vBSDcon Registrations Remain Open, Join Us In Celebrating 20 Years of FreeBSD!
vBSDcon Registrations Still Open!
As many of you are aware, the social aspect of BSD-related conferences is very important and offers opportunities to meet and socialize with one another. Maintaining that tradition, Verisign’s vBSDcon will feature a mid-conference social, brought to you exclusively by Juniper, and will be celebrating 20 years of FreeBSD. We encourage all attendees to join Verisign and Juniper to celebrate this milestone for the FreeBSD project.
Conference activities start on October 25, 2013 at 6:00PM Eastern with a reception dinner hosted by Verisign at the Dulles Hyatt. General conference activities start the following morning with a presentation by David Chisnall, FreeBSD Core Team member, on the migration from GCC to LLVM/Clang within FreeBSD. David Chisnall is a Research Associate at the University of Cambridge, where he works on the interface between languages, operating systems, and hardware. He is also a member of the FreeBSD Core Team and an LLVM/Clang committer. He is the author of several books, including the Definitive Guide to the Xen Hypervisor. He created the current GNUstep implementation of Objective-C and has maintained it for some years, and is now mostly responsible for the C++ stack in FreeBSD, having implemented the ABI library and ported the STL implementation.
We are in high gear planning for vBSDcon 2013 hosted by Verisign at the Dulles Hyatt in Herndon, VA and we are drawing closer by the week with 5 weeks left to register. Registrations are being accepted on the conference web site at http://www.vbsdcon.com/ through October 23, 2013 after which registrations will be taken in person at the event.
Reminder: vBSDcon Registrations Are Open!
vBSDcon Registrations Still Open!
Users and developers from across the BSD communities are encouraged to attend the event intended bring together members of the BSD community for a series of roundtable discussions, educational sessions, best practice conversations, and exclusive networking opportunities. Those interested in such an opportunity to learn, experience, and meet others involved in the BSD communities should plan to attend vBSDcon 2013.
vBSDcon is proud to bring such prolific speakers like:
- David Chisnall, a member of FreeBSD’s Core Team, speaking on the migration from GCC to LLVM/CLANG within the FreeBSD project.
- Luigi Rizzo, FreeBSD source committer and project developer for netmap, speaking on the Evolution of the Netmap Framework
- Baptiste Daroussin, FreeBSD source committer and project developer for PkgNG, speaking on the topic of PkgNG
- Henning Brauer & Reyk Floeter, OpenBSD developers, speaking on deep packet inspection with OpenBSD and PF
- Scott Long, FreeBSD source committer, speaking on “Disspelling the Stigma of the ‘Dot-oh’ Release”
- Devin Teske, FreeBSD source committer, with “A Comprehensive Look at bsdconfig”
- Kris Moore, PC-BSD Director of Development, speaking on automating deployment of FreeBSD and PC-BSD systems
- John Hixson, of iXsystems, speaking on the topic of FreeNAS plugins
vBSDcon is being hosted at the Dulles Hyatt in Herndon, VA making it extremely convenient for attendees who book their room at the venue. The venue is also just minutes from Dulles International Airport with regular shuttles to/from the hotel and airport terminal during the day. Breakfast, lunch, and snacks will be provided on-site by the hotel’s on premise restaurant.
The schedule includes a reception dinner at the Dulles Hyatt on the evening of October 25th provided by Verisign and a mid-conference social the following evening celebrating 20 years of FreeBSD. Space for off hours hacker lounges and doc sprints will be available in the conference facilities with complimentary wireless internet access. The BSD Certification Group will also be hosting a BSDA certification exam on Saturday evening following the completion of conference activities for the day.
All are invited to take part in this event and are encouraged to register at the vBSDcon web site at http://www.vbsdcon.com/. Simply click the “Register now” button to begin your registration! We look forward to meeting you all there!
vBSDcon 2013 Registrations Now Open!
vBSDcon Registrations Now Open!
In April 2013, Verisign announced vBSDcon 2013 to be held October 25 – 27, 2013 in Dulles, VA. The conference, formatted to resemble an unConference concept, will feature speakers such as David Chisnall, Luigi Rizzo, Baptiste Daroussin, Henning Brauer, Reyk Floeter, and others. vBSDcon will include events like hacker lounges, doc sprints, BSDA exams, and a mid-conference social*.
In these most recent months, they have been developing the vBSDcon conference website hosted at http://www.vbsdcon.com/. It includes full details surrounding the schedule, agenda, and speakers for vBSDcon. The most recent addition to the conference website is that registrations are now open!
* Schedule is subject to change without notice, The BSDA exams are hosted by the BSD Certification group and not an official part of vBSDcon.
Apache/Plesk php Exploit
While reviewing web server logs recently, I spotted the following attack…
216.237.113.27 – – [07/Aug/2013:08:12:14 -0400] “POST
/%70%68%70%70%61%74%68/%70%68%70?%2D%64+%61%6C%6C%6F
%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D
%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+
%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F
%6E%3D%6F%6E+%2D%64+%64%69%73%61%62%6C%65%5F%66%75
%6E%63%74%69%6F%6E%73%3D%22%22+%2D%64+%6F%70%65%6E
%5F%62%61%73%65%64%69%72%3D%6E%6F%6E%65+%2D%64+%61
%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D
%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%6E HTTP/1.1”
404 209 “-” “-”
Which decodes to:
/phppath/php?-d allow_url_include=on -d safe_mode=off
-d suhosin.simulation=on -d disable_functions=”” -d
open_basedir=none -d auto_prepend_file=php://input -n
One aspect of a vulnerable deployment includes an Apache configuration utilizing the following ScriptAlias configuration:
ScriptAlias /phppath/ “/usr/bin/”
For those running Plesk or others with the above configuration, it is recommended that your system be patched accordingly. Check the references below for more detailed information regarding this vulnerability.
References
Disclaimer
This blog is posted for informational purposes only. Extensive testing is recommended prior to implementing changes discussed here.
vBSDcon Website Update…
vBSDcon Website Update…
In April 2013, Verisign announced vBSDcon, a BSD-related conference, in Dulles, VA to occur October 25 – 27, 2013. In the weeks following the announcement, the vBSDcon website was activated with preliminary details on the dates and location of the event. This past weekend, the next phase of development of the website was published. The updated website contains a detailed conference agenda, speaker biographies, and descriptions of speaker’s topics, and more. The website website can be viewed at http://www.vbsdcon.com/.
The next phase of development will include a map detailing conference facilities/location, social event location(s), and local points of interest, restaurants, and recreational activities. Also slated for the next phase is the addition of a sponsor page and attendee registrations. So, check the site often and look for registrations to open up in the coming weeks!
Images are back…
A few weeks ago, the node that hosts hostileadmin.com experienced a catastrophic hardware failure. The hostileadmin blog was affected by this outage in the area of images and downloadable files.
Consequently, I procured virtual hosting services with RootBSD and have moved data from the old node to the VPS service. I am pleased to announce hostileadmin blog images and downloadable files are back!
I apologize for any inconvenience this may have caused.
Upcoming Changes to hostileadmin Blog
hostileadmin.com has experienced a hardware failure in a colocation facility that is geographically difficult to reach in a timely manner. The hostileadmin blog is affected by this outage in the area of images and downloaded files. Thus, blog posts containing images and/or other downloadable files are incomplete.
As a result of this outage, I have procured virtual hosting services with RootBSD and will begin hosting my images and files from this point forward on the new service. At an undetermined point in the future, the data on the failed hardware will be recovered and moved to the RootBSD virtual hosting service.
I have purchased a level of service that affords me the ability to move the majority of my disparate services into a single, more reliable environment. This transition will take place in phases, but will have minimal impact on the blog, which is my most visible area of work at this time.
I apologize for any inconvenience and hope to have services fully restored in the coming weeks.
BSDCan 2013
I attended BSDCan as an attendee and conference organizer. I recently embarked on journey I never thought I would. I am a co-chair for a conference. vBSDcon is the first conference or large event that I’ve organized (apart from my wedding when I married the woman who continually encourages me to grow). Therefore, my perspective of the conference covered multiple facets.
Conference Format
I’ll add that all conferences have an additional track which may or may not be planned…the social track. The social track consists of time spent in the halls between presentations discussing projects with others. It includes time spent at restaurants after the day’s conference activities. It includes time spent at the “big social event” many BSD-related conferences have.
One drawback of multiple tracks is that often there are multiple presentations occurring simultaneously one may wish to attend. This certainly was the case with me a time or two.
Tutorials
BSDCan 2013 had four tutorials scheduled. Of the four, I attended two:
DNSSEC: Theory, Troubleshooting, and Deployment With BIND
Making FreeBSD Ports
Vendor Summit
It was made clear that vendors are interested in having a cohesive and functional Java implementation available. By doing so, it will enable forward progress on the implementation of many other userland applications.
Conference Day 1
Presentations
- Open Source Meets the Commercial World by Eric Allman
- An Overview of Security in the FreeBSD Kernel by Kirk McKusick (Hacking track)
- Benchmarking FreeBSD by Ivan Voras (Sys Admin track)
- Case study: Switching from Linux to FreeBSD by Paul Chvostek (Sys Admin track)
- Lightning Fast Networking In Your Virtual Machine by Luigi Rizzo (Hacking track)
Conference Day 2
Presentations
- Modern Package Management by Baptise Daroussin (Sys Admin track)
- Tales from the North by Dwayne Hart (Sys Admin track)
- The Closing Session: The Wrap Up by Dan Langille
Impressions
All speakers created well thought out presentations all the way from the tutorials through the closing session. The content was relevant and applicable to the track and current trends in the industry. Speakers sufficiently filled their allotted time slot w/ ample time for Q&A. I found several presentations very interesting and relevant to the work I perform.
Overall Experience
This conference was an excellent opportunity for me to gleam concepts and ideas for potential inclusion at vBSDcon hosted by Verisign in October 2013.
vBSDcon website is up!
vBSDcon Website Is Up!
In April 2013, Verisign announced the inaugural biennial vBSDcon event in Dulles, VA to occur October 25 – 27, 2013. In the weeks since the initial announcement, the vBSDcon website has been activated with details on the dates and location of the event. The website is available at http://www.vbsdcon.com/.
Some details have yet to be published, but will be available on the official vBSDcon website in the coming weeks. Please check back periodically for new updates!
vBSDCon: Oct 25 – 27, 2013
vBSDCon Announcement
Save the date as Verisign, Inc. is proud to announce the inaugural biennial vBSDCon to be held October 25 – 27, 2013 at the Dulles Hyatt in Dulles, VA. Please stay tuned as additional details will become available in the next 4 – 6 weeks!
This event will feature speakers like Baptiste Daroussin, David Chisnall, Luigi Rizzo speaking on topics that include PkgNG, Clang/LLVM, netmap. vBSDCon will also feature breakout sessions and birds of a feather type discussions to make this a one of kind BSD-related conference.
