Likes Likes:  0
Resultaten 1 tot 9 van de 9
Geen
  1. #1
    Veel Linuxdistributies zijn vatbaar voor kwetsbaarheid in glibc (Ghost)
    geregistreerd gebruiker
    812 Berichten
    Ingeschreven
    08/04/08

    Locatie
    Weert

    Post Thanks / Like
    Mentioned
    13 Post(s)
    Tagged
    0 Thread(s)
    11 Berichten zijn liked


    Bedrijf: Openworx
    URL: www.openworx.nl
    Registrar SIDN: nee
    KvK nummer: 14129365
    Ondernemingsnummer: nvt

    Thread Starter

    Veel Linuxdistributies zijn vatbaar voor kwetsbaarheid in glibc (Ghost)

    Veel bekende Linuxdistributies zijn vatbaar voor een bug in de GNU C Library die een buffer overflow kan veroorzaken. Kwaadwillenden kunnen zowel lokaal als op afstand de kwetsbaarheid misbruiken, zo waarschuwen beveiligingsonderzoekers van Qualys.
    ..
    Qualys beweert dat de impact van de bug enorm is. Veel bestaande Linuxdistributies zijn namelijk kwetsbaar. Het gaat onder meer om Debian 7, Red Hat Enterprise Linux 6 en 7, CentOS 6 en 7 en Ubuntu 12.04.
    ...

    http://tweakers.net/nieuws/101055/ve...-in-glibc.html

  2. #2
    Veel Linuxdistributies zijn vatbaar voor kwetsbaarheid in glibc (Ghost)
    administrator
    21.459 Berichten
    Ingeschreven
    17/12/01

    Locatie
    Amsterdam

    Post Thanks / Like
    Mentioned
    71 Post(s)
    Tagged
    0 Thread(s)
    590 Berichten zijn liked


    Naam: Domenico Consoli
    Bedrijf: Webhostingtalk.nl
    Functie: Oprichter
    URL: webhostingtalk.nl
    Registrar SIDN: Ja
    KvK nummer: 51327317
    TrustCloud: domenico
    View domenicoconsoli's profile on LinkedIn

    We kunnen inderdaad weer aan de slag. Hier nog wat uitgebreidere info dan op Tweakers:
    http://ma.ttias.be/critical-glibc-up...tbyname-calls/

  3. #3
    Veel Linuxdistributies zijn vatbaar voor kwetsbaarheid in glibc (Ghost)
    administrator
    21.459 Berichten
    Ingeschreven
    17/12/01

    Locatie
    Amsterdam

    Post Thanks / Like
    Mentioned
    71 Post(s)
    Tagged
    0 Thread(s)
    590 Berichten zijn liked


    Naam: Domenico Consoli
    Bedrijf: Webhostingtalk.nl
    Functie: Oprichter
    URL: webhostingtalk.nl
    Registrar SIDN: Ja
    KvK nummer: 51327317
    TrustCloud: domenico
    View domenicoconsoli's profile on LinkedIn

    Dit zegt Exim:
    Today CVE-2015-0235 was released, concerning a memory mismanagement
    vulnerability in glibc's "gethostbyname" functions. This software is
    the most common provider of "libc" on GNU/Linux systems, outside of the
    embedded space. If you're running Exim on GNU/Linux and don't know
    otherwise, assume that you are using glibc to provide much of the base
    operating system functionality and that you are affected by this
    problem. The latest versions of glibc are not affected, but for clarity
    you should check with your OS vendor.

    The exploit announcement is up at:
    http://www.openwall.com/lists/oss-security/2015/01/27/9
    and we'd like to thank Qualys for being exceptionally responsible and
    trying to provide us with advance notification that Exim would be
    discussed as an exploit vector; unfortunately, the details leaked, they
    had to move more quickly than they had planned and we've been left
    playing catch-up; we're sorry that this announcement from the Exim
    Maintainers is so tardy.

    Because glibc is a library, flaws are exposed in applications which use
    those functions, so many different programs are affected. Exim was
    chosen by the researchers as one widespread possible attack vector, and
    they have been able to use this to be able to perform a "remote code
    execution" attack against Exim, under certain circumstances.

    The best fix is to install security fixes for glibc from your vendor,
    and then restart any network services such as Exim.

    If you can not sufficiently expedite such changes, then for this one
    specific attack vector as outlined in the security advisory, you can
    turn off use of the broken library functions by Exim's HELO/EHLO
    handling; this does not protect you from other uses of those functions
    by Exim, nor does it protect other products. Details below.

    The impact of an exploit is to be able to run arbitrary machine code as
    the Exim run-time user: the user which handles incoming SMTP
    connections. This is typically a user called "exim" (or "_exim" or
    "mailnull" or something else chosen by your OS vendor). For a number of
    releases now, Exim's code has explicitly blocked ill-advised attempts to
    build it with "root" as the run-time user, to limit the consequences of
    flaws such as this latest one. Taking over your machine entirely would
    require a privilege escalation attack from the Exim run-time user to
    root, but attackers just getting a foothold is likely to be sufficiently
    painful for you.

    To protect Exim against the HELO/EHLO attack vector, do *not* set either
    of these in the main configuration:

    helo_verify_hosts
    helo_try_verify_hosts

    and do *not* use the following in any ACLs:

    verify = helo

    We believe, based on rather hurried analysis, that every other
    configuration option in Exim which might use "gethostbyname()" will use
    a newer set of functions if available, and not explicitly disabled by
    your OS packagers when building Exim.

  4. #4
    Veel Linuxdistributies zijn vatbaar voor kwetsbaarheid in glibc (Ghost)
    Internet Services
    3.204 Berichten
    Ingeschreven
    27/03/06

    Locatie
    Utrecht

    Post Thanks / Like
    Mentioned
    14 Post(s)
    Tagged
    0 Thread(s)
    43 Berichten zijn liked


    Naam: Jeroen
    View nl.linkedin.com/in/jeroenvheugten's profile on LinkedIn

    Hier met collega's al meer dan een uur bezig alles up te daten en diensten opnieuw te starten.

  5. #5
    Veel Linuxdistributies zijn vatbaar voor kwetsbaarheid in glibc (Ghost)
    administrator
    21.459 Berichten
    Ingeschreven
    17/12/01

    Locatie
    Amsterdam

    Post Thanks / Like
    Mentioned
    71 Post(s)
    Tagged
    0 Thread(s)
    590 Berichten zijn liked


    Naam: Domenico Consoli
    Bedrijf: Webhostingtalk.nl
    Functie: Oprichter
    URL: webhostingtalk.nl
    Registrar SIDN: Ja
    KvK nummer: 51327317
    TrustCloud: domenico
    View domenicoconsoli's profile on LinkedIn

    Succes Jeroen!

  6. #6
    Veel Linuxdistributies zijn vatbaar voor kwetsbaarheid in glibc (Ghost)
    geregistreerd gebruiker
    104 Berichten
    Ingeschreven
    06/01/09

    Locatie
    Hoorn

    Post Thanks / Like
    Mentioned
    2 Post(s)
    Tagged
    0 Thread(s)
    6 Berichten zijn liked


    Naam: Daan
    Registrar SIDN: Nee
    KvK nummer: nvt
    Ondernemingsnummer: nvt

    Doen jullie altijd een reboot na de update? Of enkel de betrokken services opnieuw opstarten?

  7. #7
    Veel Linuxdistributies zijn vatbaar voor kwetsbaarheid in glibc (Ghost)
    geregistreerd gebruiker
    1.075 Berichten
    Ingeschreven
    15/07/03

    Locatie
    Haarlem

    Post Thanks / Like
    Mentioned
    4 Post(s)
    Tagged
    0 Thread(s)
    21 Berichten zijn liked


    Naam: Pim
    Bedrijf: RealHosting
    Functie: Ondernemer
    Registrar SIDN: ja
    KvK nummer: 39093099
    Ondernemingsnummer: nvt

    De services hebben wij in ieder geval al herstart, maar om zeker te zijn aankomende nacht toch een reboot.
    Denk ook aan de virtualisatie software bijvoorbeeld. Die heeft ook updates en herstart je niet zo makkelijk.

  8. #8
    Veel Linuxdistributies zijn vatbaar voor kwetsbaarheid in glibc (Ghost)
    geregistreerd gebruiker
    518 Berichten
    Ingeschreven
    16/09/05

    Locatie
    Terneuzen

    Post Thanks / Like
    Mentioned
    13 Post(s)
    Tagged
    0 Thread(s)
    12 Berichten zijn liked


    Naam: Frank Buijze
    Bedrijf: FraJa WeB
    Functie: Eigenaar
    URL: www.frajaweb.nl
    Registrar SIDN: ja
    ISPConnect: Lid
    KvK nummer: 58893962
    Ondernemingsnummer: nvt

    Gelukkig hebben we puppet gedeployed op onze servers. Neemt veel werk uithanden in dit soort gevallen.

  9. #9
    Veel Linuxdistributies zijn vatbaar voor kwetsbaarheid in glibc (Ghost)
    Server Freak
    3.640 Berichten
    Ingeschreven
    19/05/06

    Locatie
    Assen

    Post Thanks / Like
    Mentioned
    16 Post(s)
    Tagged
    0 Thread(s)
    215 Berichten zijn liked


    Naam: Sinterklaas

    Centraal alles geupdate en gereboot, konden we meteen een failover test doen
    90% van alle systemen waren binnen een uur na uitbrengen patches geupdate, gecheckt en gereboot.
    Voor een paar oude Debian bakken moesten we de fix handmatig verwerken.

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics