Saturday, January 4, 2014

How to Fix Ubuntu Update Errors

It happens quite often that we encounter errors while trying to run an update in Ubuntu. There are several type of errors and in this post we will see how to solve some of the most common errors encountered during update of packages in Ubuntu.

Sometimes running the updates in the Update Manger results in the following error:
Could not initialize the package information.
An unresolvable problem occurred while initializing the package information.
Please report this bug against the ‘update-manager’ package and include the following error message:
‘E:Encountered a section with no Package: header, E: Problem with MergeList /var/lib/apt/lists/archive.ubuntu.com_ubuntu_dists_natty_main_binary-amd64_Packages, E:The package lists or status file could not be parsed or opened.’
A similar error occurs while running the apt-get update command in terminal:
Reading package lists… Error!
E: Encountered a section with no Package: header
E: Problem with MergeList /var/lib/apt/lists/archive.ubuntu.com_ubuntu_dists_natty_main_binary-amd64_Packages
E: The package lists or status file could not be parsed or opened.
There is a one shot solution to the above errors. Open the terminal and run the following commands in the given order:
sudo rm -rf /var/lib/apt/lists/* 
sudo apt-get clean 
sudo apt-get update
Hope that solves the above mentioned problems. Now lets move on to another type of error.
A very common error while installing an application or updating a package is following:
E: Could not get lock /var/lib/dpkg/lock – open (11: Resource temporarily unavailable)
E: Unable to lock the administration directory (/var/lib/dpkg/), is another process using it?
The reason is quite obvious from the error itself “another process using it”. Which means another process is already using the mentioned directory (necessary for the application to be installed) through Synaptic Package Manager, Update Manger, terminal or Ubuntu Software Center.
The idea would be to look for another application which is being installed or update it. Wait for it to finish the installation or cancel it. If you cannot see the application then try running this command in the terminal to solve this error:
sudo rm /var/lib/apt/lists/lock
I faced a strange situation today when I ran the Update Manager in Ubuntu. It showed me a number of updates to be installed and when I clicked on Install Updates it showed me the following error:
The action would require the installation of packages from not authenticated sources
ubuntu-require-untrusted-packages
There could be several reason for this error:
  • Software is restricted by copyright or legal issues
  • The Software is from Canonical Partner and has not been added to Source List
  • The application has been installed form its source code
  • Missing public key of the application
If you do not know which is the root cause of error, then follow the instructions for each of them and then you can find it out. Lets see how to tackle these problem one by one:

(i) Software is restricted by copyright or legal issues

Run the Update Manager. And go to Settings as shown in the pic below:
ubuntu-update-manger-settings
Now here, go to the Ubuntu Software tab and make sure that Software is restricted by copyright or legal issues field is checked. Close the settings and install updates now.
ubuntu-synaptic-multiverse

(ii) The Software is from Canonical Partner and has not been added to Source List

In the Update Manager Settings, go to Ubuntu Software tab and include the Source Code for updates like in the pic below:
ubuntu-synaptic-canonical-settings

(iii) The application has been installed form its source code

In the Update Manger Settings, go to Ubuntu Software tab and check the Source Code option:
ubuntu-synaptic-source

(iv) Missing public key of the application

Open the terminal (Ctrl+Alt+T) and run the following command:
sudo apt-get update
Now wait till it finishes and see if you see something like this:
W: GPG error: http:/something.something Release: The following signatures couldn’t be verified because the public key is not available: NO_PUBKEY XXXXXXXXXXXXXXXX
Note down the numbers you see after NO_PUBKEY. This error is because the application’s public key has not been added. To solve the error use the following command in the terminal:
sudo apt-key adv --recv-key --keyserver keyserver.ubuntu.com XXXXXXXXXXXXXXXX
After adding the missing public key run the following command (again):
sudo apt-get update
I hope it helps solve your problem. Do provide us your feedback and if you are facing errors other than this do let us know. Comments section is all yours. Enjoy :)

The GRC program value proposition: Advice for compliance professionals

Many companies aren't itching to tackle governance, risk and compliance (GRC) initiatives, and it's largely due to perceptions around cost and ROI. Those holding the company purse strings often have difficulty seeing the value proposition of a GRC program from an expense perspective; others are thrown off by the intricacies associated with a full-on GRC strategy. Given these perceptions, it's often difficult to get beyond the "bad and the ugly" of these investments to recognize "the good" inherent in a GRC program -- and that hesitation is putting business assets and data at risk.
The compliance professionals we speak to on a regular basis agree that GRC must become integrated into daily business processes, rather than viewed as a separate burden. But how to convince others of the GRC value proposition? GRC is a topic that calls for expert tips and solutions, so SearchCompliance has scoured our sister sites to gather some of the top GRC stories you might have missed. These articles offer a mix of strategic and tactical advice for conveying the value of a GRC program and changing the perceptions of those not yet convinced that the GRC cause is worth the cash.

Why you can't ignore governance, risk and compliance

It's a simple question: What is GRC? Well, the answer is becoming increasingly complicated. Sometimes a reference to software and sometimes a methodology unto itself, GRC depends on context and perception. No matter how you look at it, a GRC program is a vital consideration in today's landscape of evolving rules and regulations that affect all levels of organization. The expert advice in this magazine article outlines how companies can assess and integrate a GRC program while rolling with the regulation punches.

GRC as a proactive investment, and how to get there

Risk management planning doesn't always receive the highest-level support from CIOs and IT departments. Rather, it's often seen as a costly burden instead of a proactive investment. Harvey Koeppel, a former CIO and a regular columnist for SearchCIO, advocates for the latter viewpoint, urging companies to look past the initial costs and evaluate what GRC preparedness has to offer in the long run. In a proper GRC maturity model, tactics and strategies should be identified and structured, then organized according to anticipated benefits, Koeppel says. By changing the way CIOs approach their GRC budget, compliance officers can better integrate risk management into the overall organization.

Equating information governance with business value

With so much to lose in a data-heavy world, how are companies continuing to make careless mistakes with private information? Many companies are approaching information governance with an "out of sight, out of mind" mindset, and that's just not going to cut it these days. By equating information governance to business value, then sifting through complexities and understanding the data you are charged with protecting, a more complete picture of your company's information appears. The tips in this case study on information governance strategy don't downplay the difficulties of governing your information, and make clear how your data could help you when the going gets tough.

Using a threat model to reframe the role of compliance

As ever-evolving regulations and laws drain IT budgets, the perceptions surrounding compliance can be draining as well. Conforming work habits to appease GRC to-do lists has left some risk-minded folks feeling disheartened, and that frustration is disrupting workflows. Re-architecting those compliance tasks to become part of business processes -- rather than added chores -- reframes the role of a GRC program. The seven-stage threat model discussed in this piece from Information Security magazine provides a detailed account on how to define, streamline and execute a new approach to compliance, and how it can change GRC attitudes for the better.

A $440 million reason to learn three IT risk lessons

"If it ain't broke, don't fix it" is a phrase that doesn't fare too well in the IT sphere, as history shows that risk can very quickly spiral into an all-out crisis that's both costly and time-consuming -- and money and time are two resources already stretched thin in most organizations. Plenty of companies have felt that pain after deciding that compliance is a separate entity to be put on the back burner. By embedding risk management into each business decision, GRC can become part of the organization and evolve as IT evolves. In this piece, Brian Barnier, a risk advisor at ISACA, outlines how IT departments can insert compliance into everyday decisions.

NSA Documents from the Spiegel Story

There are more source documents from the recent Spiegel story on the NSA than I realized. Here is what I think is the complete list:
Here are the news articles: Three English articles. Spy catalog interactive graphic. Two articles in German.
This is all really important information for those of us trying to defend against adversaries with these sorts of capabilities.

NSA Exploit of the Day: IRONCHEF

Today's item from the NSA's Tailored Access Operations (TAO) group implant catalog is IRONCHEF:
IRONCHEF (TS//SI//REL) IRONCHEF provides access persistence to target systems by exploiting the motherboard BIOS and utilizing System Management Mode (SMM) to communicate with a hardware implant that provides two-way RF communication.
(TS//SI//REL) This technique supports the HP Proliant 380DL G5 server, onto which a hardware implant has been installed that communicates over the I2C Interface (WAGONBED).
(TS//SI//REL) Through interdiction, IRONCHEF, a software CNE implant and the hardware implant are installed onto the system. If the software CNE implant is removed from the target machine, IRONCHEF is used to access the machine, determine the reason for removal of the software, and then reinstall the software from a listening post to the target system.
Status: Ready for Immediate Delivery
Unit Cost: $0
Page, with graphics, is here. General information about TAO
"CNE" stands for Computer Network Exfiltration. "Through interdiction" presumably means that the NSA has to physically intercept the computer while in transit to insert the hardware/software implant.
In the comments, feel free to discuss how the exploit works, how we might detect it, how it has probably been improved since the catalog entry in 2008, and so on.
The plan is to post one of these a day for the next couple of months.

Friday, January 3, 2014

NSA Exploit of the Day: DEITYBOUNCE

Today's item from the NSA's Tailored Access Operations (TAO) group implant catalog is DEITYBOUNCE:
DEITYBOUNCE (TS//SI//REL) DEITYBOUNCE provides software application persistence on Dell PowerEdge servers by exploiting the motherboard BIOS and utilizing System Management Mode (SMM) to gain periodic execution while the Operating System loads.
(TS//SI//REL) This technique supports multi-processor systems with RAID hardware and Microsoft Windows 2000, 2003, and XP. It currently targets Dell PowerEdge 1850/2850/1950/2950 RAID servers, using BIOS versions A02, A05, A06, 1.1.0, 1.2.0, or 1.3.7.
(TS//SI//REL) Through remote access or interdiction, ARKSTREAM is used to reflash the BIOS on a target machine to implant DEITYBOUNCE and its payload (the implant installer). Implantation via interdiction may be accomplished by nontechnical operator through use of a USB thumb drive. Once implanted, DEITYBOUNCE's frequency of execution (dropping the payload) is configurable and will occur when the target machine powers on.
Status: Released / Deployed. Ready for Immediate Delivery
Unit Cost: $0
Page, with graphics, is here. General information about TAO and the catalog is here.
In the comments, feel free to discuss how the exploit works, how we might detect it, how it has probably been improved since the catalog entry in 2008, and so on.
The plan is to post one of these a day for the next couple of months.

Thursday, January 2, 2014

GRC professionals' salaries increase as demand for their skills rises

In recent years, expanding regulatory compliance rules and seemingly endless IT security risks stemming from multiple data sources make an effective GRC program vital to the modern organization's success.
Risk strategies are different now when we don't have data in our own facility and we don't know who is dealing with it for us. Ram Karumuri
As a result, governance, risk management and compliance (GRC) professionals have seen their roles dramatically increase in importance in the past several years. Salaries are now starting to catch up with this increased onus on GRC, according to the TechTarget IT Salary Survey 2013. From a sample size of 242 respondents who specialize in GRC and IT security, 59% received a raise and 35% received a bonus in 2013. Fifty-seven percent of respondents expect a raise in 2014 as well.
As factors such as mobility and the cloud create new data security risks, GRC professionals should continue to expect their skill sets to be highly sought after, said Derek Gascon, executive director of the Compliance, Governance & Oversight Council.
"Their skills are going to be unique, at least for a while," Gascon said. "All of the data that is being distributed through those mechanisms has to be managed somehow, and the governance people understand what kinds of policies are going to be necessary."
The number of opportunities in the GRC field appears to be growing as well: Although the majority of respondents had been in the IT field for 11 to 20 years (44%) or 21 to 30 years (21%), 56% said they had only been in their current position for one year to five years.
For those in their position less than one year, 19% said they sought the new job for more money. This trend could very well continue as opportunities for those in the GRC field grow in the coming years, said Ram Karumuri, a senior manager of IT audits for a banking organization.
"The days of ignoring compliance and audits are gone," Karumuri said. "In our organization, we plan to dedicate a few more people to audits because the environment for it is increasing."
New and emerging risk factors, including those stemming from mobile technology and cloud use, will only intensify the spotlight on data-related GRC processes, Karumuri added.
"Previously, we had everything in our data center," he said. "Governance of this and risk strategies are different now when we don't have data in our own facility and we don't know who is dealing with it for us."

In recent years, expanding regulatory compliance rules and seemingly endless IT security risks stemming from multiple data sources make an effective GRC program vital to the modern organization's success.
As a result, governance, risk management and compliance (GRC) professionals have seen their roles dramatically increase in importance in the past several years. Salaries are now starting to catch up with this increased onus on GRC, according to the TechTarget IT Salary Survey 2013. From a sample size of 242 respondents who specialize in GRC and IT security, 59% received a raise and 35% received a bonus in 2013. Fifty-seven percent of respondents expect a raise in 2014 as well.
As factors such as mobility and the cloud create new data security risks, GRC professionals should continue to expect their skill sets to be highly sought after, said Derek Gascon, executive director of the Compliance, Governance & Oversight Council.
"Their skills are going to be unique, at least for a while," Gascon said. "All of the data that is being distributed through those mechanisms has to be managed somehow, and the governance people understand what kinds of policies are going to be necessary."
 

The number of opportunities in the GRC field appears to be growing as well: Although the majority of respondents had been in the IT field for 11 to 20 years (44%) or 21 to 30 years (21%), 56% said they had only been in their current position for one year to five years.
For those in their position less than one year, 19% said they sought the new job for more money. This trend could very well continue as opportunities for those in the GRC field grow in the coming years, said Ram Karumuri, a senior manager of IT audits for a banking organization.
"The days of ignoring compliance and audits are gone," Karumuri said. "In our organization, we plan to dedicate a few more people to audits because the environment for it is increasing."
New and emerging risk factors, including those stemming from mobile technology and cloud use, will only intensify the spotlight on data-related GRC processes, Karumuri added.
"Previously, we had everything in our data center," he said. "Governance of this and risk strategies are different now when we don't have data in our own facility and we don't know who is dealing with it for us."

 

"Military Style" Raid on California Power Station

I don't know what to think about this:
Around 1:00 AM on April 16, at least one individual (possibly two) entered two different manholes at the PG&E Metcalf power substation, southeast of San Jose, and cut fiber cables in the area around the substation. That knocked out some local 911 services, landline service to the substation, and cell phone service in the area, a senior U.S. intelligence official told Foreign Policy. The intruder(s) then fired more than 100 rounds from what two officials described as a high-powered rifle at several transformers in the facility. Ten transformers were damaged in one area of the facility, and three transformer banks -- or groups of transformers -- were hit in another, according to a PG&E spokesman.
The article worries that this might be a dry-run to some cyberwar-like attack, but that doesn't make sense. But it's just too complicated and weird to be a prank.
Anyone have any ideas?