GNU socialtag:nu.federati.net,2024-03-29:TagTimeline:log4jNotices tagged with log4jUpdates tagged with log4j on Federati Nu: Federated N-series GNU Social!https://upload.wikimedia.org/wikipedia/commons/0/00/Nu_uc_lc.svg2024-03-29T06:02:13+00:00http://activitystrea.ms/schema/1.0/notetag:nu.federati.net,2022-02-20:noticeId=3393968:objectType=noteNew note by lnxw48a1A member of the #<span class="tag"><a href="https://nu.federati.net/tag/log4j" rel="tag">log4j</a></span> team talks about #<span class="tag"><a href="https://nu.federati.net/tag/log4shell" rel="tag">log4shell</a></span> and their patching process <a href="https://therecord.media/the-apache-log4j-team-talks-about-the-log4shell-patching-process/" title="https://therecord.media/the-apache-log4j-team-talks-about-the-log4shell-patching-process/" rel="nofollow noreferrer" class="attachment">https://therecord.media/the-apache-log4j-team-talks-about-the-log4shell-patching-process/</a> [therecord media] <br /><br /> He's clearly been coached in avoiding making any sensational or upsetting statements. I wish more of us got such coaching.3393968http://activitystrea.ms/schema/1.0/post2022-02-20T17:47:58+00:002022-02-20T17:47:58+00:00http://activitystrea.ms/schema/1.0/personhttps://nu.federati.net/user/2lnxw48a1Main account. A GNU+Linux bearing nomad migrating across a Windows-centric desert. I save the world from incompetent headquarters IT folks. I invite comment and discussion, but I dislike arguing .lnxw48a1LinuxWalt (@lnxw48a1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864}Main account. A GNU+Linux bearing nomad migrating across a Windows-centric desert. I save the world from incompetent headquarters IT folks. I invite comment and discussion, but I dislike arguing .{58024A03-1021-499E-B14D-DF4537889BF8}tag:nu.federati.net,2022-02-20:objectType=thread:nonce=a3d6866af0534d54http://activitystrea.ms/schema/1.0/notetag:nu.federati.net,2022-01-15:noticeId=3390797:objectType=noteNew note by lnxw48a1The other thing that concerns me about these systems is when some library ( #<span class="tag"><a href="https://nu.federati.net/tag/log4j" rel="tag">log4j</a></span> for example ) has a security vulnerability. If your software is locked up inside of these containers, that means each one will need to publish an update and get you to download it when it could all be updated at once with your system updater.3390797http://activitystrea.ms/schema/1.0/post2022-01-15T20:36:33+00:002022-01-15T20:36:33+00:00http://activitystrea.ms/schema/1.0/personhttps://nu.federati.net/user/2lnxw48a1Main account. A GNU+Linux bearing nomad migrating across a Windows-centric desert. I save the world from incompetent headquarters IT folks. I invite comment and discussion, but I dislike arguing .lnxw48a1LinuxWalt (@lnxw48a1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864}Main account. A GNU+Linux bearing nomad migrating across a Windows-centric desert. I save the world from incompetent headquarters IT folks. I invite comment and discussion, but I dislike arguing .{58024A03-1021-499E-B14D-DF4537889BF8}tag:nu.federati.net,2022-01-15:objectType=thread:nonce=b90617c4f288961ehttp://activitystrea.ms/schema/1.0/notetag:nu.federati.net,2022-01-12:noticeId=3390529:objectType=noteNew note by lnxw48a1It starts. #<span class="tag"><a href="https://nu.federati.net/tag/cybercriminals" rel="tag">Cybercriminals</a></span> using #<span class="tag"><a href="https://nu.federati.net/tag/log4j" rel="tag">log4j</a></span> vulnerabilities to penetrate virtualization systems. <a href="https://www.cyberscoop.com/chinese-hackers-log4j-night-sky-ransomware-microsoft/" title="https://www.cyberscoop.com/chinese-hackers-log4j-night-sky-ransomware-microsoft/" rel="nofollow noreferrer" class="attachment">https://www.cyberscoop.com/chinese-hackers-log4j-night-sky-ransomware-microsoft/</a> [www cyberscoop com]3390529http://activitystrea.ms/schema/1.0/post2022-01-12T19:07:03+00:002022-01-12T19:07:03+00:00http://activitystrea.ms/schema/1.0/personhttps://nu.federati.net/user/2lnxw48a1Main account. A GNU+Linux bearing nomad migrating across a Windows-centric desert. I save the world from incompetent headquarters IT folks. I invite comment and discussion, but I dislike arguing .lnxw48a1LinuxWalt (@lnxw48a1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864}Main account. A GNU+Linux bearing nomad migrating across a Windows-centric desert. I save the world from incompetent headquarters IT folks. I invite comment and discussion, but I dislike arguing .{58024A03-1021-499E-B14D-DF4537889BF8}tag:nu.federati.net,2022-01-12:objectType=thread:nonce=3df16a3ec3f09d10http://activitystrea.ms/schema/1.0/notetag:nu.federati.net,2021-12-23:noticeId=3388673:objectType=noteNew note by lnxw48a1<a href="https://gleasonator.com/objects/d9043839-33b7-4ddf-ae84-8472177f88c3" title="https://gleasonator.com/objects/d9043839-33b7-4ddf-ae84-8472177f88c3" rel="nofollow">https://gleasonator.com/objects/d9043839-33b7-4ddf-ae84-8472177f88c3</a> <br /><br /> Deavmi releases DLog, a logging library for #<span class="tag"><a href="https://nu.federati.net/tag/dlang" rel="tag">DLang.</a></span> Hopefully, he's taken care not to do things the way #<span class="tag"><a href="https://nu.federati.net/tag/log4j" rel="tag">Log4J</a></span> does. I mean, there are several log4* projects that use a similar API, but AFAIK, only the Java library is causing these problems right now. So #<span class="tag"><a href="https://nu.federati.net/tag/dlog" rel="tag">DLog</a></span> could probably serve as the Log4D equivalent without having all the same flaws.3388673http://activitystrea.ms/schema/1.0/post2021-12-23T13:30:39+00:002021-12-23T13:30:39+00:00http://activitystrea.ms/schema/1.0/personhttps://nu.federati.net/user/2lnxw48a1Main account. A GNU+Linux bearing nomad migrating across a Windows-centric desert. I save the world from incompetent headquarters IT folks. I invite comment and discussion, but I dislike arguing .lnxw48a1LinuxWalt (@lnxw48a1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864}Main account. A GNU+Linux bearing nomad migrating across a Windows-centric desert. I save the world from incompetent headquarters IT folks. I invite comment and discussion, but I dislike arguing .{58024A03-1021-499E-B14D-DF4537889BF8}tag:nu.federati.net,2021-12-23:objectType=thread:nonce=991ce101898eada5http://activitystrea.ms/schema/1.0/notetag:nu.federati.net,2021-12-18:noticeId=3388158:objectType=noteNew note by lnxw48a1<a href="https://thehackernews.com/2021/12/apache-issues-3rd-patch-to-fix-new-high.html" title="https://thehackernews.com/2021/12/apache-issues-3rd-patch-to-fix-new-high.html" rel="nofollow external noreferrer" class="attachment" id="attachment-284005">https://thehackernews.com/2021/12/apache-issues-3rd-patch-to-fix-new-high.html</a> <br /> <br /> #<span class="tag"><a href="https://nu.federati.net/tag/log4j" rel="tag">log4j</a></span> ... 3rd emergency patch issued3388158http://activitystrea.ms/schema/1.0/post2021-12-18T10:38:13+00:002021-12-18T10:38:13+00:00http://activitystrea.ms/schema/1.0/personhttps://nu.federati.net/user/2lnxw48a1Main account. A GNU+Linux bearing nomad migrating across a Windows-centric desert. I save the world from incompetent headquarters IT folks. I invite comment and discussion, but I dislike arguing .lnxw48a1LinuxWalt (@lnxw48a1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864}Main account. A GNU+Linux bearing nomad migrating across a Windows-centric desert. I save the world from incompetent headquarters IT folks. I invite comment and discussion, but I dislike arguing .{58024A03-1021-499E-B14D-DF4537889BF8}tag:nu.federati.net,2021-12-18:objectType=thread:nonce=51b4581ec8eccb89http://activitystrea.ms/schema/1.0/notetag:nu.federati.net,2021-12-12:noticeId=3387744:objectType=noteNew note by lnxw48a1#<span class="tag"><a href="https://nu.federati.net/tag/android" rel="tag">Android</a></span> apps updating. #<span class="tag"><a href="https://nu.federati.net/tag/fdroid" rel="tag">F-Droid</a></span> presented me with 34 updates. Likely due to #<span class="tag"><a href="https://nu.federati.net/tag/log4j" rel="tag">log4j</a></span> vulnerability.3387744http://activitystrea.ms/schema/1.0/post2021-12-12T19:26:55+00:002021-12-12T19:26:55+00:00http://activitystrea.ms/schema/1.0/personhttps://nu.federati.net/user/2lnxw48a1Main account. A GNU+Linux bearing nomad migrating across a Windows-centric desert. I save the world from incompetent headquarters IT folks. I invite comment and discussion, but I dislike arguing .lnxw48a1LinuxWalt (@lnxw48a1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864}Main account. A GNU+Linux bearing nomad migrating across a Windows-centric desert. I save the world from incompetent headquarters IT folks. I invite comment and discussion, but I dislike arguing .{58024A03-1021-499E-B14D-DF4537889BF8}tag:nu.federati.net,2021-12-12:objectType=thread:nonce=afff843c64306025http://activitystrea.ms/schema/1.0/notetag:nu.federati.net,2021-12-11:noticeId=3387675:objectType=noteNew note by lnxw48a1For the record, !<a href="https://nu.federati.net/group/239/id" class="h-card u-url p-nickname group" title="Federati Networks (fnetworks)">fnetworks</a> does not run any #<span class="tag"><a href="https://nu.federati.net/tag/java" rel="tag">Java</a></span> software, nor is the JVM installed on any Federati server. <br /> <br /> The same applies for !<a href="https://nu.federati.net/group/372/id" class="h-card u-url p-nickname group" title="Open Source Playground (osp)">OSP</a>. <br /> <br /> I have not yet grepped logs for #<span class="tag"><a href="https://nu.federati.net/tag/log4j" rel="tag">log4j</a></span> exploitation attempts, but other server admins report multiple log entries.3387675http://activitystrea.ms/schema/1.0/post2021-12-11T17:47:40+00:002021-12-11T17:47:40+00:00http://activitystrea.ms/schema/1.0/personhttps://nu.federati.net/user/2lnxw48a1Main account. A GNU+Linux bearing nomad migrating across a Windows-centric desert. I save the world from incompetent headquarters IT folks. I invite comment and discussion, but I dislike arguing .lnxw48a1LinuxWalt (@lnxw48a1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864}Main account. A GNU+Linux bearing nomad migrating across a Windows-centric desert. I save the world from incompetent headquarters IT folks. I invite comment and discussion, but I dislike arguing .{58024A03-1021-499E-B14D-DF4537889BF8}tag:nu.federati.net,2021-12-11:objectType=thread:nonce=10859f8cc3acde5ahttp://activitystrea.ms/schema/1.0/notetag:nu.federati.net,2021-12-11:noticeId=3387640:objectType=noteNew note by lnxw48a1@<a href="https://nu.federati.net/user/16" class="h-card u-url p-nickname mention">geniusmusing</a> <br /><br /> Believed affected: * cloud platforms<br /> * enterprise applications ( which are often written in #<span class="tag"><a href="https://nu.federati.net/tag/java" rel="tag">Java</a></span> )<br /> * Minecraft ( which was where the #<span class="tag"><a href="https://nu.federati.net/tag/log4j" rel="tag">log4j</a></span> flaw was discovered )<br /> * #<span class="tag"><a href="https://nu.federati.net/tag/android" rel="tag">Android</a></span> apps ( noted by @<a href="https://libranet.de/profile/clacke" class="h-card u-url p-nickname mention">clacke</a> ) <br /><br /> Possibly, other "log4" libraries may have a similar flaw.3387640http://activitystrea.ms/schema/1.0/post2021-12-11T04:41:51+00:002021-12-11T04:41:51+00:00http://activitystrea.ms/schema/1.0/personhttps://nu.federati.net/user/2lnxw48a1Main account. A GNU+Linux bearing nomad migrating across a Windows-centric desert. I save the world from incompetent headquarters IT folks. I invite comment and discussion, but I dislike arguing .lnxw48a1LinuxWalt (@lnxw48a1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864}Main account. A GNU+Linux bearing nomad migrating across a Windows-centric desert. I save the world from incompetent headquarters IT folks. I invite comment and discussion, but I dislike arguing .{58024A03-1021-499E-B14D-DF4537889BF8}tag:nu.federati.net,2021-12-11:objectType=thread:nonce=fe86c4d86186937chttp://activitystrea.ms/schema/1.0/notetag:nu.federati.net,2021-06-14:noticeId=3369188:objectType=noteNew note by musicmanI’ve got a customer with what looks like a character encoding issue in either #<span class="tag"><a href="https://nu.federati.net/tag/elasticsearch" rel="tag">elasticsearch</a></span> or #<span class="tag"><a href="https://nu.federati.net/tag/fluentd" rel="tag">fluentd.</a></span><br /><br /> Here’s the message:<br /> 2021-06-08 17:05:50 +0800 [warn]: #<span class="tag"><a href="https://nu.federati.net/tag/0" rel="tag">0</a></span> dump an error event: error_class=Fluent::Plugin::ElasticsearchErrorHandler::ElasticsearchError error=“400 - Rejected by Elasticsearch [error type]: mapper_parsing_exception [reason]: ‘failed to parse field [message] of type [text] in document with id ‘fPHe6nkBSuYtlT3W3H56’. Preview of field’s value: ‘’’” location=nil tag=“app.was-aiahk-intranet-prod-aiab-app1-SystemOut” time=2021-06-08 17:05:14.438022000 +0800 record=<br /> {“message”=>"[6/8/21 14:37:39:438 CST] 000000f6 SystemOut O {call bunch of nulls and some sensitive data,‘CANTONESE’)}<br /><br /> I can’t tell at what point it is being recognized as Cantonese. Maybe that’s a metadata field. They gave what they claim is a fluentd config, but it doesn’t mention anything about character encoding. I’m waiting for their #<span class="tag"><a href="https://nu.federati.net/tag/log4j" rel="tag">log4j</a></span> config.<br /><br /> Any thoughts? Thanks!3369188http://activitystrea.ms/schema/1.0/post2021-06-14T14:55:52+00:002021-06-14T14:55:52+00:00http://activitystrea.ms/schema/1.0/personhttps://nu.federati.net/user/12musicmanI do 100% free software work (although my employer purchases non free tools to make this happen...sigh). My label: https://blocsonic.com/ started http://ccmusicawards.com http://datamost.com/dw twitter: dawsports cycling/running/yoga: https://www.strava.com/athletes/40503008 http://www.facebook.com/douglasawh. I've got other accounts...just ask 512 char is not enough, but hey, you have the rest of the page to fill in details.musicmanDouglas A. WhitfieldI do 100% free software work (although my employer purchases non free tools to make this happen...sigh). My label: https://blocsonic.com/ started http://ccmusicawards.com http://datamost.com/dw twitter: dawsports cycling/running/yoga: https://www.strava.com/athletes/40503008 http://www.facebook.com/douglasawh. I've got other accounts...just ask 512 char is not enough, but hey, you have the rest of the page to fill in details.Minneapolis, MN, USAhomepagehttps://bdinls576.wordpress.com/truetag:nu.federati.net,2021-06-14:objectType=thread:nonce=59bf85c3b3ae9535http://activitystrea.ms/schema/1.0/notetag:nu.federati.net,2020-06-19:noticeId=3318754:objectType=noteNew note by musicmanjust marked my first customer issue resolved on my new team. It's always frustrating when a customer doesn't get back to you, but it's been over a week and I've checked in, so I am calling it done.<br /><br /> In any case, I told him the answer in my first response, he just didn't like it. I mean, #<span class="tag"><a href="https://nu.federati.net/tag/log4j" rel="tag">log4j</a></span> may well be a better longterm solution for them, but it doesn't do exactly what they asked like my first response.3318754http://activitystrea.ms/schema/1.0/post2020-06-19T22:01:53+00:002020-06-19T22:01:53+00:00http://activitystrea.ms/schema/1.0/personhttps://nu.federati.net/user/12musicmanI do 100% free software work (although my employer purchases non free tools to make this happen...sigh). My label: https://blocsonic.com/ started http://ccmusicawards.com http://datamost.com/dw twitter: dawsports cycling/running/yoga: https://www.strava.com/athletes/40503008 http://www.facebook.com/douglasawh. I've got other accounts...just ask 512 char is not enough, but hey, you have the rest of the page to fill in details.musicmanDouglas A. WhitfieldI do 100% free software work (although my employer purchases non free tools to make this happen...sigh). My label: https://blocsonic.com/ started http://ccmusicawards.com http://datamost.com/dw twitter: dawsports cycling/running/yoga: https://www.strava.com/athletes/40503008 http://www.facebook.com/douglasawh. I've got other accounts...just ask 512 char is not enough, but hey, you have the rest of the page to fill in details.Minneapolis, MN, USAhomepagehttps://bdinls576.wordpress.com/truetag:nu.federati.net,2020-06-19:objectType=thread:nonce=bd356052adecc823