165 lines
6.3 KiB
Plaintext
165 lines
6.3 KiB
Plaintext
<h3><strong>-- During The Show --</strong></h3>
|
||
|
||
<h4>00:45 Steve's OpenSuse Experience</h4>
|
||
|
||
<ul>
|
||
<li>Splash Screen</li>
|
||
<li>Kernel Panic</li>
|
||
</ul>
|
||
|
||
<h4>03:10 Caller Ed</h4>
|
||
|
||
<ul>
|
||
<li>Best VM server</li>
|
||
<li><a href="https://www.proxmox.com/en/" rel="nofollow">Proxmox</a></li>
|
||
<li><a href="https://libvirt.org/" rel="nofollow">Libvirt</a> + <a href="https://cockpit-project.org/" rel="nofollow">Cockpit</a></li>
|
||
<li><a href="https://www.ovirt.org/" rel="nofollow">Ovirt</a></li>
|
||
</ul>
|
||
|
||
<h4>08:08 Sleuth Asked</h4>
|
||
|
||
<ul>
|
||
<li>Is there software to send and receive audio over the network that work on phones and Linux machines? My usecase is I want to listen to podcasts from antennapod on my computer and to monitor jitsi and mumble from my phone.</li>
|
||
<li>Alsa Mixer</li>
|
||
<li><a href="https://icecast.org/" rel="nofollow">IceCast</a></li>
|
||
</ul>
|
||
|
||
<h4>09:58 TwoBit Asked</h4>
|
||
|
||
<ul>
|
||
<li>Still using the Google Glass?</li>
|
||
<li>Yes</li>
|
||
</ul>
|
||
|
||
<h4>10:43 Docker Server - Mathieu</h4>
|
||
|
||
<ul>
|
||
<li>TLS/HTTPS is more than a cert</li>
|
||
<li><a href="https://www.haproxy.org/" rel="nofollow">HAProxy</a>/Nginx Reverse Proxy</li>
|
||
<li>Check documentation for the project</li>
|
||
<li>Security is more than closing ports</li>
|
||
<li><a href="https://letsencrypt.org/" rel="nofollow">LetsEncrypt</a></li>
|
||
</ul>
|
||
|
||
<h4>19:25 Archiving Emails? - Jose</h4>
|
||
|
||
<ul>
|
||
<li>Download an archive + Thunderbird</li>
|
||
</ul>
|
||
|
||
<h4>23:26 SIP Questions - Andrew</h4>
|
||
|
||
<ul>
|
||
<li><a href="https://www.3cx.com/docs/3cx-tunnel-session-border-controller/" rel="nofollow">3CX SBC</a></li>
|
||
<li>Upgrade Router to PFSense/OPNSense</li>
|
||
</ul>
|
||
|
||
<h4>28:10 Pick of the Week</h4>
|
||
|
||
<ul>
|
||
<li><a href="https://www.casaos.io/" rel="nofollow">CasaOS</a></li>
|
||
<li><a href="https://www.helpnetsecurity.com/2021/12/13/casaos-home-cloud-system/" rel="nofollow">Help Net Security Article</a></li>
|
||
<li>Based on Docker</li>
|
||
<li>Easy Self Hosted Services</li>
|
||
</ul>
|
||
|
||
<h4>30:23 Gadget of the Week</h4>
|
||
|
||
<ul>
|
||
<li><a href="https://shop.m5stack.com/products/m5stickc-plus-esp32-pico-mini-iot-development-kit?variant=35275856609444" rel="nofollow">M5stick</a></li>
|
||
<li>$14 ESP32 Dev Kit</li>
|
||
</ul>
|
||
|
||
<h4>32:52 Centos 8 EOL</h4>
|
||
|
||
<ul>
|
||
<li><a href="https://www.zdnet.com/article/centos-linux-8-is-about-to-die-what-do-you-do-next/" rel="nofollow">ZDNet Article</a></li>
|
||
<li>CentOS EOL Dec 31 2021</li>
|
||
<li>Zero Day security patches until Jan 31 2022</li>
|
||
<li>Options
|
||
|
||
<ul>
|
||
<li>Red Hat Proper</li>
|
||
<li>Free Red Hat Developer License's</li>
|
||
<li><a href="https://www.centos.org/centos-stream/" rel="nofollow">CentOS Stream</a></li>
|
||
<li><a href="https://almalinux.org/" rel="nofollow">Alma Linux</a></li>
|
||
<li>Cloud Linux OS</li>
|
||
<li>Rocky Linux</li>
|
||
</ul></li>
|
||
</ul>
|
||
|
||
<h4>38:00 Toyota Makes Keyfob a Service</h4>
|
||
|
||
<ul>
|
||
<li><a href="https://www.thedrive.com/news/43329/toyota-made-its-key-fob-remote-start-into-a-subscription-service" rel="nofollow">The Drive Article</a></li>
|
||
<li>Requiring subscription to use local keyfob functions</li>
|
||
</ul>
|
||
|
||
<h4>40:38 Pop!_OS 21.10 Released</h4>
|
||
|
||
<ul>
|
||
<li><a href="https://blog.system76.com/post/670564272872488960/popos-2110-has-landed" rel="nofollow">System76 Blog Post</a></li>
|
||
<li>Tech preview of Pop!_OS 21.10 for the RaspberryPi</li>
|
||
<li>System Refresh feature</li>
|
||
<li>Lots of new features </li>
|
||
</ul>
|
||
|
||
<h4>42:44 Main Segment - log4j Vulnerability</h4>
|
||
|
||
<ul>
|
||
<li>CVE-2021-44228</li>
|
||
<li>Remote Code Execution</li>
|
||
<li>Actively being exploited in the wild</li>
|
||
<li>Used in embedded and IOT devices as well</li>
|
||
<li><a href="https://www.youtube.com/watch?v=7qoPDq41xhQ" rel="nofollow">Minecraft Exploit Example</a></li>
|
||
<li>2.14.1 and earlier vulnerable</li>
|
||
<li>Fixed in Log4j 2.15.0</li>
|
||
<li><a href="https://github.com/YfryTchsGD/Log4jAttackSurface" rel="nofollow">Github Attack Surface List</a></li>
|
||
<li>Responsible disclosure was not followed</li>
|
||
<li>Alternative mitigations available</li>
|
||
<li>Flip the environmental variable ES JAVA OPTS= -D log4j2.formatMsgNoLookups=True</li>
|
||
<li><a href="https://blog.cloudflare.com/cve-2021-44228-log4j-rce-0-day-mitigation/" rel="nofollow">Cloudflare Mitigation</a></li>
|
||
<li><a href="https://www.helpnetsecurity.com/2021/12/12/week-in-review-apache-log4j-0day-exploited-kali-linux-2021-4-released-patch-tuesday-forecast/" rel="nofollow">Help Net Security Article</a></li>
|
||
<li><a href="https://fortune.com/2021/12/13/cyber-security-log4j-hacker-breach/" rel="nofollow">Fortune Article</a></li>
|
||
<li><a href="https://www.welivesecurity.com/2021/12/13/log4shell-vulnerability-what-we-know-so-far/" rel="nofollow">We Live Securtiy Article</a></li>
|
||
<li><a href="https://thenextweb.com/news/log4j-bug-internet-open-source-contributors-analysis" rel="nofollow">The Next Web Article</a></li>
|
||
</ul>
|
||
|
||
<h3><strong>-- The Extra Credit Section --</strong></h3>
|
||
|
||
<p>For links to the articles and material referenced in this week's episode check out this week's page from our podcast dashboard!</p>
|
||
|
||
<p><a href="http://podcast.asknoahshow.com/263" rel="nofollow">This Episode's Podcast Dashboard</a></p>
|
||
|
||
<p><a href="http://www.voxtelesys.com/asknoah" rel="nofollow">Phone Systems for Ask Noah provided by Voxtelesys</a></p>
|
||
|
||
<p>Join us in our dedicated chatroom <a href="https://element.linuxdelta.com/#/room/#geeklab:linuxdelta.com" rel="nofollow">#GeekLab:linuxdelta.com on Matrix</a></p>
|
||
|
||
<h3><strong>-- Stay In Touch --</strong></h3>
|
||
|
||
<p><strong>Find all the resources for this show on the Ask Noah Dashboard</strong></p>
|
||
|
||
<blockquote>
|
||
<p><a href="http://www.asknoahshow.com" rel="nofollow">Ask Noah Dashboard</a></p>
|
||
</blockquote>
|
||
|
||
<p><strong>Need more help than a radio show can offer? Altispeed provides commercial IT services and they’re excited to offer you a great deal for listening to the Ask Noah Show. Call today and ask about the discount for listeners of the Ask Noah Show!</strong></p>
|
||
|
||
<blockquote>
|
||
<p><a href="http://www.altispeed.com/" rel="nofollow">Altispeed Technologies</a></p>
|
||
</blockquote>
|
||
|
||
<p><strong>Contact Noah</strong></p>
|
||
|
||
<blockquote>
|
||
<p>live [at] asknoahshow.com</p>
|
||
</blockquote>
|
||
|
||
<p><strong>-- Twitter --</strong></p>
|
||
|
||
<ul>
|
||
<li><a href="https://twitter.com/kernellinux" rel="nofollow">Noah - Kernellinux</a></li>
|
||
<li><a href="https://twitter.com/asknoahshow" rel="nofollow">Ask Noah Show</a></li>
|
||
<li><a href="https://twitter.com/altispeed" rel="nofollow">Altispeed Technologies</a></li>
|
||
</ul><p>Special Guest: Steve Ovens.</p><p><a href="https://patreon.com/linuxdelta" rel="payment">Support Ask Noah Show</a></p>
|
||
|