Docker in unprivileged container (Arch based) in Proxmox

Back to proxmox

As I mentioned in my previous post, I’m using proxmox (again). But, in the same time, I wanted to migrate my services without long disruption, so I decided to move whole docker stack, as it is. But I prefer to use LXC containers than VMs. Why? Because LXC containers are faster and they are using less resources.

LXC are better than VMs because are:

  • Lightweight – than means LXC containers have a smaller footprint and require fewer system resources compared to VMs.
  • LXC containers share the host system’s kernel, reducing the overhead of running multiple operating systems.
  • Faster – LXC containers have quicker startup times.
  • Efficient resource handling – LXC containers efficiently manage system resources, optimizing performance and reducing waste. Mostly because LXC is not blocking resources like VM. So even if you declare 16GB of memory for LXC container, it will use only us much as needed, instead of block 16GB like VMs do.

Virtual Machines are better than LXC containers because they are:

  • Not connected to host kernel – that means you can virtualize any OS, not only Linux based. So if you want to use Windows, MacOS, FreeBSD, etc you cannot use LXC, but VM
  • They are isolated from host OS – that means they are safer by default. Because they’re isolated, security issues in one VM won’t spill over to others—crucial for maintaining system integrity and uptime. From the same reason, any kernel panic error will crash only VM, not whole host with all containers.
  • May emulate different hardware – Proxmox VMs emulate a complete set of hardware, creating an entirely isolated environment for each operating system.

Docker in unprivileged container

I have to mention – according to the Proxmox documentation, docker should be run in VM, not in LXC container. If you want to use LXC container, then you have two possibilities – privileged or unprivileged. Privileged containers running on host root account, so it’s not safe, that’s why I’m not using them at all.

Read more Docker in unprivileged container (Arch based) in Proxmox

New toys in my garage :)

Changes… again

I know I made changes in my home server configuration few months ago (you may read about that here), but I really like the idea of High Availability cluster based on Proxmox. In the same time, I’m in love with Archbang, and right now this is my distribution of choice (even, if I was in love with Debian for almost twenty years). In my career I worked with different distros, some Debian-based, mostly red-hat based (company standard after all). I worked with SUSE, Gentoo and many other too, but for years Debian was my preferred system. And right now I may say – Archbang is my preferred Linux distro at this moment of my life 🙂

Going back to the topic – I bought few new toys.

NAS – nothing fancy, but still working:

The Netgear ReadyNAS 314 (RN314) Small / Medium business NAS released in 2013. It is powered by Intel Atom D2701 dual-core @ 2.1 GHz CPU and 2 GB RAM. It has 1 x USB 2.0, 2 x USB 3.0 port(s) that can be used to connect printers and external drives. The ReadyNAS 314 device has 4 x 3.5″ SATA III bay(s) and 2 x Gigabit Ethernet LAN interfaces. And what is really nice, it may host some apps (except latest software version, 6.10.10, which removed this option). So I downgrade software to 6.10.9 and (after some tweaks) I have docker on it (just in case).

Read more New toys in my garage 🙂

No more VPS

A little of history

For a really long time I was using Contabo VPS as my main server. I was really happy with it. Good thing was, I bought it long time ago, before changes in packages, so I had few cores more then you may have right now for the same price. Similar story was with system memory. Ok, disk storage was lower then you will get now, but it wasn’t important for me. In my case, most of the space is used by images, and all of them are offloaded into S3 bucket anyway.

S3 and Ccloudflare

Because I’m using S3 bucket as a storage for offloaded images, I don’t need a lot of space and transfer. But… if I will serve images directly from S3, it will not look nice from the url point of view. So I mixed S3 (as storage) and Cloudflare with custom sub-domain (as CDN – Content Delivery Network).

Read more No more VPS

Youtube movies as a podcast?

Yes, it’s possible!

Some time ago, my friends from the telegram group asked if we may have a solution which will make a podcast from youtube videos. You may ask why, but answer is really simple:

Podcast applications have a rich functionality for content delivery – automatic download of new episodes, remembering last played position, sync between devices and offline listening. This functionality is not available on YouTube. But still – how to do it?

Read more Youtube movies as a podcast?

Multiple vulnerabilities in QNAP TS-464 NAS devices

The advisories from ZDI-24-470 to ZDI-24-475 detail a series of vulnerabilities affecting QNAP TS-464 NAS devices, ranging from CRLF injection and SQL injection to improper certificate validation and file upload directory traversal. These vulnerabilities could allow remote attackers to make arbitrary configuration changes, execute code, escalate privileges, and create or delete files on affected devices. QNAP has issued updates to correct these vulnerabilities, highlighting the importance of applying security patches promptly to protect against potential exploits.

Read more Multiple vulnerabilities in QNAP TS-464 NAS devices

Multiple vulnerabilities in Cisco

Here’s a summary of the Cisco Security Advisories:

  1. Cisco AppDynamics Network Visibility Service DoS Vulnerability: An unauthenticated, local attacker could cause a denial of service (DoS) condition due to improper handling of unexpected input.
  2. Cisco Crosswork NSO Open Redirect Vulnerability: An unauthenticated, remote attacker could redirect a user to a malicious web page due to improper input validation of a parameter in an HTTP request.
  3. Cisco Crosswork NSO Privilege Escalation Vulnerability: An authenticated, local attacker could elevate privileges to root on an affected device because of a user-controlled search path used to locate executable files.
  4. Cisco Secure Client NAM Privilege Escalation Vulnerability: An unauthenticated attacker with physical access could elevate privileges to SYSTEM due to a lack of authentication on a specific function.
  5. Cisco Secure Email and Web Manager XSS Vulnerabilities: Multiple vulnerabilities could allow a remote attacker to conduct XSS attacks against users of the interface due to insufficient input validation.
  6. Cisco Secure Email Gateway HTTP Response Splitting Vulnerability: An unauthenticated, remote attacker could conduct an HTTP response splitting attack due to insufficient input validation of some parameters.
  7. Cisco Unified Communications Products API DoS Vulnerability: An unauthenticated, remote attacker could cause high CPU utilization and potentially impact access and call processing due to improper API authentication and incomplete validation of the API request.
Read more Multiple vulnerabilities in Cisco

Changes in atlassian university courses after Team24

During Team 24 Atlassian announced one, but big change in Atlassian University. Previously, on-demand courses cost $39. And now you can enroll in any of courses, or any of the learning paths containing those courses for free.

You can get started with courses that cover the basics — key concepts, core product features, and best practices — then validate your skills with a career-boosting credential. Or, you can take the guided route on one of learning paths, which are series of courses designed to help you achieve a particular goal.

What’s new

  • Free Learning Access: Atlassian University now offers 100% free on-demand courses to help individuals and teams at every stage of their journey, from getting started with a new product to preparing for an official certification.
  • Course Offerings: The courses cover key concepts, core features, best practices, and soft skills. Popular courses include managing Jira Service Projects, Asset Management Essentials, and Confluence Administration.
  • Learning Paths: Guided learning paths are available for specific goals like onboarding, delivering better outcomes at work, and advancing your career.
  • Certification Preparation: Free certification preparation learning paths are provided to help users earn Atlassian Certifications, validating their knowledge and skills.

If you don’t know that, Atlassian University is here:

https://university.atlassian.com/student/catalog?

D-Link – multiple vulnerabilities, some are 0-days

Here’s a summary of the vulnerabilities reported:

  • Remote Code Execution (RCE) Vulnerabilities:
    • D-Link D-View: Two vulnerabilities (ZDI-24-448, ZDI-24-450) allow remote code execution due to command injection and exposed dangerous methods. Both require authentication, which can be bypassed. CVSS rating: 8.8.
    • D-Link G416: Attackers can execute code on G416 routers without authentication (ZDI-24-446). CVSS rating: 8.8.
    • D-Link DIR-2150: The GetDeviceSettings feature in DIR-2150 routers is vulnerable to command injection by network-adjacent attackers without authentication (ZDI-24-442). CVSS rating: 8.8.
    • D-Link DIR-2640: A stack-based buffer overflow in DIR-2640-US routers allows RCE without authentication (ZDI-24-444). CVSS rating: 8.8.
    • D-Link D-View: Another vulnerability (ZDI-24-449) allows RCE through an exposed dangerous method with bypassable authentication. CVSS rating: 8.8.
  • Local Privilege Escalation:
    • D-Link Network Assistant: A vulnerability (ZDI-24-443) allows local attackers to escalate privileges by exploiting an uncontrolled search path element. Requires execution of low-privileged code. CVSS rating: 7.3.
  • Denial-of-Service (DoS):
    • D-Link DIR-3040: A memory leak in prog.cgi websSecurityHandler can be exploited by network-adjacent attackers to cause a DoS condition (ZDI-24-445). No authentication needed. CVSS rating: 4.3.
  • Authentication Bypass:
    • D-Link D-View: A vulnerability (ZDI-24-447) allows bypassing authentication using a hard-coded cryptographic key. No authentication needed for exploitation. CVSS rating: 9.8.

All vulnerabilities are marked as “0Day,” indicating they are previously unknown and unpatched. The CVSS ratings range from 4.3 to 9.8, reflecting the severity of the vulnerabilities. The higher the CVSS score, the more severe the vulnerability. It’s important for organizations using these D-Link products to be aware of these vulnerabilities and apply any available patches or mitigations provided by the vendor.

Read more D-Link – multiple vulnerabilities, some are 0-days

The Art of Mindful Living

In today’s fast-paced world, it’s easy to get lost in the chaos and forget about the importance of taking care of ourselves. Mindful living is about being fully present in the moment, paying attention to our thoughts and feelings without judgment, and cultivating a sense of inner peace and happiness. In this blog post, we will explore the art of mindful living and how it can improve our overall well-being.

Mindfulness

Mindfulness is the practice of bringing our full attention to the present moment. By focusing on our breath, bodily sensations, and surrounding environment, we become aware of our thoughts and feelings without getting caught up in them. Mindfulness allows us to observe our experiences with curiosity and non-judgment, helping us to develop a greater understanding of ourselves and the world around us. Through regular practice, we can become more mindful in our everyday activities, such as eating, walking, and interacting with others.

Mental health

One of the key benefits of mindful living is its positive impact on our mental health. Research has shown that mindfulness can reduce stress, anxiety, and depression, while increasing feelings of calmness and well-being. By being present in the moment, we are better able to manage our emotions and respond to difficult situations with clarity and composure. Mindful living also enhances our ability to focus and concentrate, improving our productivity and overall cognitive function.

In addition to its mental health benefits, mindful living can also have a profound effect on our physical well-being. When we practice mindfulness, we become more attuned to our body’s needs, allowing us to make healthier choices in terms of diet, exercise, and sleep. By listening to our body and giving it the care it deserves, we can improve our overall health and vitality. Mindful eating, for example, involves paying attention to the taste, texture, and aroma of our food, which not only enhances our enjoyment of the meal but also promotes healthier eating habits.

Self-care

In conclusion, mindful living is a powerful tool for self-care and personal growth. By incorporating mindfulness into our daily lives, we can cultivate a deep sense of inner peace, resilience, and happiness. Whether it’s through formal meditation practice or simply being more present in our daily activities, the art of mindful living can transform our lives in profound ways. So why not start today? Take a moment to pause, breathe, and embrace the beauty of this present moment.

Remember, self-care is not selfish, it’s essential for our well-being. Let’s prioritize our mental and physical health by embracing the art of mindful living. If you are a male, living in the UK, you may visit guys from Andy’s man club, or you can search similar organization in your neighberhood.

And remember – if you need urgent help and you are in UK, call Samaritans – 116 123. It’s a free number, and theye are there to help you.

Apple Siri and ChatGPT: Revolutionizing AI Chat Technology

  •  

The article on https://www.nytimes.com discusses the collaboration between Apple’s Siri and OpenAI’s ChatGPT to enhance the capabilities of the virtual assistant. I found it really intresting.

Advancements in AI Technology: A Look at Apple’s Siri and ChatGPT

In the ever-evolving landscape of artificial intelligence (AI) technology, companies like Apple are constantly pushing the boundaries of what is possible. One of the most recent advancements in AI technology is the integration of ChatGPT into Apple’s Siri virtual assistant. This collaboration has the potential to revolutionize the way we interact with AI systems and could pave the way for even more sophisticated AI applications in the future.

ChatGPT, developed by OpenAI, is a state-of-the-art language model that uses deep learning techniques to generate human-like responses to text inputs. By incorporating ChatGPT into Siri, Apple has significantly enhanced the virtual assistant’s ability to understand and respond to natural language queries. This means that Siri can now engage in more complex and nuanced conversations with users, making interactions with the virtual assistant feel more natural and intuitive.

One of the key advantages of integrating ChatGPT into Siri is its ability to generate contextually relevant responses. This means that Siri can now better understand the context of a conversation and provide more accurate and personalized answers to user queries. For example, if a user asks Siri for restaurant recommendations, the virtual assistant can now take into account the user’s location, preferences, and past interactions to offer more tailored suggestions.

Another significant benefit of this integration is the improved conversational capabilities of Siri. With ChatGPT, Siri can now engage in more fluid and coherent conversations with users, making interactions with the virtual assistant feel more like chatting with a real person. This enhanced conversational ability not only makes Siri more user-friendly but also opens up new possibilities for how AI systems can be used in various applications, such as customer service and virtual assistants.

Furthermore, the integration of ChatGPT into Siri has the potential to improve the overall user experience of Apple’s ecosystem. By making Siri more intelligent and responsive, Apple can enhance the functionality of its devices and services, making them more valuable to users. This could lead to increased user engagement and loyalty, as well as a competitive edge in the AI technology market.

Read more Apple Siri and ChatGPT: Revolutionizing AI Chat Technology