Heads Up For Linuxbros

Putting this here for Linuxbros since I work in Security and this was just released today

add this line to /etc/sysctl.conf:
net.ipv4.tcp_challenge_ack_limit = 999999999

THERE IS A FLAW IN RFC 5961 that will open your traffic
FUCKS ALL LINUX KERNELS FROM 3.6 up BUT EASILY MITIGATED


theregister.co.uk/2016/08/10/linux_tor_users_open_corrupted_communications/
Archive: archive.is/7UNYe

thehackernews.com/2016/08/linux-tcp-packet-hacking.html
Archive: archive.is/oabhl

Other urls found in this thread:

cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5696
usenix.org/conference/usenixsecurity16/technical-sessions/presentation/cao
zdnet.com/article/fbi-refuses-to-release-tor-exploit-details-evidence-thrown-out-in-court/
youtube.com/watch?v=neaEc55kuXQ
youtube.com/watch?v=qznLBa1Ruz8
en.wikipedia.org/wiki/PRISM_(surveillance_program)
archive.is/OBGB1
archive.is/tW6fu
archive.is/2XIvX
archive.is/qLRZx
archive.is/Zny36
archive.is/sz1nt
archive.is/g3QdQ
archive.is/ko469
youtube.com/watch?v=nHA2s04Vtdc
archive.is/QnTTA
archive.is/eZKc9
d2.maxfile.ro/rwspylwbwo.webm
youtube.com/watch?v=xDeHqiydk4A
archive.is/vhjwm
archive.is/2jehd
archive.is/MB0Yy
archive.is/Tqv7s
archive.is/s3BjC
archive.is/Yy9JB
archive.is/3yo92
archive.is/Dln44
archive.is/2Vw55
archive.is/0ltgw
archive.is/9HETF
archive.is/mO3aH
twitter.com/AnonBabble

Shameless self bump:

Thanks for the fix, OP. It's scary how this exploit has gone unnoticed for four years; I wonder how many people have been affected by it?

bug date was 12-07 and was already fixed on 13-07 in fedora and Red hat, you are late to the party fag.

If you are using a meme distro like ubuntu, Arch, Suse, debian, Gentoo it is your own fault.

Isn't that the NSA distribution? I don't know how much stock I'd put in Poettering in defending my freedums. I prefer the kike hating Mint devs.

Kike hating, source?

...

I think those were the devs that said they didn't accept any donations from israeli users.

...

Nice but I wouldn't exactly call them kike haters. Clem is probably a cuck. All libtards and cucks support Palestine and hate Israel, just because of "muh feels" and nothing to do with being redpilled on Jews.

...

Would you turn away Jew haters? You need to take a lesson in game theory. If anything, these people are already redpilled on Jews if they acknowledge their warmongering in the region, the rest is just convincing them that the Tribe doesn't limit its activities to their neighbors.

That's an opening.

mac are obviously superior
they can't get viruses and dumb exploits like OP
shudup you poorfag, buy a mac

...

Despite the old /g/ meme, Gentoo is pretty fucking great. It's very flexible, and between USE flags and configuring your kernel, Gentoo's probably one of the most flexible distros out there.

Bump this is pretty big

Terrible logic

Yeah nah

gotta love open source

full of fucking bugs, but you're responsible for fixing them

better than closed source which is also full of bugs and the people responsible never do shit and you never get a chance to change it yourself

still tho

You can do this in any distro. Why gentoo is a meme is that it will compile absolutely everything from source (and you're not setting flags for all these programs no matter how autistic you are).
Insane defaults does not a good operating system make.

DELET THIS

DELET THIS

You can do most of those things in any distro, but Gentoo's design lends itself to doing those things easily and naturally through its package management. And, if you don't like it, you still have the option to use binary packages. Basically, there's just a lot freedom of choice that Gentoo has that many distros don't.

I'm not optimistic about Israel hating lefties turning on to the JQ, but I guess that's our job to expose them to these ideas to which normally they never are.

Is mint the best or should I use another one?

Mint is good. Fuck the haters who call it a meme distro. If you aren't a too much into computers, no use going for Fedora or Red hat.

I put a guide on >>>/poltech/

look before you try

Yeah tell that the people who got their iCloud hacked. You're supposed to be the first poster and to sage.

Reported for faggotry.

The fact that desktop Linux is a military backdoor is all rather superfluous because all consumer hardware is compromised anyway. We have absolutely no idea what's in Intel/AMD's bullshit firmware (but I can tell you now it's extremely powerful). Trying to protect yourself at the operating system level is like trying to brave the vacuum of space by holding your breath.

What?

well done OP you are not a fag

They are still considering making the complete switch to systemd?

What difference will this make for my ubuntu webserver running apache+php?
I don't want to be waked up by all my customers tomorrow morning

Mostly redhat

Just a tip for NEW linux users.

After doing what op said you also need to activate it in terminal:

sudo sysctl -p

wouldn't a reset do it?

Try a command too, if you don't want to reset or isn't convinced that reset will enable it.

fair enough

...

...

...

Is Lennart Poettering a jew? It would explain a lot.
From his wiki bio it sounds like the opposite:
But he's such a cunt.

Faggot

He's just a good goy front for (((Red Hat))), Gentoo boards had a great post on how young egocentric "revolutionary" types are used and manipulated by shadow forces

Why was it named poltech ?
It sounds like when leftypol tried to make their own Holla Forums


Link ?

it was taken over in the last month or so as a dead board or something when some anons were discussing how leftist Holla Forums is

I just installed mint the other day. I'm trying to do this in the terminal and it won't give me access to the directory. How do I fix this?

trying to do what? change the file in the OP?

it requires admin access dummy you gotta do it with admin rights

sudo nano /etc/sysctl.conf
then it asks you for your password and you can add the line

also did you mean directory or file?

I was trying to navigate to /etc/ and open the file with the terminal and it wouldnt let me. I entered the command you gave me and I opened the file i guess, do I just add the line to the file?

sudo is super user do, lets you do stuff with admin power

nano is a text editor like vim and emacs

cd /etc would get you into the /etc directory

yes do like the OP says and just add it to the end of the file and dont use a #

that is for comments and it won't do anything if you put it after that

scrub

it comes with mint unlike vim and emacs

Thanks mate. Just saw this an hour ago, bumping this for others to see.

I actually agree with this. The leftards I play DnD with were all flabbergasted when I told then I hated Israel and supported Palestine (well, that's a bit disingenuous, I "support" them merely to spite jews, but they don't need to know that.) It was like they couldn't understand that I was wearing a Trump hat, but am in fact not a republicuck. Polite sage for off topic.

Pic related, I always bully the halfling in game.

Nano is actually ok tbh, but vim is much more powerful once you get used to it. I can't speak for emacs, never have used it.

I honestly don't use either for code, been using sublime2, but I don't code enough to have an opinion

oh and gedit and notepad++

bump

interdasting

lol

Daily reminder to ditch windows.

I recommed Mint for beginning, vid related.

...

I'm using Fedora, so it's already fixed on my end.

This was a serious vulnerability that went undetected for a long time, but it was never exploited in the wild to any significant extent, because this pattern of traffic would be extremely obvious to any sysadmin. People would have noticed something fishy if, say, the NSA were using this to discover TOR users.

But checking the CVE it looks like it was an instream patch on fedora, go fedorafags! Now for everyone else, best get to fixin'

cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5696
usenix.org/conference/usenixsecurity16/technical-sessions/presentation/cao


And what is wonderful about linux, this could have sat as a known vulnerability with no patch for Christ knows how long and been exploited by fuck knows who well we know who. Here it's a one line fix (that you can do yourself) if you need to wait for a fix (or use an old kernel like a huge number of web-servers do).


Fancy all of those TOR users were busted and the FBI refused to give out the "how". Probably not this but you never know.

zdnet.com/article/fbi-refuses-to-release-tor-exploit-details-evidence-thrown-out-in-court/

Why are .rpm distros such shit and how do I convert .deb to work on them?

I want to use the chameleon one. No reason, I just like the chameleon.

Its a pretty dank chameleon. Reminds me of Kek a little.

...

The dank distro.

SUSE is good. Personally I would roll Fedora or Arch as your daily driver. If you want to get real crazy then go install freeBSD.

Also the TechSnap and LAS podcasts are pretty dank too
youtube.com/watch?v=neaEc55kuXQ
youtube.com/watch?v=qznLBa1Ruz8

Earlier today I had an issue where, for some reason, my IP address was wrong. Like I was being sent through a VPN. Google and IRC were treating me as if I had a spammer's IP address.
I know this is a common virus issue on Windows but couldn't find any explanation for why that would happen on Linux and, after turning on my actual VPN, it went away.
So could someone explain if this is related to me? I was seriously freaked out by it, and still don't really have an explanation.

This is a new standard of TCP, so bugs are actually expected. The reason this isn't in Windows or Mac OS X is because they haven't implemented the new standard at all.

Bump

there is no advantage to having a seperate root and home unless you have them on seperate disks.

false. As long as they share the same bus, or even bios, it's a moot point.

This is reportedly fixed in kernel 4.7 which was pushed in the last day or so. Update your system if you're arch master race.

dude I have had my IP's randomly change to German IP's, if you post about the Halocaust they will try to intercept your traffic and find out if you are a European so they can arrest you for hatespeech (Im American though)

I think you mean Void master race

That's fucked up. I don't have the IP address anymore but it was apparently a TOR node. I have TOR installed but never run it.

I'm in the US so I guess if that's what they wanted to do then uh, whatever I guess?

After I change the config in OP and commit the change, do I have to restart my computer to break a connection or should I be good on that front?

the bus can handle more traffic than either disk are capable of, and putting them on seperate disks means that if you misconfigure a script it'll only fill or thrash one disk.

the advantage isn't for security, don't be retarded. bios and bus are irrelevant, these two disks would share the same kernel.

So wait, Ubuntu and it's versions are vulnerable then?

...

I managed to do it on Xubuntu.


Did this

And then (nano 2.5.3) ctrl + O to save the file and ctrl + X to exit.

Arch Linux bro here, I don't use Tor because it is shit slow and I prefer VPN.

Also, I'm not going to go to winshit or macfag because they are literally NSA-built operating systems.

Microsoft is part of NSA's mass surveillance program "PRISM":
en.wikipedia.org/wiki/PRISM_(surveillance_program)

Microsoft informs the NSA about bugs before fixing them:
archive.is/OBGB1

Microsoft openly offeres cloud data to support PRISM:
archive.is/tW6fu

Microsoft has backdoored its disk encryption:
archive.is/2XIvX · archive.is/qLRZx

Windows snoops on the users' files, text input, voice input, location, contacts, calendar records and web browsing history, even after related settings are turned off:
archive.is/Zny36 · archive.is/sz1nt
archive.is/g3QdQ · archive.is/ko469
youtube.com/watch?v=nHA2s04Vtdc

A Traffic Analysis of Windows 10:

Keypoints: Windows 10 has a keylogger and uploads all your keystrokes every 5 minutes. Everything you type in Edge or Cortana is sent to Microsoft, along with any media files it finds. When webcam is enabled, 35MB of data goes to Microsoft.
Even with Cortana disabled/uninstalled, Windows 10 sends all microphone audio to Microsoft, when the computer is idle.
archive.is/QnTTA · archive.is/eZKc9

Windows 10 sends desktop screenshots straight to Microsoft:
d2.maxfile.ro/rwspylwbwo.webm
youtube.com/watch?v=xDeHqiydk4A

Windows 10 scans for illegal/pirated software:
archive.is/vhjwm
archive.is/2jehd

Microsoft proudly presents surveillance statistics:
archive.is/MB0Yy


Microsoft owns Pando Networks, famous for the malware/botnet Pando Media Booster.
Windows Update in Windows 10 utilizes P2P by default, most likely the same P2P technology used by Pando Media Booster.
Essentially it turns your PC into a zombie host server, wasting your bandwidth serving updates to other computers.
This also means Windows Update might be utilized later to spread malware through the P2P system via 0days.
archive.is/Tqv7s · archive.is/s3BjC · archive.is/Yy9JB

You cannot turn off "Telemetry" unless you own Windows 10 Enterprise Edition, this means your computer will continuously leak unspecified information to Microsoft and there's no way of turning this off.
archive.is/3yo92
You cannot turn off "Real-time Protection", aka Windows Defender. Even if you do it will turn itself on again after a while.
This means you cannot prevent your PC from sending random files and information to Microsoft for "analysis".
archive.is/Dln44
Cortana has zero local storage functionality and does not function unless you have a Microsoft Account connected.
It will even inform you about this if you try using it on a local account, and then shut itself down.
archive.is/2Vw55
Windows 10 start menu will have "Content suggestions" which are on by default, which means you'll be seeing ads.
archive.is/0ltgw
Windows 10 "Wifi Sense" will be begging for your Facebook account details so it can get to know you better.
It will also be sharing your Wifi password with all your Facebook/Skype/Outlook friends, their friends, as well as Microsoft.
archive.is/9HETF · archive.is/mO3aH

The advantage is that if you want to upgrade your OS, you don't need to move all your /home partitionfiles.

user I really like your webm, I'm gonna put it in the install guide thread

Well, this certainly explains why 10 is such total garabage even without the spying, they spent all the money on making it spyware instead of a decent os.

OpenSUSE is really nice, what problems are you having with RPMs? The opensuse build service was quite nice and I could usually find everything I needed from there.

Otherwise, use FreeBSD or OpenBSD.

Which version of Linux Mint is easiest for a windows convert to get in to? Which has the best support?

I am trying to decide between Cinnamon, MATE, and xfce

I have a spare SSD to for a dual booting but I want switch over to Mint for daily use.

pay no attention to the gifs I just didn't have anything appropriate for asking a question.