Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Too Many Hacks
Hal Flynn, 2003-10-15

The open-source community should abandon its piecemeal approach to securing Linux-- and soon.

Comments Mode:
A series of misconceptions 2003-10-16
Anonymous (1 replies)
First of all, there's a certain level of ignorance about the inetd problem demonstrated in this article. inetd does, indeed have a configurable setting that disables a service if it spawns too many times in a short period of time. The reason is simple -- it's better to disable a service than have the whole box brought to its knees by the load. inetd was *never* intended for running critical services, and the startup overhead of launching a new process for each connection alone clues most people in that busy services should be run on their own, not through inetd.

Secondly, if someone has high enough privilages to patch your kernel, they *already* own your system. All that ability does is make it easier for them to cover their tracks. Even if they couldn't alter the kernel, they would already have the ability to do essentially anything they want with the system. I do not see this particular issue as important enough to make a fundamental change like moving over to a Trusted Computing-style platform where "unofficial" binaries are completely locked out. One of the key features of "Trusted Computing" is that only approved, digitally-signed binaries are allowed to run on the system. This seems fundamentally at odds with what open-source computing is all about. What good is having the source code if a binary you compile yourself won't be allowed to run?


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/191/23177#23177
You've added more misconceptions 2003-10-16
Anonymous (2 replies)
You've added more misconceptions 2003-10-17
Anonymous
You've added more misconceptions 2003-10-17
Anonymous
Looking like donkey's 2003-10-16
Anonymous (3 replies)
Looking like donkey's 2003-10-16
Anonymous (1 replies)
Looking like donkey's 2003-10-20
Anonymous (2 replies)
Looking like donkey's 2003-10-22
Darwin
Looking like donkey's 2003-10-25
Another Hobbit
Looking like donkey's or a horse's 2003-10-16
Axe-2-Grind
Looking like donkey's 2003-10-27
Anonymous
Too Many Hacks 2003-10-16
Anonymous (3 replies)
Thanks Anonymous 2003-10-16
Axe-2-Grind
misinformation 2003-10-16
Kelly Martin
Too Many Hacks 2003-10-21
Anonymous
New Editorial Direction for SF? 2003-10-16
Al Franken (1 replies)
New Editorial Direction for SF? 2003-10-16
Anonymous (3 replies)
Shatter 2003-10-17
Anonymous (1 replies)
Shatter 2003-10-17
Anonymous (1 replies)
Shatter 2003-10-20
Anonymous
New Editorial Direction for SF? 2003-10-18
Anonymous (1 replies)
New Editorial Direction for SF? 2003-10-20
Anonymous
New Editorial Direction for SF? 2003-10-20
Anonymous (1 replies)
New Editorial Direction for SF? 2003-10-20
Anonymous
Evolution, a necessary evil 2003-10-16
Axe-2-Grind (1 replies)
Evolution, a necessary evil 2003-10-17
Faust (1 replies)
Evolution, a necessary evil 2003-10-21
Anonymous (1 replies)
Evolution, a necessary evil 2003-10-24
tycho
Too Many Hacks 2003-10-17
Deven Phillips, CISSP
Too Many Hacks 2003-10-17
Alberto Guglielmo
Too Many Hacks 2003-10-17
fli-flop
Too Many Hacks 2003-10-17
A nonny mouse (1 replies)
Too Many Hacks 2003-10-17
Faust
Too Many Hacks 2003-10-17
David
Too Many Hacks 2003-10-18
Anonymous Coward
Too Many Hacks 2003-10-18
Charles Forbin
R u sure u r not a donkey yourself? 2003-10-20
Anonymous (2 replies)
R u sure u r not a donkey yourself? 2003-10-20
Anonymous (1 replies)
R u sure u r not a donkey yourself? 2003-10-20
Anonymous (2 replies)
R u sure u r not a donkey yourself? 2003-10-20
Anonymous (1 replies)
R u sure u r not a donkey yourself? 2003-10-20
Anonymous Coward (1 replies)
R u sure u r not a donkey yourself? 2003-10-27
penfold@dlofnep.com
man inetd.conf 2003-10-21
Anonymous
Too Many Hacks 2003-10-21
Anonymous
Wil-E-Coyote bridge design 2003-10-21
DWilliams (1 replies)
Wil-E-Coyote bridge design 2003-10-22
D McQuay (1 replies)
Wil-E-Coyote bridge design 2003-10-24
tycho
Too Many Hacks 2003-10-24
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus