spectre-meltdown-checker v0.46 is out with support for #Zenbleed aka CVE-2023-20593. Is your system affected? If yes, is it vulnerable? If yes, can you do something about it? The tool will tell you everything (Linux only for now, BSD soon) https://t.co/HAJKY4HBlU
@fccagou@nolimitsecu Ça commence à bouger avec leur version "Windows Server Core", qui est à priori livrée sans "X11" :) Mais oui ça va sans doute prendre du temps...
@fccagou@nolimitsecu Si on accepte d'administrer du Windows en CLI seulement, y'a probablement moyen oui, surtout que maintenant on peut avoir un sshd pseudofficiel dessus sans installer de soft obscur ! Mais certains cas d'usage (la plupart, sans doute), s'attendent à du RDP malheureusement...
📣The Bastion is now opensource! So glad we could finally make it happen! The announcement is here: https://t.co/1FjBht9qL1. Head on to the GitHub page https://t.co/e98dr0xGzo to give it a try, now you have something to play with this weekend ;)
@HtamNet @DClabaut ...because if there's a problem with the directory, bastions must still stand. There is an additional protection: it can check at each connection that the account still exists in the directory (provide any script that returns ok or ko, preferably using cached information)
@HtamNet @DClabaut We use automation to synchronize the users from the company directory to the bastions (using an account with the accoutCreate and accoutDelete privileges), to get the best of both worlds: centralization of identities and robustness of the bastions...
@DubRzr ...also configurable session locking and/or session termination on input timeout (can be global, per group or per host). In the end it's way more than just a tty recorder, but the files it produces are still standard well-known ttyrec files. :)
@DubRzr Our enhanced (but compatible) ttyrec version has some features we need, such as on-the-fly compression, as we write 2 millions of ttyrecs per *day*, ttyrec log rotation for long sessions (some people like to stay connected for weeks w/o interruption), and...
I'm excited to speak at Open Source Summit + Embedded Linux Conference Europe 2020 https://t.co/vin2Mt0h2P #ossummit with Agata Gruza from Intel! Everything you ever wanted to know about Spectre & Meltdown Checker https://t.co/HAJKY4HBlU