October 31, 2007
Evaluating the Security of Apple’s New OS
"A quick look at the changelog history for PCRE highlighted a vulnerability which could used to create a heap overflow"
Following the release of Apple's latest operating system, Mac OS X 10.5 Leopard, security experts have taken a look at the new OS and are complaining not only that Leopard's firewall isn't turned on by default, ... via CIO Today
Filed under Open Source Software by Open Source Software News
License: BSD License (original)
Changes:
Previously, this product was only available as a proprietary hosted software service.
Filed under Open Source Software by freshmeat.net announcements (Global)
Bunny the Fuzzer is a closed loop,
high-performance, general purpose protocol-blind
fuzzer for C programs. It uses compiler-level
integration to seamlessly inject precise and
reliable instrumentation hooks into the traced
program. These hooks enable the fuzzer to receive
real-time feedback on changes to the function call
path, call parameters, and return values in
response to variations in input data.
Filed under Open Source Software by freshmeat.net announcements (Global)
The Skeleton Engine is a starting point for
creating a MySQL Storage Engine. It comes with
everything you need to write a pluggable engine.
Autoconf, an initial framework, and scripting
tools are all provided. The Skeleton Engine has
been the starting point for the PBXT, Nitro,
Memcache, AWS, HTTP, and many other engines.
License: BSD License (revised)
Changes:
License file cleanups, better documents, and the removal of some public functions (aka they are now declared as static).
License: BSD License (revised)
Changes:
License file cleanups, better documents, and the removal of some public functions (aka they are now declared as static).
Filed under Open Source Software by freshmeat.net announcements (Global)
samhain is a daemon that can check file integrity, search the file tree for SUID files, and detect kernel module rootkits (Linux only). It can be used either standalone or as a client/server system for centralized monitoring, with strong (192-bit AES) encryption for client/server connections and the option to store databases and configuration files on the server. For tamper resistance, it supports signed database/configuration files and signed reports/audit logs. It has been tested on Linux, FreeBSD, Solaris, AIX, HP-UX, and Unixware.
License: GNU General Public License (GPL)
Changes:
A framework for running extension modules in separate threads has been implemented. The login check module and the process check module have been updated to run as threads.
License: GNU General Public License (GPL)
Changes:
A framework for running extension modules in separate threads has been implemented. The login check module and the process check module have been updated to run as threads.
Filed under Open Source Software by freshmeat.net announcements (Global)

