Intel ‘Re-imagines’ The Data Center With New Avoton Server Architecture, Software-Defined Services

Intel isn’t just pushing Avoton as as low-power solution that’ll compete with products from ARM and AMD, but as the linchpin of a system for software defined networking and software defined storage capability. In a typical network, a switch is programmed to send arriving traffic to a particular location. Both the control plane (where traffic goes) and the data plane (the hardware responsible for actually moving the bits) are implemented in hardware and duplicated in every switch.

via Intel ‘Re-imagines’ The Data Center With New Avoton Server Architecture, Software-Defined Services – HotHardware.

Software defined networking replaces this by using software to manage traffic (OpenFlow in the example diagram below) and monitoring it from a central controller. Intel is moving towards such a model and talking it up as an option because it moves control away from specialized hardware baked into expensive routers made by people that aren’t Intel, and towards centralized technology Intel can bake into the CPU itself.

Open Source IaaS Software offering a real alternative to commercial clouds

With commercial cloud systems, there is no investment in hardware required. This enables start-up businesses to easily test out a new business idea. Whilst commercial cloud services are popular, they charge for CPU usage by the hour, storage, and bandwidth consumed. In a large organization, where many users need to be served, it may be cheaper to purchase hardware to create a private cloud. This article showcases the finest open source projects that provide a key alternative for those who wish to avoid using a commercially provided cloud.

via Open Source IaaS Software offering a real alternative to commercial clouds – Linux Links – The Linux Portal Site.

How Facebook threatens HP, Cisco, and more with its “vanity free” servers

Facebook, Amazon, and Google are all very picky about their server hardware, and these tech giants mostly build it themselves from commodity components. Frank Frankovsky, VP of hardware design and supply chain operations at Facebook, was instrumental in launching the Open Compute Project because he saw the waste in big cloud players reinventing things they could share. Frankovsky felt that bringing the open-source approach Facebook has followed for software to the hardware side could save the company and others millions—both in direct hardware costs and in maintenance and power costs.

via How Facebook threatens HP, Cisco, and more with its “vanity free” servers | Ars Technica.

The OCP hardware designs are “open” at a higher level. This way anyone can use standards-based components to create the motherboards, the chassis, the rack-mountings, the racks, and the other components that make up servers.

The birth of MMOs: World of Warcraft’s debt to MUD

Before there were the current generations of MMOs there were MUDs – multi-user dungeons or ‘dimensions’. And before there were MUDs there was MUD: A multi-player, text-based game running off a mainframe at Essex University.

MUD (known as MUD1 since the release of its successor, MUD2) used an interface similar to that of single player text adventure games and transplanted it to a multi-player realm where players could live virtual lives, solving puzzles, collecting treasure and killing fantastic creatures (and/or each other). The game launched in 1978, developed by Essex students Roy Trubshaw and, later, Richard Bartle.

via The birth of MMOs: World of Warcraft’s debt to MUD – games – Software – Techworld.

How Twitter Rebuilt Google’s Secret Weapon

Borg is a way of efficiently parceling work across Google’s vast fleet of computer servers, and according to Wilkes, the system is so effective, it has probably saved Google the cost of building an extra data center. Yes, an entire data center. That may seem like something from another world — and in a way, it is — but the new-age hardware and software that Google builds to run its enormous online empire usually trickles down to the rest of the web. And Borg is no exception.

via Return of the Borg: How Twitter Rebuilt Google’s Secret Weapon | Wired Enterprise | Wired.com.

At Twitter, a small team of engineers has built a similar system using a software platform originally developed by researchers at the University of California at Berkeley. Known as Mesos, this software platform is open source — meaning it’s freely available to anyone — and it’s gradually spreading to other operations as well.

Department Of Labor Attack Points To Industry Weaknesses

“This is basically the same pattern that a lot of advanced malware is taking today,” says Srinivas Kumar, CTO of TaaSERA. By taking a multi-stage approach and going after server-side vulnerabilities at legitimate sites, the attackers can be assured that unsuspecting visitors to the site are more likely to trust links redirecting to malware-laden sites, he says.

via Department Of Labor Attack Points To Industry Weaknesses — Dark-Reading

Apparently the Department of Labor’s site was hosting links to malware.  Usually users get hacked by sites hosting compromised  advertisements.

Possible Exploit Vector for DarkLeech Compromises

The script attempted to exploit the Horde/IMP Plesk Webmail Exploit in vulnerable versions of the Plesk control panel. By injecting malicious PHP code in the username field, successful attackers are able to bypass authentication and upload files to the targeted server. These types of attacks could be one avenue used in the DarkLeech compromises. Although not as common as the Plesk remote access vulnerability (CVE-2012-1557) described in the report, it does appear that this vulnerability is being actively exploited. 

via Possible Exploit Vector for DarkLeech Compromises.

Creating a Centralized Syslog Server

For this article, I’ll be focusing on syslog-ng as this is more up to date, and if the reader wishes, can be ‘supported’ via the company that owns the syslog-ng software by going with their enterprise edition version at a later date.

via Creating a Centralized Syslog Server | Linux Journal.

This is a good tutorial to get going with syslog-ng.  Monitoring events being logged into syslog can provide ample warning when a server is about to die.