New Server Install - Downtime Ahead

Just a heads up to all of our faithful readers, we are getting a new web server installed this weekend. The results will be a much faster user experience, with foundations laid for a site overhaul when the crew is ready. The downside is that there will be some downtime this weekend. Just wanted to give everybody a heads up, as I'm sure at least one lamer out there will claim to have DDoS'd us offline. Everything should be up and running no later than Monday, August 29th, 2016. While we're still online, you should check out new tutorials by r3q13m - our latest crew member of SX.

r3q13m Promoted to Crew

Congratulations to r3q13m for being promoted to the rank of SoldierX crew for his hard work; on the software projects RAPTORRDP,Mirage Disk Image and his tutorial "Software as a Service (SAAS) demystified from a programming perspective." His enthusiasm is an encouragement, and we await to see more great feats. Again, congrats well deserved!

OFACE ISO Alpha now available!

Up to this point, we have encouraged people to create their own ISOs and thumbdrives to run OFACE. After revisiting this topic though, I have decided to release a proof of concept ISO with the current version of OFACE. Please note that I am in the midst of looking at making OFACE itself more powerful so this is nowhere near finalized yet and that this release is for VIP only. All details along with a download link are available via its SX Labs entry for those who are interested.

Where are some of our tax dollars going?

Today, RaT posted on our forums about a recent connection discovered concerning some recent bot issues that we have had. I won't elaborate much as I feel that he did an effective explanation of it. What I will say is that I am nothing short of outraged by this misuse of tax dollars and the level of shadiness that this supposed place of "higher learning" has displayed. Furthermore, the staff at this university that carried forward with this should be nothing short of ashamed of themselves for employing such disgusting tactics that not only are unnecessary, but are a complete waste of time and money on all sides.

Shinobi Announces Presidential Campaign!

We here at SoldierX usually don't get involved in politics and with good reason. Typically, we have seen that such an involvement could harm our bottom line which is the primary reason. However, this election cycle has been anything but normal to say the least. After watching the primaries unfold, our very own Shinobi has decided that he has had enough and has announced that he will be running for the President of the United States of America.

When asked about his platform, his response was telling about the situation he feels our country is in, and his rhetoric was relentless. "Our country is dealing with a giant mess due to numerous failures to address pivotal issues within the last twenty five years due to party lines, and it's time to end this crap." which is a sentiment shared amongst many amongst the crew. His adoption of the slogans "With Jews You Lose" and "Let's Dump Trump" however is a controversial one. When asked about his choice of slogans, Jewish crew member RaT stated that he didn't approve of the message, but he approves of Shinobi. The most controversial aspect of his campaign is his plan after inaguration, in which he will reportedly defecate on the desks of numerous heads of federal agencies including, but not limited to the NSA, FBI, FDA, USDA, VA, DOJ, DOE, and Department of Homeland Security as he feels that they are in part responsible for the mess the country is in and they should have to deal with their share of the mess.

HardenedBSD secadm 0.3.0 Released

We at HardenedBSD have been hard at work on secadm. Brian Salcedo rewrote core parts of secadm, making it much more efficient. As part of the rewrite, the rule syntax has changed. Please refer to the new secadm.conf(5) manpage for details on the new syntax.

Here's what has changed between secadm 0.2 and secadm 0.3.0:

  • Rewritten backend
  • Integriforce dedup - more on this below
  • Integriforce in whitelist mode - more on this below
  • manpages! secadm(8) and secadm.rules(5)
  • Allow modification and deletion of files that have rules pertaining to them if the rule is disabled
  • Various bugfixes

Integriforce in whitelist mode is a form of verified application whitelisting. When Integriforce is set in whitelisting mode, all desired applications along with their shared objects must have an Integriforce rule. The rtld should also have an Integriforce rule. If an application attempts to start and there is no Integriforce rule for that application or the shared objects it depends on, execution is denied. Whitelisting is only enforced when explicitly enabled and there is at least one Integriforce rule loaded.

As we at HardenedBSD found out with the new rewrite, in the beta releases of secadm 0.3, it was not possible to have Integriforce rules loaded for two files that were hardlinks to each other, like /bin/[ and /bin/test. secadm 0.3 now supports that, but will disregard the second (or following) rules. Both files are still protected as they really point to the same underlying file. As a result, if a hash mismatch occurs, the filename printed out refers to the first rule that matches the hardlinked file.

Download secadm 0.3.0 here. GPG signature is here

Syndicate content