Posts

The biggest java security vulnerability of 2021

If you use Log4j please update your libraries to the latest non affected version.  Recommended version is  2.17.0 . 0-day exploit in the popular Java logging library log4j was discovered that results in Remote Code Execution (RCE) by logging a certain string. https://www.lunasec.io/docs/blog/log4j-zero-day 

OGC Apis at Api days Paris

Image
Excellent presentation by Gobe Hobona about about OGC WEB APIs. A GIS standard that everyone should ensure awareness off.  Youtube link: https://www.youtube.com/watch?v=qSiTaZB9-Xw&t=4675s

GoDaddy security breach

An unknown attacker had gained unauthorized access to GoDaddy's managed WordPress site passwords. If you have a site with them make sure you change your password. Source link:  https://www.wordfence.com/blog/2021/11/godaddy-breach-plaintext-passwords/

FOSS4G 2021 Argentina

 Video playlist for FOSS4G 2021 Argentina is available on youtube, Youtube playlist Schedule of the talks is here:  https://2021.foss4g.org/schedule/outline.html

Microsoft Azure Security Vulnerability

 An attacker can bypass the Management Interface Authentication and execute remote code. 9.8/10 rated CVE for Azure Linux VM users. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38647

Open source alternative to Docker for Mac

Image
 As docker desktop for Mac/Win licensing is changing it is worth to consider open source alternatives. containerd & Lima might be the right combo for you. Source:  https://medium.com/nttlabs/containerd-and-lima-39e0b64d2a59

Open source free text/spatial search

Solr is an outstanding tool do free text search it also has spatial support. This allows users to search using free text + spatial boundary. An excellent soultion for trying to find assets at a certain geospatial location. Source example: https://stackoverflow.com/questions/48348312/solr-7-how-to-do-full-text-search-w-geo-spatial-search