Event Report: SCALE 7x
A look back at the seventh annual Southern California Linux ExpoBy
The seventh annual Southern California Linux Expo, held February 20-22, included a wide variety of talks on open source projects, system administration, and software development from luminaries in the open source community. This year’s conference was larger than ever and included keynotes from Bradley Kuhn, President of Software Freedom Conservancy, and Joe 'Zonker' Brockmeier, openSUSE's Community Manager. Kuhn talked about concerns with Software as a Service (a.k.a. the cloud), and Brockmeier discussed ways to improve the reach of an open source project.
The presenters at SCALE 7x delivered cutting-edge topics and practical information. For example, Ross Turk (SourceForge.net) discussed how to leverage open source software for business, and Edmunds.com's Shawn Anderson talked about writing small tools and applications in the Ruby programming language.
SCALE offered multiple topics and presentations to whet any technical appetite, and the topics ranged from purely technical to open source community-related issues. The SCALE conference is community supported and run by volunteers.
Anthony Lineberry's talk, Undermining the Linux Kernel: Malicious Code Injection Via /dev/mem, covered how to hack the Linux Kernel and gain privileged access using the Kernel device /dev/mem. The talk started off with examples of common methods for exploiting the Linux Kernel, including rootkits and trojans, and how to prevent exploits.
Lineberry also examined the special procedure of injecting code into /dev/mem. /dev/mem is a driver interface to physically addressable memory, which can be read and written like a regular Linux character device. Some examples of fun things a user can do with this privileged access, such as hiding files, processes, and controlling network activity, were demonstrated. The last part of the talk gave examples of how to patch this specific method of gaining privileged access to the Linux kernel.
See a SCALE 7x Women in Open Source report at the ROSE blog.
If you missed SCALE 7x, be sure to watch our events calendar for updates about SCALE 8x.
A new class of problems lets a malicious app pre-configure an invisible privilege update.
New Hack language adds static typing and other conveniences.
New crypto policy system will offer easier configuration and more uniform security.
Ubuntu founder denounces insecurity in proprietary, close-source software blobs.
Vulnerability affects many Linux web servers
The Bavarian capital shuns Microsoft, Google, and other alternatives to implement an open source groupware solution.
Phone vendor partnerships bring Mark Shuttleworth's dream of Ubuntu on a phone a step closer to reality.
Donors will get to vote on new features for the free video editor.
Debian project puts init out to pasture and says no to Ubuntu's Upstart.