

Portuguese scientists identify a dinosaur that may have been the largest predator ever to roam across the European landmass.
Equating Civil Liberties with Privacy (InfoRiskToday) SANS ISC SecNewsFeed(cached at March 5, 2014, 11:30 pm)

Rampant FireEye Shares Makes Founder Ashar Aziz A Cybersecurity Billionaire (Forbes) SANS ISC SecNewsFeed(cached at March 5, 2014, 11:30 pm)

TCP/5000 - The OTHER UPNP Port, (Wed, Mar 5th) SANS Internet Storm Center, InfoCON: green(cached at March 5, 2014, 11:30 pm)

We've all read a lot about the scans and exploits of UPNP (Universal Plug N Play), on UDP port 1900.  Jens, one of our readers, pinged us this morning with a question about an uptick he was seeing in TCP/5000, which is also listed as UPNP - who knew?  (not me, that's who!)

After a quick check, I'm seeing an uptick in attack activity on TCP/5000 starting in mid-February, both in our dshield database and on various customer firewalls.  Our reader was seeing his attacks come from an IP allocated to China, but I'm seeing more attacks sourced from the US.

https://isc.sans.edu/port.html?startdate=2014-02-03&enddate=2014-03-05&port=5000&yname=sources&y2name=targets


Does anyone have any of these attack packets captured, preferably more than just SYN packets? 

Or if anyone has a sample of the attack software or any malware involved, we'd of course love a sample of that as well !

===============
Rob VandenBrink
Metafore

(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Ask Slashdot: Reviewing 3rd Party Libraries? Slashdotby Soulskill on programming at January 1, 1970, 1:00 am (cached at March 5, 2014, 11:02 pm)

Carcass666 writes "It is usually good to use existing libraries, rather than reinventing the wheel, especially with open source. Unfortunately, sometimes we have to work with closed source implementations. Recently, we were diagnosing a .NET assembly and, after getting nowhere with the vendor, ran it through a decompiler. The code was a morass of SQL concatenation, sloppy type conversions, and various things that are generally thought of as insecure. My question is: What are Slashdot readers' preferred tools for analyzing .NET and Java compiled libraries (not source code) for potential security vulnerabilities? Ideally, I would like to know if a library is a security liability before I code against it. For example, Microsoft used to have something called FxCop, but it hasn't been updated for current versions of the .NET framework."

Read more of this story at Slashdot.








Bitcoin Mass Hysteria: The Disaster that Brought Down Mt. Gox (Forbes) SANS ISC SecNewsFeed(cached at March 5, 2014, 11:00 pm)

Mathematicians Are Chronically Lost and Confused Slashdotby Soulskill on math at January 1, 1970, 1:00 am (cached at March 5, 2014, 10:32 pm)

An anonymous reader writes "Mathematics Ph.D. student Jeremy Kun has an interesting post about how mathematicians approach doing new work and pushing back the boundaries of human knowledge. He says it's immensely important for mathematicians to be comfortable with extended periods of ignorance when working on a new topic. 'The truth is that mathematicians are chronically lost and confused. It's our natural state of being, and I mean that in a good way. ... This is something that has been bred into me after years of studying mathematics. I know how to say, “Well, I understand nothing about anything,” and then constructively answer the question, “What’s next?” Sometimes the answer is to pinpoint one very basic question I don’t understand and try to tackle that first.' He then provides some advice for people learning college level math like calculus or linear algebra: 'I suggest you don't worry too much about verifying every claim and doing every exercise. If it takes you more than 5 or 10 minutes to verify a "trivial" claim in the text, then you can accept it and move on. ... But more often than not you'll find that by the time you revisit a problem you've literally grown so much (mathematically) that it's trivial. What's much more useful is recording what the deep insights are, and storing them for recollection later.'"

Read more of this story at Slashdot.








NATO to suspend cooperation with Russia AL JAZEERA ENGLISH (AJE)(cached at March 5, 2014, 10:30 pm)

Announcement comes as diplomats meet over Ukraine crisis and US says it will give more military aid to eastern Europe.
EMCVoice: What Motivates Employees To Succeed? (Forbes) SANS ISC SecNewsFeed(cached at March 5, 2014, 10:30 pm)

Apple Support for Snow Leopard Wanes TidBITS(cached at March 5, 2014, 10:03 pm)

It appears that Apple has pushed Snow Leopard off the back of the support truck, releasing the most recent security fixes only for Lion, Mountain Lion, and Mavericks. Adam Engst explains what’s likely behind the decision and offers suggestions on what Snow Leopard users can do next.

 

Read the full article at TidBITS, the oldest continuously published technology publication on the Internet. To get a full-text RSS feed, help support our work and become a TidBITS member! Members also enjoy an ad-free version of our Web site, email delivery of individual articles, the ability to make long comments with live links, and discounts on Take Control orders and other Apple-related products.

Type Ia Supernovae As Not-Quite-So-Standard Cosmological Candles Slashdotby Soulskill on space at January 1, 1970, 1:00 am (cached at March 5, 2014, 10:02 pm)

Shag writes "Type Ia supernovae are used as cosmological 'standard candles' to measure distance because of their strong similarity to one another. This has made possible, for example, the research into universal expansion that led to the Nobel-winning discovery of 'dark energy.' For years, astrophysicists believed white dwarves exploded when they accreted enough mass from companion stars to reach a limit of 1.38 times the mass of our Sun. A decade ago, the 'Champagne supernova' (SN 2003fg) was so bright astrophysicists concluded the limit had been exceeded by two white dwarves colliding. Now a new paper (PDF) from the Nearby Supernova Factory collaboration suggests that type Ia supernovae occur at a wider range of stellar masses. Fortunately, there appears to be a calculable correlation between mass and light-curve width, so they can still fill the 'standard candle' role, and research based on them is probably still valid. (I took data for the paper, but am not an author.)"

Read more of this story at Slashdot.








Oregon Withholding $25.6M From Oracle Over Health Website Woes Slashdotby Soulskill on oracle at January 1, 1970, 1:00 am (cached at March 5, 2014, 10:02 pm)

itwbennett writes "Oregon is holding back $25.6 million in payments from Oracle (out of some $69.5 million Oracle claims it is owed) over work the vendor did on the state's troubled health care exchange website. The site was supposed to go live on Oct. 1 but its launch has been marred by a slew of bugs and it is not yet fully functional. This week, Cover Oregon said it had reached an agreement with Oracle laying out 'an orderly transition of technology development services, and protects current and future Cover Oregon enrollees,' according to a statement. Oregon officials reached the deal with Oracle after the company reportedly threatened to pull all of its workers off the project and essentially walk away."

Read more of this story at Slashdot.








DigitalOcean-0.09 search.cpan.orgby Adam Hopkins at January 1, 1970, 1:00 am (cached at March 5, 2014, 10:01 pm)

An OO interface to the Digital Ocean API.
Test-Warn-0.30 search.cpan.orgby Alexandr Ciornii at January 1, 1970, 1:00 am (cached at March 5, 2014, 10:01 pm)

Perl extension to test methods for warnings