This was the last reported exploit we've seen from the old
BIND 8 problem where the worm would use BIND combined with
Wu-FTP which is back in the news again with a theoretical
exploit problem.
If there were many ways to break into a Linux system, they'd
be exploited all the time.
Many Windows users feel they ONLY reason they are exploited is
because their Windows users, the largest number of OS users on
the Planet.
This is not true. Not by a long shot.
You can read this article and see where 3 seperate worms were
designed to infect RedHat boxes which had the Bind 8 problem
combined with Wu-Ftpd.
If there is a security flaw Linux will get exploited as much
as Windows does.
And because Bind 8 was replaced with Bind 9 and most people
choose ProFtpd or OpenFtpd or one of the others for FTP -
or even OpenSSH's scp , there is not security threat to Linux.
But everybody should know that they've found another "Theoreticle"
exploit in Wu-Ftp so if anybody out there is still running this
software you might want to either upgrade to the patched version
or leave Wu-Ftpd.
Now, "Theoreticle" means the exploit is proven but no virus or
worm currently exists on the internet today which would exploit
this problem with Wu-Ftpd. But one surely will.
What happens with Windows is they ignore the "Theoreticle" warnings
various security agencies give them and have decided to just
allow their user base to become infected with what ever is discovered
in these security firms.
--
Charlie
> http://news.cnet.com/news/0-1003-200-5506966.html?tag=rltdnws
>
> This was the last reported exploit we've seen from the old
> BIND 8 problem where the worm would use BIND combined with
> Wu-FTP which is back in the news again with a theoretical
> exploit problem.
>
> If there were many ways to break into a Linux system, they'd
> be exploited all the time.
>
> Many Windows users feel they ONLY reason they are exploited is
> because their Windows users, the largest number of OS users on
> the Planet.
>
> This is not true. Not by a long shot.
I'd agree, the crackers would love to break into some of the big linux
servers out there, they are the real prizes, not some home windows box.
It's just not possible at the moment.
I've been playing with iptables, with the result that every firewall tester
I can find displays 'stealth' on every port with every kind of test.
Took me a day of research and about three lines typed in the console. :)
www.Hackerwhacker.com just freezes when scanning, and can't complete.
Does anyone else find this 'problem' with hackerwhacker and linux?
I have no comment. HA.
I think all the Windows users should run the hackerwhacker test though.
--
Charlie
I have used them with Linux no problems. What distro are you running?
version?
--
John Pisini
http://cafecomputer.com/faqindex
Registered Linux User #100542
"No. Try not. Do. Or do not. There is no try." -- Yoda
hence the reason why:
Microsoft: ambulance at the bottom of the cliff mentality
*nix: RHA method; prevention is better than cure
Matthew Gardiner
I've been playing with SE Linux lately and I am very impressed. It takes Linux
security to a whole new level. If an OS doesn't have a means of handling buffer
overflows, I am no longer willing to pronounce it secure. I'm making another
more detailed post in a thread called "SE Linux" now. Take a look at it.
--
Tracy Reed http://www.ultraviolet.org
"Memory is like gasoline. You use it up when you are running. Of course you
get it all back when you reboot..." - Microsoft Helpdesk
I'm using Mandrake 8.1. Hackerwhacker works fine until I enable my
firewall, then it seems to not be able to work at all. 'Shields up'
(www.grc.com) can still scan with the firewall enabled, but just reports
'stealth'. I'm still very new at all this, but learning. Perhaps it's the
way I've configured iptables.
Yes and this keeps their "Silent" Partner Symantec just "ROLLING" in the Dough.
Wonder how much stock old Billy Boy owns in Symantec.
Id bet it is ALOT
Just my 2@
Jim
If your operating system MUST HAVE A VIRUS SCANNER then YOU MUST HAVE
A DIFFERENT OPERATING SYSTEM!!!
Especially if you want to use the internet!
And speaking of which, I heard a rumble about the next version of
Internet Exploder comming standard wtih the VB script runner turned
OFF. Also heard the same rumor about Outlook Mistake.
Anybody else have anything on this?
--
Charlie
Okay... so Microsoft should bundle a virus protection package with Windows?
In that case... your complaints will then change to:
"MICROSOFT HAS A MONOPOLY ON VIRUS SCANNERS" in all caps...
>
> Especially if you want to use the internet!
>
> And speaking of which, I heard a rumble about the next version of
> Internet Exploder comming standard wtih the VB script runner turned
> OFF. Also heard the same rumor about Outlook Mistake.
It's just that... a rumor...
Perhaps. But the argument still remains.
If the OS is any good at security then a VIRUS SCANNER is not necessary.
It is clearly insain to have an OS which permits damage to be done only
for some daemon VIRUS SCANNER to alert you some microseconds afterwards.
You might as well have the VIRUS SCANNER re-install the idiots OS for
them whilst your at it.
--
Charlie
> Okay... so Microsoft should bundle a virus protection package with Windows?
> In that case... your complaints will then change to:
>
> "MICROSOFT HAS A MONOPOLY ON VIRUS SCANNERS" in all caps...
Yep. 'Zaclty! Hehe, you must be a genius to have figured out Chucky's
brilliant thought patterns.
I just have to wonder why the fucking guy can't seem to understand
the strangeness of an OS which requires a VIRUS SCANNER...
It's like the authentication gig you find in XP.
Do users feel a NEED to have MS tell them what they can and can't
install on XP due to licenses???
Doesn't it amaze you everytime you hear a REPUBLICAN mouth off about
abortion issues yet fight gun control to the point they don't even
want a special safety trigger on handguns???
Yet at the same time - AUTHENTICATION - is quite legitimate in their
world. We can't have you installing unauthorized/unlicensed software
yet we don't mind if you shoot getto mom in the tummy and kill her baby.
For that matter, how about the one where we're telling the entire
middle east we are not allied with Israel.
Or how about the one where we told them we are fighting a war against
terrorism yet none of you arabs are welcome to American anymore, until
this thing is sorted out.
The Republican mind is simply fucked.
And XP is the epitomy of that religion.
--
Charlie
Yeah.