Re: 99.9 % of Software/Hardware Firewalls DO-NOT.....

From: Rob J Meijer (rmeijer@xs3.xs4all.nl)
Date: 01/03/02


From: rmeijer@xs3.xs4all.nl (Rob J Meijer)
Date: 3 Jan 2002 17:33:08 GMT

Lars M. Hansen <badnews@hansenonline.net> writes:

>On Tue, 01 Jan 2002 21:54:56 -0600, Patrick Farrell spoketh

>>So how is it that anyone is able to run any dns servers. Surely your not
>>suggesting that all of the servers out there are MS boxes or mac :) Yes there
>>have been vunerabilities, but these have been patched. There have been
>>vulnerabilities in telnet, ssh, (IIS anyone? :), etc.
>>
>>I'm just curious if your aware of something regarding up to date patched DNS
>>boxes that I'm not.
>>

>"These have been patched" ... That's assuming alot, isn't it? The patch
>for Code Red and Nimda has been out for over 6 months, but everybody
>hasn't patched their servers yet...

True, and next to that you can be sure that most software has some more
exploitable bugs not yet public. For this reason 'all' servers should
run in multiple layers of host based containment (Unpriviladged user,
chrooted enviroment, user based and/or application based firewalling etc)
and network based containment.

This is not just a bind issue, this goes for all servers.

Rob



Relevant Pages

  • Re: huge email system
    ... > 3 NFS servers with RAID and SCSI ... We bought a NetApp for the mail store; it is currently our one single ... FC-attach it to a pair of FreeBSD boxes which serve it out ... inexpensive balancer; I'd be interested in hearing ideas. ...
    (freebsd-isp)
  • Re: [fw-wiz] Security Audit and Priorities
    ... > Get yourself on the list of the people notified when new boxes are ... > built and old ones are retired. ... collect logs from its UNIX servers, routers, or firewalls. ... (I say that if this attitude persists they should get ...
    (Firewall-Wizards)
  • 2.6.20.4: NETDEV WATCHDOG and lockups
    ... we have serious problems with 2 of our servers: both shiny new amd64 dual core, with both 2GB RAM, 32bit kernel+userland. ... Both boxes are running fine but after "a while" they lock up and eventually restart all of a sudden. ... we went to 2.6.18-4-k7 and the problem persistent. ...
    (Linux-Kernel)
  • Re: Noise question
    ... I have a chance to pick up 7 v20z servers I was going to use as PDC/BDC's and Citrix Metaframe XPE boxes on Windows. ... And beware of that rack's Plexiglas frontend, it can be cause of overheating and even more noisy servers. ...
    (comp.sys.sun.hardware)
  • Re: T2000 performance Vs V240
    ... "CoolThreads" servers for a spin yet? ... web servers. ... T2000 boxes look very tempting, ... - The V240 is still being sold (and it will keep being sold for some time. ...
    (comp.unix.solaris)

Quantcast