×
Security

Hundreds of GoDaddy-Hosted Sites Backdoored In a Single Day (bleepingcomputer.com) 19

Internet security analysts have spotted a spike in backdoor infections on WordPress websites hosted on GoDaddy's Managed WordPress service, all featuring an identical backdoor payload. The case affects internet service resellers such as MediaTemple, tsoHost, 123Reg, Domain Factory, Heart Internet, and Host Europe Managed WordPress. BleepingComputer reports: The discovery comes from Wordfence, whose team first observed the malicious activity on March 11, 2022, with 298 websites infected by the backdoor within 24 hours, 281 of which were hosted on GoDaddy. The backdoor infecting all sites is a 2015 Google search SEO-poisoning tool implanted on the wp-config.php to fetch spam link templates from the C2 that are used to inject malicious pages into search results. The campaign uses predominately pharmaceutical spam templates, served to visitors of the compromised websites instead of the actual content.

The goal of these templates is likely to entice the victims to make purchases of fake products, losing money and payment details to the threat actors. Additionally, the actors can harm a website's reputation by altering its content and making the breach evident, but this doesn't seem to be the actors' aim at this time. The intrusion vector hasn't been determined, so while this looks suspiciously close to a supply chain attack, it hasn't been confirmed. [...] In any case, if your website is hosted on GoDaddy's Managed WordPress platform, make sure to scan your wp-config.php file to locate potential backdoor injections. Wordfence also reminds admins that while removing the backdoor should be the first step, removing spam search engine results should also be a priority.

United States

Four US States Plan $8 Billion Hydrogen Fuel Hub (apnews.com) 145

This week the governors of Colorado, New Mexico, Utah and Wyoming announced plans for a "hydrogen hub," reports the Associated Press.

The states hope to use $8 billion in recently approved federal infrastructure funding to make hydrogen — the most abundant element in the universe — "more available and useful as clean-burning fuel for cars, trucks and trains." Hydrogen can be derived from water using an electric current and when burned emits only water vapor as a byproduct. The fuel could theoretically reduce greenhouse emissions and air pollution, depending on how it's obtained. As with electric vehicles, however, hydrogen's potential has been limited by infrastructure. Lack of fueling stations limits the market for hydrogen-fueled vehicles. Few hydrogen-fueled vehicles limits investment in producing and moving hydrogen....

Critics point out that as it's now produced, hydrogen isn't green, carbon-free or unlimited. Currently nearly all hydrogen commercially produced in the U.S. comes not from water but natural gas, according to the U.S. Energy Information Administration. While advocates say using fossil fuels to produce hydrogen now can help to develop a clean industry later, environmentalists are skeptical. "It's essentially a push for expanded oil and gas development. More oil and gas development is completely at odds with the need to confront the climate crisis and drastically reduce our dependence on fossil fuels," Jeremy Nichols with the Santa Fe, New Mexico-based environmental group WildEarth Guardians said by email.

Colorado, New Mexico and Wyoming rank seventh, eighth and ninth, respectively, for U.S. onshore gas production. Utah also is significant gas-producing state, according to the Energy Information Administration.

Star Wars Prequels

'Windowless Bunker': First Reviews Come In for Disney's $5,000 'Star Wars Hotel (sfgate.com) 74

Disney World's "Star Wars: Galactic Starcruiser" hotel will be expensive and immersive, writes SFGate. ("For two adults, the starting price is about $5,000. For three adults and one child, it's nearly $6,000.")

And while the hotel doesn't open to paid guests until Tuesday, free previews have already been given to online influencers: Reviews so far are generally positive — particularly praised are the character actors who carry the experience — with a few caveats. Because the hotel itself, called the Halcyon, is supposed to be a luxury cruise ship in space, the biggest complaint is that rooms are small and cramped...

For some, the lack of windows may add to a sense of claustrophobia. Hotel rooms have a digital display showing outer space and no view of the real outside world. Folks needing some fresh air can, however, visit an outdoor communal space called a "climate simulator." Reporters from the YouTube channel Disney Food Blog, which has nearly 800,000 subscribers, were invited to the media preview. In their review of the hotel, they put it thusly: "Disney went all-in on an experience that seemingly puts only the wealthiest guests inside a windowless bunker for two full days."

But most reviewers agreed that guests will be spending minimal time in their room anyway. The two days are packed with lightsaber training, clandestine rendezvous, elaborate entertainment and exploration of the ship. Guests need to download an app for their smartphone to chat with characters on board, receive their missions and learn their storylines. This was the other major drawback: If you're an introvert, this may be the wrong trip for you.

The Military

Largest Plane Ever Built May Have Been Destroyed, Ukraine Foreign Minister Says (sfgate.com) 152

SFGate reports: The largest plane ever built has been destroyed at an airport outside Kyiv, Ukraine Minister of Foreign Affairs Dmytro Kuleba said Sunday....

The Antonov An-225 Mriya was built in Ukraine in 1985 when the nation was still controlled by the Soviet Union. It has six turbofan engines and is the heaviest aircraft ever built. It was created as a strategic airlift cargo craft, carrying Soviet space orbiters, but was later purchased by Antonov Airlines. It's since been used to airlift oversized cargo and large loads of emergency aid during natural disasters....

Although Kuleba's tweet confirmed the plane's demise, Antonov says it is still gathering information on the massive plane's fate.

Earth

Is There Hope in New Climate Science? (msn.com) 69

Three climate scientists wrote an encouraging opinion piece for the Washington Post: One of the biggest obstacles to avoiding global climate breakdown is that so many people think there's nothing we can do about it. They point out that record-breaking heat waves, fires and storms are already devastating communities and economies throughout the world. And they've long been told that temperatures will keep rising for decades to come, no matter how many solar panels replace oil derricks or how many meat-eaters go vegetarian. No wonder they think we're doomed.

But climate science actually doesn't say this. To the contrary, the best climate science you've probably never heard of suggests that humanity can still limit the damage to a fraction of the worst projections if — and, we admit, this is a big if — governments, businesses and all of us take strong action starting now.

For many years, the scientific rule of thumb was that a sizable amount of temperature rise was locked into the Earth's climate system. Scientists believed — and told policymakers and journalists, who in turn told the public — that even if humanity hypothetically halted all heat-trapping emissions overnight, carbon dioxide's long lifetime in the atmosphere, combined with the sluggish thermal properties of the oceans, would nevertheless keep global temperatures rising for 30 to 40 more years. Since shifting to a zero-carbon global economy would take at least a decade or two, temperatures were bound to keep rising for at least another half-century.

But guided by subsequent research, scientists dramatically revised that lag time estimate down to as little as three to five years. That is an enormous difference that carries paradigm-shifting and broadly hopeful implications for how people, especially young people, think and feel about the climate emergency and how societies can respond to it.

This revised science means that if humanity slashes emissions to zero, global temperatures will stop rising almost immediately. To be clear, this is not a get-out-of-jail-free card. Global temperatures will not fall if emissions go to zero, so the planet's ice will keep melting and sea levels will keep rising. But global temperatures will stop their relentless climb, buying humanity time to devise ways to deal with such unavoidable impacts.

In short, we are not irrevocably doomed — or at least we don't have to be, if we take bold, rapid action.

Intel

Intel Ramps Up Linux Investment By Acquiring Linutronix (phoronix.com) 3

Intel has acquired Linutronix, the German-based Linux consulting firm that is focused on embedded Linux and real-time computing. From a report: Intel's acquisition of Linutronix appears to be primarily focused as an acqui-hire with getting Linutronix's very talented staff at Intel. Among the prominent Linutronix engineers is their CTO Thomas Gleixner as a longtime kernel maintainer and important contributor on the x86 side, including with Linux's CPU security mitigations and perhaps most notably for the real-time (PREEMPT_RT) work.
Linux

ReiserFS Proposed To Be Removed From Linux In 2022 (phoronix.com) 217

UnknowingFool writes: Linux kernel developers have discussed on the kernel developers forum to remove ReiserFS from the kernel starting in 2022. ReiserFS was added as Linux's first journaling file system 21 years ago with SUSE using it as the default filesystem until 2006. However, since Hans Reiser was sent to jail 15 years ago for murder, there has not been much development or interest in it. Noting that there have been no user-spotted fixes since 2019, longtime kernel developer Matthew Wilcox also cited that ReiserFS was only block for some kernel changes he wished to implement. These days there are better alternatives like EXT4, Btrfs, XFS, and OpenZFS.
Power

After Blackouts, Texas Became a Top State for New Solar Installations as Thousands Install Microgrids (houstonchronicle.com) 60

"Thousands of Texans who have turned to solar power and battery storage, creating so-called microgrids, as a solution to blackouts," reports the Houston Chronicle.

"With a venture creating the same little power plants for apartment buildings, Texas has become a national leader in residential solar power installations." From 2019 to 2020, small-scale solar capacity in Texas grew by 63 percent, to 1,093 megawatts from 670 megawatts, according to the Energy Information Administration. In the first three quarters of 2021, another 250 megawatts of residential solar were installed in the state, according to the Solar Energy Industries Association. In last year's third quarter alone, Texas ranked second behind California in the amount of power from new installations during the period, the industry's Washington, D.C. trade group said.

Surging demand for residential solar power in Texas after the February 2021 freeze put pressure on installers to keep up, said Abigail Hopper, president and CEO of the association. The race to buy new rooftop panels has slowed some, she said, but Texas remains among the top three states for new installations. And the shrinking price of solar cells will help support its growing popularity, Hopper said.

"I think as more and more Americans really struggle with the impact of severe weather — everything from fires, the cold, hurricanes, droughts — and see the impacts on power and power outages, you're going to continue to see folks looking for resiliency," Hopper said.

IT

San Francisco's Mayor is Urging Employers to Return Workers to Downtown Offices (sfchronicle.com) 288

San Francisco mayor London Breed "is working with business leaders to push San Francisco employers to start bringing more workers back to downtown offices at some point in March," reports the San Francisco Chronicle.

"Breed said she was developing a strategy with the Chamber of Commerce and other groups to help turn around the city's once-bustling commercial core." San Francisco's downtown has been hit hard as most employees have stayed home during the pandemic.... Breed's comments reflect the pressure she's under to revive San Francisco's struggling downtown where weekday foot traffic remains sparse, small businesses have shuttered and massive office towers sit largely empty nearly two years after COVID-19 sent most workers home indefinitely. Some workers are likely to stay remote because they're concerned about being exposed to the virus or for other personal reasons.... San Francisco officials predict that around 15% of office workers will stay remote when the economy is expected to stabilize in 2023, a major shift that would permanently hurt business tax revenue, according to a report released last month....

Despite rampant commercial vacancies and an abundance of employees choosing to work remotely in perpetuity or leave San Francisco entirely, Breed said she was encouraged by a number of businesses that have signed new leases or are looking at new opportunities in the city. "Working from home has been so convenient and so comfortable, let's be honest," Breed said. "But at the same time, people miss people. They miss being out in the streets. They miss being at places and restaurants."

John Bryant, CEO of the Building Owners and Managers Association of San Francisco, tells the newspaper that downtown San Francisco's buildings are only about 20% occupied now. And that this year he hopes to see that double — to 40%.

Thanks to Slashdot reader nray for sharing the story...
Space

The Sun Has Erupted Non-Stop All Month, and There Are More Giant Flares Coming (sciencealert.com) 68

Over the past few weeks the sun "has undergone a series of giant eruptions that have sent plasma hurtling through space," reports Science Alert: Perhaps the most dramatic was a powerful coronal mass ejection and solar flare that erupted from the far side of the Sun on February 15 just before midnight. Based on the size, it's possible that the eruption was in the most powerful category of which our Sun is capable: an X-class flare.

Because the flare and CME were directed away from Earth, we're unlikely to see any of the effects associated with a geomagnetic storm, which occurs when material from the eruption slams into Earth's atmosphere. These include interruptions to communications, power grid fluctuations, and auroras. But the escalating activity suggests that we may anticipate such storms in the imminent future. "This is only the second farside active region of this size since September 2017," astronomer Junwei Zhao of Stanford University's helioseismology group told SpaceWeather. "If this region remains huge as it rotates to the Earth-facing side of the Sun, it could give us some exciting flares."

According to SpaceWeatherLive, which tracks solar activity, the Sun has erupted every day for the month of February, with some days featuring multiple flares. That includes three of the second-most powerful flare category, M-class flares: an M1.4 on February 12; an M1 on February 14; and an M1.3 on February 15. There were also five M-class flares in January. The mild geomagnetic storm that knocked 40 newly launched Starlink satellites from low-Earth orbit followed an M-class flare that took place on January 29.

The article suggests this is normal activity, since the sun is about halfway towards "solar maximum" (its peak of sunspot and flare activity) expected to arrive in 2025, while the "solar minimum" was in 2019.

Further Reading: SciTechDaily reports that the ESA/NASA Solar Orbiter spacecraft has now "captured the largest solar prominence eruption ever observed in a single image together with the full solar disc."

Thanks to long-time Slashdot reader schwit1 for submitting the story
Programming

TIOBE Adjusts Programming Language Popularity Calculations. Python, C, and Java Still Popular (techrepublic.com) 31

"As of the 1st of May, the Alexa web traffic ranking engine is going to stop its services," the TIOBE Index reminds us. So for the first time, TIOBE has switched to Similarweb this month to choose which search engines' results to use for its ranking of the popularity of programming languages. Fortunately, there are no big changes in the index due to this swap. The only striking difference is that the top 3 languages, Python, C, and Java, all gained more than 1 percent in the rankings.

We are still fine-tuning the integration with Similarweb, which is combined with a shift to HtmlUnit in the back-end. Some websites are not onboarded yet, but will follow soon. Now that HtmlUnit is applied for web crawling, it will become possible to add more sites to the index, such as Stackoverflow and Github. This will hopefully happen in the next few months.

TechRepublic reports: Python continues to sit atop the index, with C and Java directly behind it. In Feb. 2021, those three also occupied the top spot, but with Python in the number three position, C at top, and Java in second place.

Beyond the top three, there hasn't been much movement in the index, with positions four through eight unchanged from the same time last year. Those slots are occupied, respectively, by C++, C#, Visual Basic, JavaScript and PHP. Positions nine and 10 swapped from Feb. 21 to now, with Assembly Language and SQL now occupying each other's positions.

The one big move of note between Feb. 2021 and Feb. 2022 was with the Groovy programming language, an object-oriented language for Java. Over the course of the year, Groovy fell from 12th position all the way to 20th, putting it perilously close to the "other programming languages" list.

Thanks to Amigan (Slashdot reader #25,469) for sharing the story.
Patents

Alarm Raised After Microsoft Wins Data-Encoding Patent (theregister.com) 46

Microsoft last month received a US patent covering modifications to a data-encoding technique called rANS, one of several variants in the Asymmetric Numeral System (ANS) family that support data compression schemes used by leading technology companies and open source projects. The Register reports: The creator of ANS, Jaroslaw Duda, assistant professor at Institute of Computer Science at Jagiellonian University in Poland, has been trying for years to keep ANS patent-free and available for public use. Back in 2018, Duda's lobbying helped convince Google to abandon its ANS-related patent claim in the US and Europe. And he raised the alarm last year when he learned Microsoft had applied for an rANS (range asymmetric number system) patent.

Now that Microsoft's patent application has been granted, he fears the utility of ANS will be diminished, as software developers try to steer clear of a potential infringement claim. "I don't know what to do with it -- [Microsoft's patent] looks like just the description of the standard algorithm," he told The Register in an email. The algorithm is used in JPEG XL and CRAM, as well as open source projects run by Facebook (Meta), Nvidia, and others. "This rANS variant is [for example] used in JPEG XL, which is practically finished (frozen bitstream) and [is] gaining support," Duda told The Register last year. "It provides ~3x better compression than JPEG at similar computational cost, compatibility with JPEG, progressive decoding, missing features like HDR, alpha, lossless, animations. "There is a large team, mostly from Google, behind it. After nearly 30 years, it should finally replace the 1992 JPEG for photos and images, starting with Chrome, Android."

Chromium

Otter Browser Aims To Bring Chromium To Decades-Old OS/2 Operating System (xda-developers.com) 54

"The OS/2 community is getting close to obtaining a modern browser on their platform," writes Slashdot reader martiniturbide. In an announcement article on Monday, president of the OS/2 Voice community, Roderick Klein, revealed that a public beta of the new Chromium-based Otter Browser will arrive "in the last week of February or the first week of March." XDA Developers reports: OS/2 was the operating system developed jointly by IBM and Microsoft in the late 1980s and early 1990s, with the intended goal of replacing all DOS and Windows-based systems. However, Microsoft decided to focus on Windows after the immense popularity of Windows 3.0 and 3.1, leaving IBM to continue development on its own. IBM eventually stopped working on OS/2 in 2001, but two other companies licensed the operating system to continue where IBM left off -- first eComStation, and more recently, ArcaOS.

BitWise Works GmbH and the Dutch OS/2 Voice foundation started work on Otter Browser in 2017, as it was becoming increasingly difficult to keep an updated version of Firefox available on OS/2 and ArcaOS. Firefox 49 ESR from 2016 is the latest version available, because that's around the time Mozilla started rewriting significant parts of Firefox with Rust code, and there's no Rust compiler for OS/2. Since then, the main focus has been porting Qt 5.0 to OS/2, which includes the QtWebEngine (based on Chromium). This effort also has the side effect of making more cross-platform ports possible in the future.

Crime

SFPD Puts Rape Victims' DNA Into Database Used To Find Criminals, DA Alleges (arstechnica.com) 132

An anonymous reader quotes a report from Ars Technica: The San Francisco Police Department's crime lab has been checking DNA collected from sexual assault victims to determine whether any of the victims committed a crime, according to District Attorney Chesa Boudin, who called for an immediate end to the alleged practice. "The crime lab attempts to identify crime suspects by searching a database of DNA evidence that contains DNA collected from rape and sexual assault victims," Boudin's office said in a press release yesterday. Boudin's release denounced the alleged "practice of using rape and sexual assault victims' DNA to attempt to subsequently incriminate them."

"Boudin said his office was made aware of the purported practice last week, after a woman's DNA collected years ago as part of a rape exam was used to link her to a recent property crime," the San Francisco Chronicle reported yesterday. The woman "was recently arrested on suspicion of a felony property crime, with police identifying her based on the rape-kit evidence she gave as a victim, Boudin said." That was the only example provided, and Boudin gave few details about the case to protect the woman's privacy. But the database may include "thousands of victims' DNA profiles, with entries over 'many, many years,' Boudin said," according to the Chronicle. "We should encourage survivors to come forward -- not collect evidence to use against them in the future. This practice treats victims like evidence, not human beings. This is legally and ethically wrong," Boudin said.

San Francisco Police Chief Bill Scott said the department will investigate and that he is "committed to ending the practice" if Boudin's allegation is accurate. But Scott also said the suspect cited by Boudin may have been identified from a different DNA database. "We will immediately begin reviewing our DNA collection practices and policies... Although I am informed of the possibility that the suspect in this case may have been identified through a DNA hit in a non-victim DNA database, I think the questions raised by our district attorney today are sufficiently concerning that I have asked my assistant chief for operations to work with our Investigations Bureau to thoroughly review the matter and report back to me and to our DA's office partners," Scott said in a statement published by KRON 4. Scott also said, "I am informed that our existing DNA collection policies have been legally vetted and conform with state and national forensic standards," but he noted that "there are many important principles for which the San Francisco Police Department stands that go beyond state and national standards." "We must never create disincentives for crime victims to cooperate with police, and if it's true that DNA collected from a rape or sexual assault victim has been used by SFPD to identify and apprehend that person as a suspect in another crime, I'm committed to ending the practice," Scott said.
Even though the alleged practice may already be illegal under California's Victims' Bill of Rights, State Senator Scott Wiener (D-San Francisco) and District 9 Supervisor Hillary Ronen are planning legislation to stop the alleged misuse of DNA.

Wiener said that "if survivors believe their DNA may end up being used against them in the future, they'll have one more reason not to participate in the rape kit process. That's why I'm working with the DA's office to address this problem through state legislation, if needed."
Transportation

DeLorean Is Being Revived (Again), This Time As Electric Vehicle (bloomberg.com) 82

An anonymous reader quotes a report from Bloomberg: The newest entrant in the fight for EV market share is going back to the future with an all-electric DeLorean. The infamous gull-winged car is being resurrected in Texas by a group of executives who most recently spent time at China-backed EV startup Karma Automotive. They're working with Stephen Wynne, who acquired the DeLorean branding rights in the 1990s and supplies parts for the 6,000 or so remaining vehicles. [...] The new company is called DeLorean Motors Reimagined LLC and its chief executive officer is Joost de Vries, Texas business records and LinkedIn postings show. The firm will set up a headquarters and an engineering outfit in San Antonio, with potential to bring 450 jobs, the city's development arm said in a statement.

It's not the first time the idea of a DeLorean redux has surfaced -- web searches turn up stories every few years about how Wynne has tried to revive the brand or produce low-volume models -- but using an electric powertrain is a new twist on the idea. The original car gained notoriety in the early 1980s both for its quality problems and for the legal woes of its creator, the late John DeLorean, before the "Back to the Future" film franchise turned it into a pop-culture icon.

Intel

Intel Thread Director Is Headed to Linux for a Major Boost in Alder Lake Performance (hothardware.com) 38

The Linux 5.18 kernel is adding support this spring for the Intel Hardware Feedback Interface to make better decisions about where to place given work among available CPU cores/threads, reports Phoronix.

This is significant because Intel's Alder Lake CPUs "are the first x86-64 processors to embrace a hybrid paradigm with two separate CPU architectures on the same die," explains Hot Hardware: These two separate CPU architectures have different strengths and capabilities. The Golden Cove "performance cores" (or P-cores) feature Intel's latest high-performance desktop CPU architecture, and they are blisteringly fast. Meanwhile, the Gracemont "efficiency cores" (or E-cores) are so small that four of them, along with 2MB of shared L2 cache, can nearly fit in the same space as a single Golden Cove core. They're slower than the Golden Cove cores, but also much more efficient, at least in theory.

The idea is that background tasks and light workloads can be run on the E-cores, saving power, while latency-sensitive and compute-intensive tasks can be run on the faster P-cores. The benefits of this may not have been exactly as clear as Intel would have liked on Windows, but they were even less visible on Linux. That's because Linux isn't aware of the unusual configuration of Alder Lake CPUs.

Well, that's changing in Linux 5.18, slated for release this spring. Linux 5.18 is bringing support for the Intel Enhanced Hardware Feedback Interface, or EHFI...

This is essentially the crux of Intel's "Thread Director," which is an intelligent, low-latency hardware-assisted scheduler.

United States

US Nuclear Power Plants Contain Dangerous Counterfeit Parts, Report Finds (theverge.com) 129

At least some nuclear power plants in the US contain counterfeit parts that could pose significant risks, an investigation by the inspector general's office of the Nuclear Regulatory Commission has found. Those parts "present nuclear safety and security concerns that could have serious consequences," says the resulting report (PDF) published on February 9th. The Verge reports: The investigation was conducted after unnamed individuals alleged that "most, if not all," nuclear plants in the US have fake or faulty parts. The inspector general's office uncovered problems with counterfeit parts at a few different plants as part of its investigation. The report also says that the DOE had separately flagged 100 "incidents" involving counterfeit parts just last year. It's a problem that the US will have to crack down on if it moves forward with plans to include nuclear power in its transition to clean energy. Without greater oversight at the NRC, the report warns, the risk of counterfeit parts going unnoticed in the nation's nuclear power plants could rise.

As part of its inquiry, the inspector general's office looked for parts that are illegally altered to look like legitimate products, parts that are "intentionally misrepresented to deceive," and parts that don't meet product specifications. It sampled four power plants across the US and found evidence of counterfeit parts at one of those plants in the midwest. It also points to nuclear power plants in the Northeast, separate from those it sampled, where a "well-placed NRC principal" found that counterfeit parts were involved in two separate component failures.

The NRC might be underestimating the prevalence of counterfeit parts, the report warns, because the regulatory agency doesn't have a robust system in place for tracking problematic parts. It only requires plants to report counterfeits in extraordinary circumstances, like if they lead to an emergency shutdown of a reactor. The report also notes that the NRC hasn't thoroughly investigated all counterfeit allegations. There were 55 nuclear power plants operating in the US as of September 2021, and the inspector general's office sampled just four for its report. NRC Public Affairs Officer Scott Burnell told The Verge in an email that "nothing in the report suggests an immediate safety concern. The NRC's office of the Executive Director for Operations is thoroughly reviewing the report and will direct the agency's program offices to take appropriate action."

Security

Hundreds of E-Commerce Sites Booby-Trapped With Payment Card-Skimming Malware (arstechnica.com) 9

An anonymous reader quotes a report from Ars Technica, written by Dan Goodin: About 500 e-commerce websites were recently found to be compromised by hackers who installed a credit card skimmer that surreptitiously stole sensitive data when visitors attempted to make a purchase. A report published on Tuesday is only the latest one involving Magecart, an umbrella term given to competing crime groups that infect e-commerce sites with skimmers. Over the past few years, thousands of sites have been hit by exploits that cause them to run malicious code. When visitors enter payment card details during purchase, the code sends that information to attacker-controlled servers.

Sansec, the security firm that discovered the latest batch of infections, said the compromised sites were all loading malicious scripts hosted at the domain naturalfreshmall[.]com. "The Natural Fresh skimmer shows a fake payment popup, defeating the security of a (PCI compliant) hosted payment form," firm researchers wrote on Twitter. "Payments are sent to https://naturalfreshmall.com/p...." The hackers then modified existing files or planted new files that provided no fewer than 19 backdoors that the hackers could use to retain control over the sites in the event the malicious script was detected and removed and the vulnerable software was updated. The only way to fully disinfect the site is to identify and remove the backdoors before updating the vulnerable CMS that allowed the site to be hacked in the first place.

Sansec worked with the admins of hacked sites to determine the common entry point used by the attackers. The researchers eventually determined that the attackers combined a SQL injection exploit with a PHP object injection attack in a Magento plugin known as Quickview. [...] It's not hard to find sites that remain infected more than a week after Sansec first reported the campaign on Twitter. At the time this post was going live, Bedexpress[.]com continued to contain this HTML attribute, which pulls JavaScript from the rogue naturalfreshmall[.]com domain. The hacked sites were running Magento 1, a version of the e-commerce platform that was retired in June 2020. The safer bet for any site still using this deprecated package is to upgrade to the latest version of Adobe Commerce. Another option is to install open source patches available for Magento 1 using either DIY software from the OpenMage project or with commercial support from Mage-One.

Intel

Intel's Pay-As-You-Go CPU Feature Gets Launch Window (tomshardware.com) 180

Intel's mysterious Software Defined Silicon (SDSi) mechanism for adding features to Xeon CPUs will be officially supported in Linux 5.18, the next major release of the operating system. Tom's Hardware reports: SDSi allows users to add features to their CPU after they've already purchased it. Formal SDSi support means that the technology is coming to Intel's Xeon processors that will be released rather shortly, implying Sapphire Rapids will be the first CPUs with SDSi. Intel started to roll out Linux patches to enable its SDSi functionality in the OS last September. By now, several sets of patches have been released and it looks like they will be added to Linux 5.18, which is due this Spring. Hans de Goede, a long-time Linux developer who works at Red Hat on a wide array of hardware enablement related projects, claims that SDSi will land in Linux 5.18 if no problems emerge, reports Phoronix. "Assuming no major issues are found, the plan definitely is to get this in before the 5.18 merge window," said de Goede.

Intel Software Defined Silicon (SDSi) is a mechanism for activating additional silicon features in already produced and deployed server CPUs using the software. While formal support for the functionality is coming to Linux 5.18 and is set to be available this spring, Intel hasn't disclosed what exactly it plans to enable using its pay-as-you-go CPU upgrade model. We don't know how it works and what it enables, but we can make some educated guesses. [...]

Operating Systems

System76-Scheduler Is a New Pop!_OS Rust Effort To Improve Desktop Responsiveness (phoronix.com) 43

slack_justyb writes: "Quietly making its v1.0 debut yesterday was system76-scheduler as a Rust-written daemon aiming to improve Linux desktop responsiveness and catering to their Pop!_OS distribution," reports Phoronix.

The daemon will work with the kernel's CFS scheduler to give priority to components that System76 deems important for its distro. Out of the box, the scheduler will assign priority to the X.Org Server and desktop window managers/compositors, while pushing compilers and other background tasks lower. However, the scheduler will be configurable via Rusty Object Notation (RON) files found in /etc/system76-scheduler/assignments/ and /usr/share/system76-scheduler/assignments/.

Over on the GitHub page for the project, the team indicates that they are indeed making a trade-off from the default CFS to benefit Desktop configurations over the typical load a server might see.

Slashdot Top Deals