Fake patient data could have been uploaded through SAP medical app

SAP has fixed two flaws in a mobile medical app, one of which could have allowed an attacker to upload fake patient data.The issues were found in SAP’s Electronic Medical Records (EMR) Unwired, which stores clinical data about patients including lab results and images, said Alexander Polyakov, CTO of ERPScan, a company based in Palo Alto, California, that specializes in enterprise application security.Researchers with ERPScan found a local SQL injection flaw that could allow other applications on a mobile device to get access to an EMR Unwired database. That’s not supposed to happen, as mobile applications are usually sandboxed to prevent other applications from accessing their data.To read this article in full or to leave a comment, please click here

Lab: iBGP and OSPF Traffic Engineering

Click to enlarge

Here's the scenario: An enterprise network with an MPLS core and two branch locations connected to their own Provider Edge (PE) router. In addition to the MPLS link, the PEs are also connected via a DMVPN tunnel. The PEs are peering via iBGP (of course) and are also OSPF neighbors on the DMVPN. Both Customer Edge (CE) routers at the branch are OSPF neighbors with their local PE.

Task: Use the high speed MPLS network as the primary path between the CE routers and only use the DMVPN network if the MPLS network becomes unavailable.

Question: Is the solution as simple as adjusting the Admin Distance (AD) so that the iBGP routes are more preferred?

VMWare Player and VM Networking

VMWare Player is the Virtualization software/hypervisor provided free of charge by VMWare. Player is for personal use. Paid versions are available as VMWare Player Pro or VMWare Workstation. Following link covers the differences between different editions. I have used Virtualbox for most of my VM needs. There were few recent scenarios where I had to use … Continue reading VMWare Player and VM Networking

DNSSEC – Moving the Needle

The New Zealand ISP market is dominated by Spark, Vodafone & CallPus/Orcon. A side effect of this is that if one player does the Right Thing™, it really moves the needle. Recently, Spark has done the Right Thing with DNSSEC.

DNSSEC takeup has been low with New Zealand ISPs. The APNIC stats indicated that around 5% of users were using DNS resolvers that had DNSSEC validation capabilities. But in December 2014, that number jumped to ~15%:

dnssec_nz_stats

It turns out this is because Spark has enabled DNSSEC validation on some of their resolvers. NZRS have done some analysis, and found that Spark turned on 4 new resolvers that do DNSSEC validation:

They’re still running their old resolvers, so right now it’s hit & miss for their customers. But it’s a great start, and presumably they’ll upgrade the remaining systems soon.

So Vodafone, CallPlus, Snap, Trustpower…when are you going to take customer security seriously too? And Spark…how long until DNSSEC is enabled for all your resolvers?

And please, no arguments about “we’re not sure if it will work.” Google has been doing it since March 2013…who do you think processes more DNS requests per day? Google, or your ISP?

Raytracing Quake demos

I decided to combine these two problems into one solution:

  • Modern CPUs are idle way too much of the time. Why have all this computational power if we don’t use it?
  • I have these funny old Quake demos that there’s no good way to convert to something playable.

My solution is to convert Quake .dem files to .pov files and render them with POV-Ray.

Update: New better screenshot:

Quake scene rendered in POV-Ray

Quake scene rendered in POV-Ray Quake scene rendered in POV-Ray. Two more here and here.

Quake is closing in on 20 years old now, and it’s starting to get annoying to make it even work. Yes, it’s opensource, and there are a couple of forks. But they’ve also always been annoying to get working. Hell, even GLQuake in Steam won’t start for me. (yes, I know this is a bad reason, but I’m doing this for fun)

Many of the tools and resources are hard to find. I couldn’t find ReMaic, and only found lmpc thanks to FreeBSD having made it a package. Converting demos to an ASCII format using lmpc helped in confirming that my file parsing was correct.

The steps needed to render a demo:

  1. Extract .mdl files to .pov and .png (skin) files.
  2. Extract . Continue reading

Raytracing Quake demos

I decided to combine these two problems into one solution:

  • Modern CPUs are idle way too much of the time. Why have all this computational power if we don’t use it?
  • I have these funny old Quake demos that there’s no good way to convert to something playable.

My solution is to convert Quake .dem files to .pov files and render them with POV-Ray.

Quake scene rendered in POV-Ray
Quake scene rendered in POV-Ray. Two more here and here.

Quake is closing in on 20 years old now, and it’s starting to get annoying to make it even work. Yes, it’s opensource, and there are a couple of forks. But they’ve also always been annoying to get working. Hell, even GLQuake in Steam won’t start for me. (yes, I know this is a bad reason, but I’m doing this for fun)

Many of the tools and resources are hard to find. I couldn’t find ReMaic, and only found lmpc thanks to FreeBSD having made it a package. Converting demos to an ASCII format using lmpc helped in confirming that my file parsing was correct.

The steps needed to render a demo:

  1. Extract .mdl files to .pov and .png (skin) files.
  2. Extract .bsp files to .pov Continue reading

A peek into the USM format

A peek into the USM format

A game that I really liked the visuals off, Crysis 3 uses a video file format called USM, This is a rather odd to me, since when I am used to pulling games apart for their assets, I am used to BINK video being used for th

Show 229 – Network Break 32 – Juniper Innovation Showcase & More

Over-opinionated analysis on data network and IT Infrastructure. And virtual doughnuts.

Author information

Ethan Banks

Ethan Banks, CCIE #20655, has been managing networks for higher ed, government, financials and high tech since 1995. Ethan co-hosts the Packet Pushers Podcast, which has seen over 3M downloads and reaches over 10K listeners. With whatever time is left, Ethan writes for fun & profit, studies for certifications, and enjoys science fiction. @ecbanks

The post Show 229 – Network Break 32 – Juniper Innovation Showcase & More appeared first on Packet Pushers Podcast and was written by Ethan Banks.

My mechanical keyboard

You spend all your waking time at a keyboard. This blog post is about keyboards, and can be summarized as: Buy quality, cry once.

I spend a lot of time typing on a keyboard, yet I have never looked into what keyboard would be best for me. There are natural keyboards and kinesis keyboards that people speak well of, but I spend a lot of time typing on laptops and don’t want a completely different setup for laptop and desktop.

I had the same concern before switching to Dvorak back when I was a consultant (thus often using other peoples managed machines), but happily switched after verifying that even on a locked down Windows machine as a non-admin user I could select Dvorak. Also there are adapters from Dvorak to Qwerty that I could use in extremely locked down environments such as the CCIE lab (they required a doctors note though, long story).

So it would have to be a keyboard that looks like a normal one. Preferably with Dvorak on the keycaps. It seems that mechanical keyboards are all the rage, so I thought I’d give that a go.

I ended up buying a 88 key Cherry MX brown-based Continue reading

My mechanical keyboard

You spend all your waking time at a keyboard. This blog post is about keyboards, and can be summarized as: Buy quality, cry once.

I spend a lot of time typing on a keyboard, yet I have never looked into what keyboard would be best for me. There are natural keyboards and kinesis keyboards that people speak well of, but I spend a lot of time typing on laptops and don’t want a completely different setup for laptop and desktop.

I had the same concern before switching to Dvorak back when I was a consultant (thus often using other peoples managed machines), but happily switched after verifying that even on a locked down Windows machine as a non-admin user I could select Dvorak. Also there are adapters from Dvorak to Qwerty that I could use in extremely locked down environments such as the CCIE lab (they required a doctors note though, long story).

So it would have to be a keyboard that looks like a normal one. Preferably with Dvorak on the keycaps. It seems that mechanical keyboards are all the rage, so I thought I’d give that a go.

I ended up buying a 88 key Cherry MX brown-based Continue reading

Upcoming Apple TV will feature App Store and Siri

Amid reports that Apple is planning to roll out its own streaming TV service later this fall, we now have word regarding what Apple's fourth-gen Apple TV is going to look like.Reporting for Buzzfeed, John Paczkowski reports, that Apple plans to show off a completely revamped version of its Apple TV at WWDC sometime this June. And though previous Apple TV updates have been somewhat limited to internal upgrades, this one promises to be a doozy.First off, the next iteration of the Apple TV will reportedly include, at long last, an App Store. Just as the App Store significantly increased the value proposition of iOS devices, we can expect to see a similar transformation with respect to the Apple TV. Even more so when one considers the possibilities of using external controllers, or even one's iOS device, as a controller while playing games on a big screen HDTV.To read this article in full or to leave a comment, please click here

Android’s smart lock now detects when you carry your phone

Google is adding a feature to Android’s smart lock that could significantly cut down on the number of times users need to enter a passcode to unlock their phones while they are out and about.On-body detection uses the accelerometer in the phone to detect when it’s being held or carried by a person. If enabled, the feature requires a passcode the first time the phone is accessed but then keeps the device unlocked until it is placed down.That means, for example, that someone walking down the street won’t have to unlock their phone every time they take it out of their pocket.The feature doesn’t appear to have been announced by Google, but it began appearing in some phones on Friday.To read this article in full or to leave a comment, please click here

Could Facebook be your next phone company?

This vendor-written tech primer has been edited by Network World to eliminate product promotion, but readers should note it will likely favor the submitter’s approach.

Could Facebook or LinkedIn become the nexus for your voice calls and other communications? Not yet, but thanks to a technology known as WebRTC you can’t rule out the possibility.

WebRTC — the initials stand for Real Time Communications — is an open-source project that aims to transform the ordinary Web browser into a full-featured unified communications portal. With WebRTC, users establish real-time communication sessions from their browser, search, find and point to the servers of people they want to communicate with, and establish connections — all without needing to know the recipient’s phone number or email address.

To read this article in full or to leave a comment, please click here

Bare-metal switches poised to take off in data centers

Bare-metal switches that can be programmed like Linux servers aren’t just for big Web companies anymore. They may show up in a lot more average enterprises in the next few years.Cloud-based service providers like Facebook and Google have been building data-center networks out of generic hardware and homegrown software for years. Now vendors including HP and Dell are beginning to sell switches much like they do bare-metal servers. They may pre-load an operating system and provide ongoing support, but that OS is open and their customers will have much more freedom with this new kind of gear than they do with traditional switches from vendors like Cisco Systems.To read this article in full or to leave a comment, please click here

Bare-metal switches poised to take off in data centers

Bare-metal switches that can be programmed like Linux servers aren’t just for big Web companies anymore. They may show up in a lot more average enterprises in the next few years.Cloud-based service providers like Facebook and Google have been building data-center networks out of generic hardware and homegrown software for years. Now vendors including HP and Dell are beginning to sell switches much like they do bare-metal servers. They may pre-load an operating system and provide ongoing support, but that OS is open and their customers will have much more freedom with this new kind of gear than they do with traditional switches from vendors like Cisco Systems.To read this article in full or to leave a comment, please click here

China discloses cyberwarfare unit, no one surprised

It came as a shock to just about no one in the cybersecurity industry that China has a cyberware unit, which was acknowledged by the government there this week.While the Chinese government has long denied attacking U.S. targets, U.S. businesses and government agencies have complained for years about attacks originating from China.The Chinese government noted the existence of the country’s cyberwarfare unit in “The Science of Military Strategy,” a publication put out by a research institute of the People’s Liberation Army, according to news reports this week. The U.S. military has acknowledged its own cyberwarfare capabilities for over a decade.To read this article in full or to leave a comment, please click here

Plexxi Pulse – Bringing Data to Life at Arrow’s IoT Immersions Conference

Next week, our co-founder, CTO and EVP of products and technology, Dave Husak, will be heading to Arrow’s Internet of Things Immersions Conference to participate in two panels. The event will be held on March 26 at the Hynes Convention Center in Boston, MA.

The first panel Husak will join will weigh in on the topic “Bringing Data to Life: How to Turn Data Intelligence into Actionable Sales Growth.” Husak will be joined on this panel by other industry thought leaders from Arrow, EMC, Intel, NXP and Oracle. Husak and the other panelists will analyze how to effectively harness massive amounts of sales data and turn it into something actionable and meaningful for their organization. He’ll follow up this panel with a general panel at 6:50 as part of the Innovator’s Showcase.

In case you’re in the area, you can register for the event here. If you aren’t, follow along with us on Twitter here.

Below please find a few of our top picks for our favorite news articles of the week. Have a great weekend!

 

Network Computing: SDN Benefits For The SME

By Tom Hollingsworth

Working in a small or medium enterprise (SME) is a constant juggling Continue reading

Monetizing medical data is becoming the next revenue stream for hackers

The personal information found in health care records fetches hefty sums on underground markets, making any company that stores such data a very attractive target for attackers.“Hackers will go after anyone with health care information,” said John Pescatore, director of emerging security trends at the SANS Institute, adding that in recent years hackers have increasingly set their sights on EHRs (electronic health records).With medical data, “there’s a bunch of ways you can turn that into cash,” he said. For example, Social Security numbers and mailing addresses can be used to apply for credit cards or get around corporate antifraud measures.To read this article in full or to leave a comment, please click here