
Blog
Three OpenVPN setups, and which one you need
The TurnKey OpenVPN appliance supports three modes because “I need a VPN” hides three different jobs. Pick the job first. The routing makes more sense after that. 1. Reach your …
Topic
31 matching pages

Blog
The TurnKey OpenVPN appliance supports three modes because “I need a VPN” hides three different jobs. Pick the job first. The routing makes more sense after that. 1. Reach your …
Blog
In case you missed it, earlier this month, Mibew released an update that include "many security updates". So we have deprecated all previous versions and now provided an updated …
Blog
It has come to our attention that a number of Webmin releases include a vulnerability that could allow a remote attacker to take control of a server with a vulnerable version of …
Blog
Bugfixes and Updates We have published a number of updated appliances since my last appliance updates blog post (all the way back in February!?). This post is well overdue and in …
Blog
Bugfixes and Updates There are 13 12 Appliances that have recently been updated, and one new appliance; OpenCart. Some appliances include security related updates, some include …
Blog
SA-CORE-2019-003 - Highly critical - Remote Code Execution Popular CMS platform Drupal recently announced a highly critical security vulnerability: SA-CORE-2019-003. This …
Blog
SA-CORE-2018-006 - Multiple Vulnerabilities in Drupal 7 & 8 Popular CMS platform Drupal have just announced that versions of Drupal 7 prior to 7.60 and Drupal 8 prior to 8.5.8 …
Blog
UPDATE: An updated v15.1 Drupal 8 appliance has been released. Read more here (part of the v15.0 stage 3 announcement). SA-CORE-2018-005 - Drupal 8 Popular CMS platform Drupal …
Blog
Late last week, the Drupal Security Team announced a "Highly critical" remote code execution vulnerability that affects Drupal 6 (EOL), Drupal 7 and Drupal 8. SA-CORE-2018-002 …
Blog
By now, I'm sure that you've already heard of the latest vulnerabilities doing the rounds; tagged Meltdown and Spectre. As seems to be the fashion, these new vulnerabilities have …
Blog
Once again, thanks to community member John Carver for highlighting a new Linux vulnerability. Qualys Security Labs discovered and demonstrated the vulnerability, and have named …
Blog
Thanks to TurnKey community member John Carver it has come to our attention that all existing deployments of TurnKey Linux are potentially vulnerable to CVE-2016-5195. As reported …
Blog
Another year, another Pwn2Own contest. http://blog.trendmicro.com/pwn2own-2016-begun/ http://blog.trendmicro.com/pwn2own-day-2-event-wrap/ TL;DR results for 2016: Prize money: …
Blog
Alon is contemplating replacing his laptop so I figured I would recommend he take a look at Purism, a company offering laptops that are designed for people that care about …
Blog
It has come to our attention that existing deployments of TurnKey GitLab (versions 14.0 & 14.1) are vulnerable to CVE-2016-4340, a critical security issue that allows …
Blog
Thanks to vondrt4 for bringing CVE-2016-4010 to our attention. This was a potentially critical vulnerability in Magento that turns out not to apply to TurnKey Magento, because it …
Blog
Thanks to ElColmo it has come to our attention that existing deployments of TurnKey Jenkins are still vulnerable to CVE-2015-8103, a critical issue that allows remote code …
Blog
Imagine someone half-competent wants to hack into your computer. They want to read your e-mail, steal your bitcoins, transfer funds via your PayPal account, etc. You're behind a …
Blog
A remotely exploitable, 14 year old bug in glibc has reared its ugly head: CVE-2015-0235 Security updates have been pushed out automatically, courtesy of Debian (security tracker) …
Blog
Peter Lieven from KAMP.de discovered a problem with TurnKey 13.0 where the OpenSSH ECDSA key is not regenerated on firstboot like the RSA and DSA host keys. We've issued a signed …
Blog
Just because you're paranoid doesn't mean they aren't out to getcha. Here's another example of why we need free software running the Internet. When I bought my Medialink router it …
Blog
@pa2013 helpfully posted Alon's BitKey announcement from last week to the Bitcoin Reddit, which sparked an interesting discussion regarding whether or not you can safely trust …
Blog
This announcement is for Debian 6.0 (AKA Squeeze / TurnKey 12) users who have not yet upgraded to Debian 7.0 (AKA Wheezy / TurnKey 13): ~# cat /etc/issue.net Debian GNU/Linux 6.0 …
Blog
Without action, your TurnKey 13 installations may remain vulnerable to the critical Heartbleed OpenSSL attack (DSA-2896-1 CVE-2014-0160). This is not a theoretical attack. A …
Blog
I have some bad news and some good news. The bad news is that if your TurnKey installation is older than 2 weeks you may no longer be receiving security updates. The good news is …
Blog
I'd like to introduce Joe. He is a good looking, experienced sys-admin and like all good sysadmins, he has more stuff to do than time to do it. Joe wants to get up and running on …
Blog
In our quest to make the upcoming TurnKey 11.0 release more "turnkey", I set out to extend the firstboot inithooks to include application specific …
Blog
Background: how a backup key works In TKLBAM the backup key is a secret encrypted with a passphrase which is uploaded to the Hub. Decrypting the backup key yields the secret which …
Blog
We've just pushed out a maintenance release for the 2009.10 appliance batch featuring: Bugfixes for all outstanding issues (we're out of beta baby!) Security updates Simplified …
Blog
Important note: Please note that current appliances include support for getting free Let's Encrypt SSL certificates. Please see the Let's Encrypt docs within the new Confconsole …
Blog
Why we disabled SSL and use an SSH tunnel for web site administration Content managements systems like the one we're using for the web site (Drupal) need to provide a privileged …