Posts by Banny

    Source -

    Code
    http://www.ghacks.net/2012/09/02/warning-java-still-vulnerable-after-patch/?_m=3n%2e0038%2e630%2ezm0ao029l4%2en8g


    Oracle pushed out a patch a few days ago that resolves the security issue In Java 7 Patch 6 and earlier. Polish-based security company Security Explorations however discovered a new vulnerability in Oracle’s patched version that attackers can exploit to get out of the Java sandbox on vulnerable systems to execute code on the operating system.


    The company has informed Oracle about the new vulnerability, and won’t release public information or proof of concept code until Oracle addresses the issue. What’s interesting in this regard is that the company claims to have submitted 29 Java 7 vulnerabilities to Oracle in April, of which two have been actively exploited by attackers in the last days.


    What does this mean for Java users? If you do not need Java and are sure about it, your best bet is to uninstall it from your system. Your second best bet after that is to disable Java in all of your web browsers, or use a feature like click to play (Chrome click to play, Firefox click to play) or a security add-on like NoScript to block Java contents from being executed when you load a web page.


    Most computer users do not need Java, especially not in the web browser. While there are great programs available that have been developed in Java, like RRSOwl, JDownloader or the popular game Minecraft, it is a technology that the majority of users do not need installed on their systems due to lack of programs or applications. If you are running a Java desktop program and want to keep using it, you may want to check out Java portable, a portable version of Java that is not adding itself to web browsers and only running when you launch the program.

    With all the Zoostorms posted, if you wanted a machine to act as an multi purpose server, personally id go with this (what do others think?) -


    Code
    http://www.ebay.co.uk/itm/ws/eBayISAPI.dll?ViewItem&item=251093589524&clk_rvr_id=382579448053


    Twin (2) x Xeon Quad Core L5410 CPUs
    8 x 2.33GHz total processing power
    16GB RAM and 1TB (1,000GB) SATA hard drive
    Upgradeable to massive 128GB RAM -16 DIMM slots
    and 3 x 4TB (12,000GB) SATA HDD - 3 Hot plug caddies
    Intel S5400SF motherboard & Delta TDPS-600CBC PSU


    Shame im having a cash flow problem, id be tempted myself.


    Slightly related - Don't supose, anyone knows anyone who buys PC Parts, in bulk round NW Area, as id rather sell them all and get something like this.

    Here are the results for home users on Windows 7 each is scored in 3 categories Protection, Repair and Useabilty.


    The last tests were done in May/June
    Home -

    Code
    http://www.av-test.org/en/tests/home-user/mayjun-2012/


    Coperate

    Code
    http://www.av-test.org/en/tests/corporate-user/mayjun-2012/


    The 2011 awards went as follows -


    The AV-TEST AWARD FOR BEST PROTECTION 2011 will be presented to the best product of the year in terms of its protective effect as a security solution. The candidates were examined using a variety of types of current malware in order to test how they respond to threats. These examinations took the entire functionality of the protection programs into account.


    Home User: Bitdefender Internet Security,
    Corporate: F-Secure Client Security.
    The AV-TEST AWARD FOR BEST REPAIR 2011 will be presented in recognition of the repair performance of a security solution. We evaluated the products' ability to remove active malware and to restore other system changes, as well as their performance when detecting and removing specially hidden malware (rootkits).


    Home User: Kasper*** Internet Security,
    Corporate: Kasper*** Endpoint Security.


    The AV-TEST AWARD FOR BEST USABILITY 2011 will be presented to the security software that has the least influence upon a system once installed. The candidates were examined according to warning messages, general messages and blockages and false positives during system scans, as well as whether the computer slowed down while the software was being used.


    Home User: ESET Smart Security,
    Corporate: Microsoft Forefront Endpoint Protection.



    Some of these will come as little surprise, and some you will be surprised how much they have improved.

    I put smargo as that what I was going to use originally my bad there, they are omnikeys.


    Where do I get the corresponding camkey/camdata from, or which patched version of OSCam?

    No drivers are required as far as I know
    Lsusb will tell you which usb port your device is connected to


    Your reader will end up being something like -


    [reader]
    label = uk
    description = ***uk
    protocol = pcsc
    device = 000:000
    caid 09*3
    ecmwhitelist = blahh blahh
    detect = cd
    mhz = 480
    cardmhz = 500
    ident 0963:000000
    group = 1
    emmcache = 1,3,2
    blockemm - unknown = 1
    blockemm - g = 1
    lb-weight = 101


    I think you either use detect or the device id, I don't think both are necessary?

    I made some progress...


    The device id had changed, and ive tried what you suggested but either way im still getting the following -


    1/09/2012 16:48:24 85C4A30 r smargo2 [pcsc] card detected
    1/09/2012 16:48:24 85C4A30 r smargo2 [pcsc] ATR: 3B 9F 11 40 60 49 52 44 45 54 4F 20 41 43 53 20 56 36 2E 30
    1/09/2012 16:48:25 85C4A30 r smargo2 [pcsc] Hist. Bytes: I***** ACS V6.0
    1/09/2012 16:48:25 85C4A30 r smargo2 [pcsc] detect i***** card
    1/09/2012 16:48:25 85C4A30 r smargo2 [pcsc] WARNING: ACS57 card can require the CamKey from config
    1/09/2012 16:48:25 85C4A30 r smargo2 [pcsc] caid: 0666, acs: 0.06, country code: CZE
    1/09/2012 16:48:26 85C4A30 r smargo2 [pcsc] providers: 4, ascii serial: ##########, hex serial: ######, hex base: ##
    1/09/2012 16:48:26 85C4A30 r smargo2 [pcsc] You have a bad Cam Key set
    1/09/2012 16:48:26 85C4A30 r smargo2 [pcsc] card system not supported
    1/09/2012 16:48:26 85C4A30 r smargo2 [pcsc] Normal mode failed, reverting to Deprecated Mode

    I have activated the card but its still showing no entitlements.


    The reader is oscam looks as follows -



    [reader]
    label = smargo2
    protocol = pcsc
    device = 001:005
    #detect = cd
    blockemm-u = 0
    blockemm-s = 0
    blockemm-g = 1
    blockemm-unknown = 1
    emmcache = 1,3,2
    group = 2
    mhz = 600
    cardmhz = 600
    caid = 0666:000000
    #caid = 0D0F


    I have also tried with the caid, commented out above.