POPULARITY
In this 121st episode of The G2 on 5G, Anshel and Will Cover:1. T-Mobile For Business Analyst Summit2. Semiconductor export restrictions go into effect, what does it mean for 5G?3. Reliance Jio announces Ericsson and Nokia partnerships to build its new 5G network4. Charter's new $50 internet and wireless bundle5. Verizon announces commercial SA 5G Core6. Open Signal shows Verizon and AT&T speeds improving due to C-Band rollout
Negosyong usapang Looking Forward Lagi, Pag-iisip Ng Bagong Negosyo Para Sa Iyong Man Power, Puntiryahin Ang Negosyo Na Pasok Sa Core Gift Mo At Iba Pa Sa Negosyo --- Send in a voice message: https://anchor.fm/arvinorubia/message Support this podcast: https://anchor.fm/arvinorubia/support
Today on Webcology we talk about how Google parent Alphabet Inc. has announced financial results for the first quarter of 2018. The company reported $31.1 billion in quarterly revenue, which was down sequentially but up year over year. Revenues beat Wall Street consensus estimates by about $870 million, and earnings also beat analyst expectations. Bill Slawski published an article noting that Google updated a patent related to PageRank. This is an important algorithm because it affects how sites are ranked and explain why some sites rank well while others do not. A Drupal core vulnerability was announced on the official Drupal website. This is called the SA-CORE-2018-004 vulnerability. This vulnerability allows a remote attacker to execute code on a Drupal website through “multiple attack vectors.” The official Drupal site recommends upgrading to the most recent versions of Drupal 7 or 8. Attacks based on this vulnerability have not yet been observed in the wild. So it’s important to get ahead of it and update soon. Google parent Alphabet Inc. has announced financial results for the first quarter of 2018. The company reported $31.1 billion in quarterly revenue, which was down sequentially but up year over year. Revenues beat Wall Street consensus estimates by about $870 million, and earnings also beat analyst expectations. Also, Google has confirmed rumors that a search algorithm update took place on Monday. Some sites may have seen their rankings improve, while others may have seen negative or zero change.
Today on Webcology we talk about how Google parent Alphabet Inc. has announced financial results for the first quarter of 2018. The company reported $31.1 billion in quarterly revenue, which was down sequentially but up year over year. Revenues beat Wall Street consensus estimates by about $870 million, and earnings also beat analyst expectations. Bill Slawski published an article noting that Google updated a patent related to PageRank. This is an important algorithm because it affects how sites are ranked and explain why some sites rank well while others do not. A Drupal core vulnerability was announced on the official Drupal website. This is called the SA-CORE-2018-004 vulnerability. This vulnerability allows a remote attacker to execute code on a Drupal website through “multiple attack vectors.” The official Drupal site recommends upgrading to the most recent versions of Drupal 7 or 8. Attacks based on this vulnerability have not yet been observed in the wild. So it's important to get ahead of it and update soon. Google parent Alphabet Inc. has announced financial results for the first quarter of 2018. The company reported $31.1 billion in quarterly revenue, which was down sequentially but up year over year. Revenues beat Wall Street consensus estimates by about $870 million, and earnings also beat analyst expectations. Also, Google has confirmed rumors that a search algorithm update took place on Monday. Some sites may have seen their rankings improve, while others may have seen negative or zero change.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Obfuscating Without XOR https://isc.sans.edu/forums/diary/Obfuscating+without+XOR/22544/ Airbnb OAUTH Token Theft https://www.arneswinnen.net/2017/06/authentication-bypass-on-airbnb-via-oauth-tokens-theft/ Critical Drupal Vulnerablity https://www.drupal.org/SA-CORE-2017-003 Auditing Docker Containers https://www.sans.org/reading-room/whitepapers/auditing/checklist-audit-docker-containers-37437
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Obfuscating Without XOR https://isc.sans.edu/forums/diary/Obfuscating+without+XOR/22544/ Airbnb OAUTH Token Theft https://www.arneswinnen.net/2017/06/authentication-bypass-on-airbnb-via-oauth-tokens-theft/ Critical Drupal Vulnerablity https://www.drupal.org/SA-CORE-2017-003 Auditing Docker Containers https://www.sans.org/reading-room/whitepapers/auditing/checklist-audit-docker-containers-37437
Vi pratar om Drush pluginen "Site audit" som kan generera en informationsspäckad rapport om din webbplats. Vi går igenom den rapport vi fick på drupalsnack.se. Länkar till moduler, webbplatser och tjänster vi pratade om i detta avsnitt: En ny programledare sökes Är du intresserad att vara en av Drupalsnacks programledare? Skriv då en rad till oss! Site audit Site Audit projektsida Site audit rapport för drupalsnack.se (drush audit_all –html –detail –bootstrap > site_audit.html) Modulen Hacked Modulen Security review Säkerhetsmeddelandet från Drupal.org från den 15e oktober Bredbandsbolagets modem är lätta att kapa DrupalCamp Gothenburg 14-16e november Eftersnack Apple Pay Shellshock Winter is coming Föreningen Drupal Göteborg
## The Drupal Security Team * What type of people are on the Drupal Security Team? * https://security.drupal.org/team-members * Mostly coders, some project managers, core maintainers * What does the security team do? * We fix issues in drupal * Resolve reported security issues in a Security Advisory * Provide assistance for contributed module maintainers in resolving security issues * Provide documentation on how to write secure code * Provide documentation on securing your site * Help the infrastructure team to keep the drupal.org infrastructure secure * What doesn’t the security team do * projects without stable releases * Site support * Set policy around security with the security working group. * Is there a D7 security team and a D8 security team with different people? (What about Drupal 6) * How can others get involved? * What was the recent bug that was fixed ## Questions from Twitter * [Paulius Pazdrazdys](http://www.twitter.com/Paulenas) How this latest security release is different from others? Do you have any information if this bug done any harm before release? #MUP122 * aboros @hunaboros The recent bug was über critical, still only 20/25. What would be a 25/25 bug? #MUP122 * [aboros](http://www.twitter.com/hunaboros) Do you notify any high value targets before SA is sent out? Is the list of those public? Can one be part of this privileged group? #MUP122 * [Carie Fisher](http://www.twitter.com/cariefisher) When the latest bug was found? is there a private drupal security group where this was discussed? could we have found out sooner? #MUP122 * [David Hernandez](http://www.twitter.com/davidnarrabilis) #MUP122 What is the average time from discovery to announcement? * [Damien McKenna](http://www.twitter.com/DamienMcKenna) @ModsUnraveled #MUP122 Are there existing stats on how long it takes from initial reporting, to maintainer response, to first patch & fix? * [Heine Deelstra](http://www.twitter.com/Ustima) How was SA-CORE-005 (in hindsight) able to be public for so long in the public queue? #MUP122 * [Mark Conroy](http://www.twitter.com/markconroy) I think the #drupal security team are great. Working extremely hard. (I know, that wasn't a question) #MUP122 * [aboros](http://www.twitter.com/hunaboros) Are there plans for some sort of bounty program run by DA maybe? #MUP122 * [David Hernandez](http://www.twitter.com/davidnarrabilis) #MUP122 What kind of work does the security team do besides review code? What is the administrative overhead?
Topics Security Patch Released today Approaches to address the issue. Update or patch. Handling customers Open source - security Oomph Ally Services Managing the update process with a customer Charge for updates or included in monthly service fee Writing secure code: Importance of using the API Modules Conditional Fields https://www.drupal.org/project/conditional_fields Define dependencies between fields based on their states and values. Conditional Fields for Drupal 7 is an user interface to the new States API, plus the ability to modify fields appearance and behavior on certain conditions when viewing content Resources Security Release - https://www.drupal.org/SA-CORE-2014-005 Security FAQ - https://www.drupal.org/node/2357241 Drupal Secutiry Page - https://security.drupal.org/about Oomph Ally Servcies - http://oomphinc.com/ally Drupal Security - https://twitter.com/drupalsecurity Hosts Stephen Cross - www.ParallaxInfoTech.com @stephencross Jason Pamental - www.hwdesignco.com @jpamental John Picozzi - www.oomphinc.com @johnpicozzi Nic Laflin - www.nLightened.net @nicxvan