« My Data I Wanna | Main | Emulation »

27 August 2004

Fully Patched

With all that automated ssh scanning going on, someone thought to set up a honey pot to see what the scanners are up to. (Well, I guess he already knew what they were up to, but wanted to see the intruders in action.)

In his words, he "set up a debian woody fully patched with both accounts activated, and got rooted some days later..." Subsequently, he clarified that sshd was the only service running on said boxen.

A long discussion followed, with various opinions expressed and questions raised:

Some of the above points sounded silly or facetious when you read them in their original mailing list-followup form, but I think they are all good points when presented in a list like this. ;-)

The key concern is: If one runs a fully-patched box, is one still susceptible to local root exploits? How bad is the situation?

Before one worries about that, though, one ought to make sure "fully patched" really means fully patched, imho.


Posted by ngps at 10:17 | Comments (0) | Trackbacks (0)
Comments
There is no comment.
Trackbacks
Please send trackback to:http://sandbox.rulemaker.net/ngps/98/tbping
There is no trackback.