li

Re: Xen Security Advisory 464 v2 (CVE-2024-45819) - libxl leaks data to PVH guests via ACPI tables

Posted by Demi Marie Obenour on Nov 12

Is this unconditional (perhaps because the relevant data gets zeroed out
by the shim), or does it only apply when the PV guest can't extract data
from the shim's memory? For instance, 32-bit PV guests aren't security
supported anymore, but the PV shim isn't supposed to rely on the
security of the shim itself, only of the rest of the system.




li

CVE-2024-52533: Buffer overflow in socks proxy code in glib < 2.82.1

Posted by Alan Coopersmith on Nov 12

Another CVE was issued by Mitre yesterday for another bug listed on
https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home

https://gitlab.gnome.org/GNOME/glib/-/issues/3461 reports that:
"set_connect_msg() receives a buffer of size SOCKS4_CONN_MSG_LEN but it writes
up to SOCKS4_CONN_MSG_LEN + 1 bytes to it. This is because SOCKS4_CONN_MSG_LEN
doesn't account for the trailing nul character that set_connect_msg() appends...




li

Panasonic Manages Consumer Comfort, Controllability, and Costs

Panasonic Corp. of North America is honing in on its focus to make it easier for both residential and commercial building owners to control the temperature and comfort level within the space. The company hit its targets with the introduction of two new products — the ECONAVI air conditioner and the Variable Refrigerant Flow (VRF) Smart Connectivity Controller.




li

Commercial HVAC Customers Demand Smart RTUs, Manufacturers Deliver

It is 2018, and this is not your father’s rooftop equipment. The old, reliable system taking up space on the roof has become so much more.




li

Industry Responds as Companies Commit to Battling Climate Change

Corporate America is making pledges to take action against climate change, which is opening up opportunities for HVAC contractors.




li

Manufacturers Meet Demand for More Intelligent Building Controls

Smart products enable service providers to take a more proactive approach to addressing HVAC system and equipment issues, said Susie Gornick.




li

Honeywell Launches Autonomous Building Sustainability Solution To Fight Rising Global Energy Consumption

Honeywell announced the launch of Honeywell Forge Energy Optimization, a cloud-based, closed-loop, machine learning solution.




li

New Belimo Retrofit Program Designed to Boost Efficiency

RetroFIT+ is the next iteration of the Belimo retrofit program, which offers online resources, including a product-selection tool, as well as personal support to provide quick and easy access to HVAC replacement solutions for actuators, valves, and sensors.




li

DOE, Industry Finalize Standards for Commercial HVAC Products

After six meetings, the working group reached consensus and provided recommendations for energy conservation standards, test procedures, and metrics.




li

Portable HVAC Products Provide Specialized Solutions

Since they don’t have to stay in one place, portable cooling units have been known to show up in some pretty unique places. Here’s a closer look at how portable units are serving in some outside-the-box applications.




li

Enertech Global Sweeps the Light Commercial DDA Honors

A series of geothermal heat pumps from Enertech Global swept the HVAC Light Commercial Equipment category of the 2015 Dealer Design Awards, starting with the gold award winner, the TVS/TVT TETCO Commercial Series Geothermal Heat Pump.




li

Nortek Global HVAC Introduces 3-Phase Light Commercial Air Conditioner

Nortek Global HVAC has introduced a new three-phase electric/electric packaged cooling solution. The company said the Model P8SE delivers 14 SEER cooling in capacity ranges from 3 to 5 tons in even tonnages, making it an energy-efficient choice for strip malls, restaurants, and retail stores.




li

Residential Cooling Showcase 2016: Systems Designed to Keep Customers Cool

Every year, The NEWS introduces the latest cooling equipment available for the upcoming summer season in order to help contractors prepare for this busy period by doing the research that will help them to distinguish between brands. The coverage features specific information about each individual product as submitted by the manufacturers.




li

Commercial Cooling Showcase 2016: Summer Heat No Match for HVAC Cooling Equipment

The manufacturers provided all of the data included in the product grid as well as the photo feature. Therefore, any questions should be directed to them via the contact information provided in the photo feature section.




li

Serviceability, Flexibility Earn Aaon’s WH Series DDA Gold

Aaon’s focus on serviceability and performance helped the WH Series earn gold in The NEWS’ 2017 Dealer Design Awards HVAC Light Commercial Equipment category.




li

Extech, a division of Flir Systems Inc.: IAQ Meter

This handheld device displays CO, CO2, air temperature, rh, dew point, and wet bulb temperature measurements.




li

Extech, a division of Flir Systems Inc.: Digital Multimeter

Designed for HVAC and refrigeration professionals to view electrical and temperature readings, this product logs data remotely using the ExView® W-Series app on smartphones and tablets via Bluetooth.




li

Contractors Discuss How to Handle Tool Policies With Technicians

Summer cooling season is in full gear, which means that both technicians and their tools are being kept extremely busy.




li

Questions about IPS-Policy

Posted by Bestell_E-Mail via Snort-sigs on Oct 22

Hello.

First of all, please excuse me if this question is asked a lot.

I am a beginner and currently using the IPS Policy with the Business License.

I am not sure if Personal or Business License is right for me. Are the IPS policies different in any way for these two
licenses?

Best regards

Waldemar Sager_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org...




li

A Way to Listen to Every Interaction Your Tech has with a Customer

AI technology can help HVAC contractors monitor each sales and repair call.




li

A Case Study: Driving Energy Efficiency Through Utility Incentives

Is reducing a facility's energy consumption by over 130,000 kWh annually through HVAC optimization possible?




li

Q&A: Does Building Automation Make a Difference in Air Quality?

Today’s commercial structures are full of sophisticated controls that have been changing building automation systems exponentially.




li

Daikin Applied Introduces Building Controls

Daikin Applied’s recently introduced SiteLine Building Controls gives building owners and operators the tools and insights needed to optimize performance, improve IAQ, and trim energy use and carbon emissions.




li

Siemens Works Hard to Make Life Easier

Siemens is working to expand their offerings to fit any building size, with any amount of complexity.




li

Age, Technology Dictate Building Controls Lifespan

While a controls upgrade may be costly, the reality is, the longer you wait, the more expensive a replacement can be.




li

Easy Connections, Size Highlight Residential Controls Offerings

The ESP-400 by Jackson Systems LLC has earned gold in the Residential Controls category of The NEWS’ 2017 Dealer Design Awards.




li

Easy Installation, Use Highlight Residential Controls Offerings

Over a year of research and design went into the 2018 Dealer Design Awards gold-winning product in the Residential Controls category. After listening to feedback from both contractors and consumers for a more basic, easy-to-use, and cost-effective thermostat, Nest created the Nest Thermostat E.




li

Project Files: Episode 24 — The Lido House

The project team and property management realized they needed to maximize open space for use by hotel guests. They chose LG’s Multi V™ 5 and Multi V™ S VRF systems, noted for energy efficiency and flexibility in design and installation options.




li

ZoneFirst Introduces Thermostat-Light Switch Combo

For years, ZoneFirst President Dick Foster has used the light-switches-in-the-home comparison while promoting the benefits of zoning. At their AHR Expo booth, they introduced a product that brought new meaning to that comparison.




li

Future Proofing Your Building: Where HVAC and Sustainability Come Together

With cost reduction, sustainability enablement, increased comfort and performance benefits, VRF systems allow commercial buildings to gain a competitive advantage by reducing their carbon footprint and providing custom comfort to occupants.




li

Cold Climate Heat Pumps See ‘Nothing But Growth’

Only 4% of homeowners know modern heat pumps can heat down to -4°F. That’s a huge opportunity for HVAC contractors to step in and be the experts.




li

Heat Pumps and Refrigerant Changes driving Climate Change Efforts

This e-book includes a summary of sustainable HVAC developments, in particular of heat pumps and refrigerant changes to address climate change.




li

Residential Cooling Showcase 2024

In this showcase, The ACHR NEWS introduces the latest cooling equipment available for the upcoming summer season in order to help contractors distinguish between brands.




li

Sizing Heat Pumps For Colder Climates

Contractors must be careful when sizing heat pumps for colder climates in order to avoid mold problems and homeowner discomfort.




li

Air-to-Water Heat Pump Innovations Driving Efficiency, Safety, and Performance in Residential Heating and Cooling

To meet the ambitious environmental goals being proposed at all levels of government, residential air-to-water heat pumps are emerging as a transformative solution to lower carbon emissions, enhance energy efficiency, and reduce utility bills.




li

California Musician Pens Love Song to Heat Pumps

“(I’m Your) Heat Pump” is a soft, funky, R&B love song told from the perspective of a heat pump that depicts just what a heat pump can provide to its users.




li

California Heat Pump Partnership Aims to Scale Up Electrification of HVAC

This new private-public partnership wants to quadruple heat pump installation in California over the next 6 years.




li

Advances in Heat Pump Rooftop Units for Cold Climates

The DOE's new Rooftop Accelerator program encourages manufacturers to develop efficient commercial rooftop heat pumps for cold climates, which could reduce GHG emissions and energy costs by up to 50%.




li

Residential Heating Scene Shows Mix of Cold Climate Heat Pumps, Furnaces

Cold climate heat pumps were on full display on the AHR show floor and manufacturers were eager to share their progress reports in the Department of Energy’s CCHP Challenge.




li

Peterman Brothers Charity Showdown Supports Indianapolis-Area Community Organizations

Throughout March, voters will help the staff at Peterman Brothers select four charity partner organizations for 2023.




li

Mandating High-Efficiency Furnaces Will Limit Consumer Choice, Critics in HVAC Industry Say

Residential gas furnaces must all have a minimum AFUE of 95% beginning in five years. Some in the HVAC industry say the new Department of Energy rule will ultimately hurt homeowners.




li

How to make a minimal HTTPS request with ncat --ssl with explicit HTTP content?

Posted by Ciro Santilli OurBigBook via dev on Sep 17

Hello, I was trying for fun to make an HTTPS request with explicit hand-written HTTP content.

Something analogous to:

printf 'GET / HTTP/1.1 Host: example.com ' | ncat example.com 80

but for HTTPS. After Googling one of the tools that I found that seemed it might do the job was ncat from the nmap
project, so I tried:

printf 'GET / HTTP/1.1 Host: example.com ' | ncat --ssl example.com 443

an that works...




li

[PATCH 0/1] Improved the legibility of Makefile

Posted by Ariel Otilibili on Sep 17

Hello committers,

The same patch is on this PR: https://github.com/nmap/nmap/pull/2938

Have a good weekend,
Ariel

Ariel Otilibili (1):
Improved the legibility of `Makefile`

Makefile.in | 14 +++-----------
1 file changed, 3 insertions(+), 11 deletions(-)




li

[PATCH 1/1] Improved the legibility of `Makefile`

Posted by Ariel Otilibili on Sep 17

* source files obtained by a wildcard
* headers and objects generated by differences.

```
$ grep -P '(SRCS|HDRS|OBJS) =' Makefile.in |
sed -e 's/^export.*= //g; s/$.*//g; s/OBJS = //' |
sed -ne '2p' |
tr ' ' ' ' |
sed -e 's/.h//' |
sort -d |
grep -vP '^$' > headers

$ grep -P '(SRCS|HDRS|OBJS) =' Makefile.in |
sed -e...




li

"Exploitation Less Likely"

Posted by Dave Aitel via Dailydave on Aug 12

DefCon is a study in cacophony, and like many of you I'm still digging
through my backlog of new research in multifarious browser tabs, the way a
dragonfly keeps track of the world through scintillated compound lenses. In
between AIxCC (which proved, if anything, the boundaries
<https://dashboard.aicyberchallenge.com/collectivesolvehealth> of automated
bug finding using current LLM tech?), James Kettle's timing attack research...




li

Re: "Exploitation Less Likely"

Posted by Don A. Bailey via Dailydave on Aug 13





li

Re: "Exploitation Less Likely"

Posted by Dave Aitel via Dailydave on Aug 13

https://github.com/CloudCrowSec001/CVE-2024-38077-POC/blob/main/CVE-2024-38077.md
https://github.com/Wlibang/CVE-2024-38077/blob/main/One%20bug%20to%20Rule%20Them%20All%2C%20Exploiting%20a%20Preauth%20RCE%20vulnerability%20on%20Windows%20(2024_8_9%2010_59_06).html

But while you are at it, always good to watch a video for no reason:
https://www.youtube.com/watch?v=mVXrl4W1jOU

-dave




li

Hacking the Edges of Knowledge: LLMs, Vulnerabilities, and the Quest for Understanding

Posted by Dave Aitel via Dailydave on Nov 02

[image: image.png]

It's impossible not to notice that we live in an age of technological
wonders, stretching back to the primitive hominids who dared to ask "Why?"
but also continually accelerating and pulling everything apart while it
does, in the exact same manner as the Universe at large. It is why all the
hackers you know are invested so heavily in Deep Learning right now, as if
someone got on a megaphone at Chaos...




li

Episode 7: Error Handling

This week, Arno and Markus take a look at error handling at the architectural level. They discuss the different kinds of errors, the groups of people who need to know about them and proven high-level approaches. Later episodes will investigate more technical aspects of error handling, such as idioms for using exceptions or a discussion of checked vs. unchecked exceptions.