Re: Information disclosure with SMC webserver on Solaris 9
From: Jon Hart (warchild_at_spoofed.org)
Date: 10/23/03
- Previous message: Pavel Urban: "rpc broadcasts"
- Maybe in reply to: Jon Hart: "Information disclosure with SMC webserver on Solaris 9"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 23 Oct 2003 08:43:55 -0400 To: focus-sun@securityfocus.com
On Wed, Oct 22, 2003 at 09:38:24AM -0500, Wheeler, Randy wrote:
> Jon
>
> I have had the same problems with SMC and have determined that Sun does not
> put many resources into the SMC software(from the grapevine)
That is unfortunate, especially because, from what I've seen, SMC ships
on by default. Sure, it might depend on what type of install you do,
but if some large percentage of Solaris machines out there are running
some buggy piece of software that gets little or no attention from its
owners, thats a Bad Thing.
> If you have a Plantinum/Gold etc contract with Sun and SMC is under
> support at your company.I would escalate this with the district manager..
> This usually gets results..
>
> Remember though that if it is not under software support with Sun they
> are
> not obligated to support.
No contract here. This is an unfortunate trend I've been seeing. Just
because I don't have a contract or support option on a given product
doesn't mean I should be ignored or jerked around when it comes to
security matters. If a user does the responsible thing and contacts the
vendor before making a security issue public, then I would like to think
that the vendor would have the common courtesy to acknowledge this and
act appropriately.
At the same time I understand how things can fall through the cracks or
not get escalated properly. In the case of Sun, however, since
security-alerts@sun.com is apparently the place to send security related
discoveries, perhaps they should take a look at why this fell through.
-jon
- Previous message: Pavel Urban: "rpc broadcasts"
- Maybe in reply to: Jon Hart: "Information disclosure with SMC webserver on Solaris 9"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|