Mitigating the log4j Vulnerability (CVE-2021-44228) with NGINX

2021-12-15 KENNETH 0

Mitigating the log4j Vulnerability (CVE-2021-44228) with NGINX Friday, December 10, 2021 is a date that will be remembered by many IT folks around the globe. It’s when a highly critical zero‑day vulnerability was found in the very popular logging library for Java applications, log4j. The name “Log4Shell” was quickly coined for the exploit, and companies of all sizes rushed to implement mitigation strategies. This was followed by a patching marathon which at the time of writing is still ongoing. NGINX and F5 have analyzed the threat and in this post we offer various mitigation options to keep your applications protected. What is Log4Shell? Version 2.15 and earlier of the log4j library is vulnerable to the remote code execution (RCE) vulnerability described in CVE-2021-44228. (Version 2.16 of log4j patches the vulnerability.) Log4Shell is the name given to the exploit of this vulnerability. [ more… ]

No Image

USN-5193-1: X.Org X Server vulnerabilities

2021-12-15 KENNETH 0

USN-5193-1: X.Org X Server vulnerabilities Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled certain inputs. An attacker could use this issue to cause the server to crash, resulting in a denial of service, or possibly execute arbitrary code and escalate privileges. Source: USN-5193-1: X.Org X Server vulnerabilities

No Image

Sea of Thieves Festival of Giving is now underway

2021-12-15 KENNETH 0

Sea of Thieves Festival of Giving is now underway Between now and Dec. 27, Sea of Thieves players can take part in the Festival of Giving, where presents are given to generous pirates who share their loot with their fellow freebooters. “During this carnival of the charitable, you can unlock new Wreath of Winter items and earn gold and Seasonal Renown by having other crews hand in your loot,” says a post on SeaOfThieves.com. Head over to the post  to find out how it all works. Source: Sea of Thieves Festival of Giving is now underway

[도서] 유닉스·리눅스 시스템 관리 핸드북 5/e

2021-12-15 KENNETH 0

[도서] 유닉스·리눅스 시스템 관리 핸드북 5/e 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]유닉스·리눅스 시스템 관리 핸드북 5/e 에비 네메스,가스 스나이더,트렌트 헤인,벤 웨일리,댄 맥킨 저/김세영,정윤선 역 | 에이콘출판사 | 2022년 01월 판매가 57,600원 (10%할인) | YES포인트 3,200원(5%지급) 유닉스, 리눅스 시스템 관리자에게 필요한 방대한 사항을 하나하나 설명한다. 기본적인 시스템 관리에 필요한 사항뿐 아니라 현대에 집중 조명되고 있는 클라우드 컴퓨팅 및 가상화에 필요한 사항들도 함께 다룬다. Source: [도서] 유닉스·리눅스 시스템 관리 핸드북 5/e

No Image

Minecraft Dungeons releases first Seasonal Adventure: Cloudy Climb

2021-12-15 KENNETH 0

Minecraft Dungeons releases first Seasonal Adventure: Cloudy Climb The first Seasonal Adventure from Minecraft Dungeons – Cloudy Climb – has arrived, and it’s free. “Cloudy Climb – an update all about heights and aiming for the top – contains plenty of new content for climb-enthusiastic adventurers to enjoy: a mysterious tower to explore and test your skills in, the introduction of a new reward track system and many new themed cosmetic items such as skins, pets, flairs, emotes and capes,” says a new post on Minecraft.net. “And while there’s an option to purchase a second reward track, the update is otherwise completely free.” Head over to Minecraft.net for all the details and to watch the launch trailer. Or just boot up Minecraft Dungeons, where Season one is in full swing. Source: Minecraft Dungeons releases first Seasonal Adventure: Cloudy Climb