[PLUG] A moment of silence please
Steve Beattie
steve at wirex.net
Thu Aug 14 14:18:01 UTC 2003
On Thu, Aug 14, 2003 at 01:15:16PM -0700, Russ Johnson wrote:
> * Steve Beattie <steve at wirex.net> [2003-08-14 12:31]:
> > Call me silly, but having an internet connected machine be woefully out
> > of date w.r.t. security updates is not something to brag about (yes,
> > there've been security vulnerabilities fixed in the 2.2 kernels since
> > 2.2.12 was released).
>
> Depending on the nature of the vulnerability, they may not apply.
At least one vulnerability allowed privilege escalation from a local
shell to root <http://icat.nist.gov/icat.cfm?cvename=CAN-2003-0127>.
Combine this vulnerability with a vulnerability in any of the network
services (for example, the apache/openssl vulnerability exploited by
the slapper worm), and you've got another DDoS zombie or worse. About
the only way they wouldn't have applied is if the machine had no users
and no visible network services (i.e. was a NAT firewall).
Just because a machine might not have local users does not mean local
root escalation vulnerabilities should be ignored.
It's hard enough to get users/admins to apply security
patches -- Eric Rescorla's study of the openssl vulnerability
<http://www.rtfm.com/upgrade.pdf> showed that 30 days *after* the slapper
worm was announced, roughly 35% of hosts he monitored still had not
patched openssl. Do we really need to encourage people to brag about
not applying security updates in the name of a big uptime?
--
Steve Beattie Don't trust programmers?
<steve at wirex.net> Complete StackGuard distro at
http://NxNW.org/~steve/ immunix.org
http://www.sardonix.org -- Audit code, earn respect.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
URL: <http://lists.pdxlinux.org/pipermail/plug/attachments/20030814/744d2f56/attachment.asc>
More information about the PLUG
mailing list