main site infected?

Discuss anything not covered by any of the other categories.
goldenboy
Posts: 924
Joined: Fri Sep 05, 2008 11:04 pm
Location: Kiel
Contact:

Re: main site infected?

Post by goldenboy »

It's true, Linux/Unix isn't immune. I see lots of exploits on the Gentoo/Ubuntu security trackers all the time. Those that become known are fixed pretty quickly; I guess those that are not known are the bigger problem though :-s

Safety is illusionary anyway.
revelator
Posts: 2621
Joined: Thu Jan 24, 2008 12:04 pm
Location: inside tha debugger

Re: main site infected?

Post by revelator »

Worse the bug is 25 years old Oo if servers got by with a security flaw like this for that many years, one can wonder if reporting it now was such a smart idea ?.
It means we are actually lucky that most script kiddies dont know the innards of the systems they are trying to attack, what a revolting thought :mrgreen:
Productivity is a state of mind.
scar3crow
InsideQC Staff
Posts: 1054
Joined: Tue Jan 18, 2005 8:54 pm
Location: Alabama

Re: main site infected?

Post by scar3crow »

The lamest bandaid temporary workaround stitched together with chickenwire and spit is now up.
...and all around me was the chaos of battle and the reek of running blood.... and for the first time in my life I knew true happiness.
revelator
Posts: 2621
Joined: Thu Jan 24, 2008 12:04 pm
Location: inside tha debugger

Re: main site infected?

Post by revelator »

thanks m8 :)
Productivity is a state of mind.
revelator
Posts: 2621
Joined: Thu Jan 24, 2008 12:04 pm
Location: inside tha debugger

Re: main site infected?

Post by revelator »

btw msys should be safe as long as you dont use things like apache that takes advantage of bash scripting capabilities (uh oh my old msys package has apache built in :S) another reason to dump it as there will probably newer be an update to its bash shell. Also it seems the maintainer of the old msys/mingw has gone mia. cygwin also has apache but atleast bash is allready updated there. If it fixes the flaw completely
is unknown atm. Msys2 also updated bash several times allready and my last upload (installer version) allready has it, users of my previous versions should do a pacman -Syu in the Msys2 shell to get the latest updates fast. Best thing for users of my old msys package would be to block bash from accessing the internet.
Productivity is a state of mind.
Post Reply