Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×

Submission + - Drupal Fixes Highly Critical SQL Injection Flaw 1

An anonymous reader writes: Drupal has patched a critical SQL injection vulnerability in version 7.x of the content management system that can allow arbitrary code execution. The flaw lies in an API that is specifically designed to help prevent against SQL injection attacks. “Drupal 7 includes a database abstraction API to ensure that queries executed against the database are sanitized to prevent SQL injection attacks,” the Drupal advisory says. “A vulnerability in this API allows an attacker to send specially crafted requests resulting in arbitrary SQL execution. Depending on the content of the requests this can lead to privilege escalation, arbitrary PHP execution, or other attacks.”
United States

Pentagon Reportedly Hushed Up Chemical Weapons Finds In Iraq 376

mr_mischief writes "Multiple sources report that the US found remnants of WMD programs, namely chemical weapons, in Iraq after all. Many US soldiers were injured by them, in fact. The Times reports: "From 2004 to 2011, American and American-trained Iraqi troops repeatedly encountered, and on at least six occasions were wounded by, chemical weapons remaining from years earlier in Saddam Hussein's rule. In all, American troops secretly reported finding roughly 5,000 chemical warheads, shells or aviation bombs, according to interviews with dozens of participants, Iraqi and American officials, and heavily redacted intelligence documents obtained under the Freedom of Information Act."
DRM

Mozilla Teams Up With Humble Bundle To Offer Eight Plugin-Free Games 67

An anonymous reader writes Mozilla and Humble Bundle announced a new package that features award-winning indie best-sellers for which gamers can choose how much they want to pay. Naturally called the Humble Mozilla Bundle, the package consists of eight games that have been ported to the Web. The first five games (Super Hexagon, AaaaaAAaaaAAAaaAAAAaAAAAA!!! for the Awesome, Osmos, Zen Bound 2, and Dustforce DX) can cost you whatever you want. The next two (Voxatron and FTL: Faster Than Light) can be had if you beat the average price for the bundle. You can pay $8 or more to receive all of the above, plus the last game, Democracy 3. Previously, all of these indie games were available only on PC or mobile. Now they all work in browsers on Windows, Mac, and Linux without having to install any plugins.
Google

Google Announces Motorola-Made Nexus 6 and HTC-Made Nexus 9 201

An anonymous reader writes In addition to Android 5.0 Lollipop, Google today also announced the first devices running the new version of its mobile operating system: the Nexus 6 and the Nexus 9. The former is a phablet built by Motorola, and the latter is a tablet built by HTC. The Nexus 6 is going up for pre-order on October 29, starting at $649. The Nexus 9 meanwhile is going up for pre-order this Friday (October 17), and you'll also be able to get it in stores on November 3.
Transportation

Designing Tomorrow's Air Traffic Control Systems 72

aarondubrow writes According to FAA estimates, increasing congestion in the air transportation system of the United States, if unaddressed, will cost the American economy $22 billion annually in lost economic activity by 2022. MIT researcher Hamsa Balakrishnan and her team are making air traffic control systems more efficient through a combination of better models and new embedded technologies. Testing their algorithms at Logan Airport in Boston, they showed that by holding aircraft back for 4.5 minutes, they could improve flow on the runways and save nearly 100 pounds of fuel for each aircraft.
Earth

Pentagon Unveils Plan For Military's Response To Climate Change 228

An anonymous reader writes Rising sea levels and other effects of climate change will create major problems for America's military, including more and worse natural disasters and food and water shortages that could fuel disputes around the world, Defense Secretary Chuck Hagel said Monday. From the article: "The Pentagon's 2014 Climate Change Adaptation Roadmap (PDF) describes how global warming will bring new demands on the military. Among the report's conclusions: Coastal military installations that are vulnerable to flooding will need to be altered; humanitarian assistance missions will be more frequent in the face of more intense natural disasters; weapons and other critical military equipment will need to work under more severe weather conditions. 'This road map shows how we are identifying — with tangible and specific metrics, and using the best available science — the effects of climate change on the department's missions and responsibilities,' Hagel said. 'Drawing on these assessments, we will integrate climate change considerations into our planning, operations, and training.'"
Television

Netflix To Charge More For 4K Video 158

Mr D from 63 points out that watching Netflix in Ultra high-definition is going to cost you a little extra per month. A higher-resolution, 4K stream from Netflix will cost more. The company has boosted its monthly price for streaming ultrahigh-definition television and movies to $11.99 per month, citing the higher expenses associated with that content. In May, Netflix announced that its original series, such as House of Cards, would be available to stream in the 4K format, which offers roughly four times the resolution of current high-def TVs.

Submission + - Pentagon unveils plan for military's response to climate change

An anonymous reader writes: Rising sea levels and other effects of climate change will create major problems for America's military, including more and worse natural disasters and food and water shortages that could fuel disputes around the world, Defense Secretary Chuck Hagel said Monday. From the article: "The Pentagon’s '2014 Climate Change Adaptation Roadmap' describes how global warming will bring new demands on the military. Among the report's conclusions: Coastal military installations that are vulnerable to flooding will need to be altered; humanitarian assistance missions will be more frequent in the face of more intense natural disasters; weapons and other critical military equipment will need to work under more severe weather conditions. 'This road map shows how we are identifying — with tangible and specific metrics, and using the best available science — the effects of climate change on the department’s missions and responsibilities,' Hagel said. 'Drawing on these assessments, we will integrate climate change considerations into our planning, operations, and training.'”
Security

Password Security: Why the Horse Battery Staple Is Not Correct 549

First time accepted submitter Dadoo writes By now, everyone who reads Slashdot regularly has seen the XKCD comic discussing how to choose a more secure password, but at least one security researcher rejects that theory, asserting that password managers are the most important technology people can use to keep their accounts safe. He says, "In this post, I'm going to make the following arguments: 1) Choosing a password should be something you do very infrequently. 2) Our focus should be on protecting passwords against informed statistical attacks and not brute-force attacks. 3) When you do have to choose a password, one of the most important selection criteria should be how many other people have also chosen that same password. 4) One of the most impactful things that we can do as a security community is to change password strength meters and disallow the use of common passwords."
Space

Secretive X-37B Military Space Plane Could Land On Tuesday 81

schwit1 writes After twenty-two months in orbit, on its second space mission, the Air Force plans to bring the X-37B back to Earth this coming Tuesday. From the article: "The exact time and date will depend on weather and technical factors, the Air Force said in a statement released on Friday. The X-37B space plane, also known as the Orbital Test Vehicle, blasted off for its second mission aboard an unmanned Atlas 5 rocket from Cape Canaveral Air Force Station in Florida on Dec. 11, 2012. The 29-foot-long (9-meter) robotic spaceship, which resembles a miniature space shuttle, is an experimental vehicle that first flew in April 2010. It returned after eight months. A second vehicle blasted off in March 2011 and stayed in orbit for 15 months."
EU

Google Rejects 58% of "Right To Be Forgotten" Requests 144

gurps_npc writes CNN Money has a short, interesting piece on the results of Google implementing Europe's "Right to be Forgotten." They are denying most requests, particularly those made by convicted criminals, but are honoring the requests to remove salacious information — such as when a rape victim requested the article mentioning her by name be removed from searches for her name. "In evaluating a request, we will look at whether the results include outdated or inaccurate information about the person," Google said. "We'll also weigh whether or not there's a public interest in the information remaining in our search results -- for example, if it relates to financial scams, professional malpractice, criminal convictions or your public conduct as a government official."
Books

Book Review: Scaling Apache Solr 42

First time accepted submitter sobczakt writes We live in a world flooded by data and information and all realize that if we can't find what we're looking for (e.g. a specific document), there's no benefit from all these data stores. When your data sets become enormous or your systems need to process thousands of messages a second, you need to an environment that is efficient, tunable and ready for scaling. We all need well-designed search technology. A few days ago, a book called Scaling Apache Solr landed on my desk. The author, Hrishikesh Vijay Karambelkar, has written an extremely useful guide to one of the most popular open-source search platforms, Apache Solr. Solr is a full-text, standalone, Java search engine based on Lucene, another successful Apache project. For people working with Solr, like myself, this book should be on their Christmas shopping list. It's one of the best on this subject. Read below for the rest of sobczakt's review.
Patents

Interviews: Ask Florian Mueller About Software Patents and Copyrights 187

Florian Mueller is a blogger, software developer and former consultant who writes about software patents and copyright issues on his FOSSPatents blog. In 2004 he founded the NoSoftwarePatents campaign, and has written about Microsoft's multi-billion-dollar Android patent licensing business and Google's appeal of Oracle's Android-Java copyright case to the Supreme Court. Florian has agreed to give us some of his time in order to answer your questions. As usual, ask as many as you'd like, but please, one per post.
Google

Ask Slashdot: Why Can't Google Block Spam In Gmail? 265

An anonymous reader writes Every day my gmail account receives 30-50 spam emails. Some of it is UCE, partially due to a couple dingbats with similar names who apparently think my gmail account belongs to them. The remainder looks to be spambot or Nigerian 419 email. I also run my own MX for my own domain, where I also receive a lot of spam. But with a combination of a couple DNSBL in my sendmail config, SpamAssassin, and procmail, almost none of it gets through to my inbox. In both cases there are rare false positives where a legit email ends up in my spam folder, or in the case of my MX, a spam email gets through to my Inbox, but these are rare occurrences. I'd think with all the Oompa Loompas at the Chocolate Factory that they could do a better job rejecting the obvious spam emails. If they did it would make checking for the occasional false positives in my spam folder a teeny bit easier. For anyone who's responsible for shunting Web-scale spam toward the fate it deserves, what factors go into the decision tree that might lead to so much spam getting through?
Privacy

The Correct Response To Photo Hack Victim-Blamers 622

Bennett Haselton writes As commenters continue to blame Jennifer Lawrence and other celebrities for allowing their nude photos to be stolen, there is only one rebuttal to the victim-blaming which actually makes sense: that for the celebrities taking their nude selfies, the probable benefits of their actions outweighed the probable negatives. Most of the other rebuttals being offered, are logically incoherent, and, as such, are not likely to change the minds of the victim-blamers. Read below to see what Bennett has to say.

Slashdot Top Deals

"If you want to know what happens to you when you die, go look at some dead stuff." -- Dave Enyeart

Working...