Event Report: SCALE 7x
A look back at the seventh annual Southern California Linux ExpoBy
The seventh annual Southern California Linux Expo, held February 20-22, included a wide variety of talks on open source projects, system administration, and software development from luminaries in the open source community. This year’s conference was larger than ever and included keynotes from Bradley Kuhn, President of Software Freedom Conservancy, and Joe 'Zonker' Brockmeier, openSUSE's Community Manager. Kuhn talked about concerns with Software as a Service (a.k.a. the cloud), and Brockmeier discussed ways to improve the reach of an open source project.
The presenters at SCALE 7x delivered cutting-edge topics and practical information. For example, Ross Turk (SourceForge.net) discussed how to leverage open source software for business, and Edmunds.com's Shawn Anderson talked about writing small tools and applications in the Ruby programming language.
SCALE offered multiple topics and presentations to whet any technical appetite, and the topics ranged from purely technical to open source community-related issues. The SCALE conference is community supported and run by volunteers.
Anthony Lineberry's talk, Undermining the Linux Kernel: Malicious Code Injection Via /dev/mem, covered how to hack the Linux Kernel and gain privileged access using the Kernel device /dev/mem. The talk started off with examples of common methods for exploiting the Linux Kernel, including rootkits and trojans, and how to prevent exploits.
Lineberry also examined the special procedure of injecting code into /dev/mem. /dev/mem is a driver interface to physically addressable memory, which can be read and written like a regular Linux character device. Some examples of fun things a user can do with this privileged access, such as hiding files, processes, and controlling network activity, were demonstrated. The last part of the talk gave examples of how to patch this specific method of gaining privileged access to the Linux kernel.
See a SCALE 7x Women in Open Source report at the ROSE blog.
If you missed SCALE 7x, be sure to watch our events calendar for updates about SCALE 8x.
DARPA and NICTA release the code for the ultra-secure microkernel system used in aerial drones.
Should you trust an online service to store your online passwords?
New B+ board lets you build cool things without the complication of a powered USB hub.
Redmond rushes in to root out alleged malware haven.
New initiative will bring futuristic virtual reality effects to the web surfing experience.
Dyreza malware launches a man-in-the-middle attack that compromises SSL.
New cloud combines worldwide access with local attention to data security.
A first cousin of the recent Heartbleed attack affects EAP-based wireless and peer-to-peer authentication.
FOSS community acts to protect freedom of choice for laptop devices.