Koozali.org: home of the SME Server

Intrusion Detection Tools

Offline Jean-Philippe Pialasse

  • *
  • 2,761
  • +11/-0
  • aka Unnilennium
    • http://smeserver.pialasse.com
Re: Intrusion Detection Tools
« Reply #15 on: July 07, 2017, 12:14:25 AM »
Not a good idea...

http://www.openwall.com/lists/oss-security/2017/06/29/2

indeed,

I have added a warning on the contribs, and I just build a new version with update disabled as default.

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: Intrusion Detection Tools
« Reply #16 on: July 07, 2017, 12:28:53 AM »
systemd goodness ?

e.g. running services which say:

User=7up

with root privileges?

http://www.openwall.com/lists/oss-security/2017/07/06/17

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: Intrusion Detection Tools
« Reply #17 on: July 07, 2017, 12:29:33 AM »
I have added a warning on the contribs, and I just build a new version with update disabled as default.

Good plan!

Offline ReetP

  • *
  • 3,731
  • +5/-0
Re: Intrusion Detection Tools
« Reply #18 on: July 07, 2017, 08:45:29 AM »
e.g. running services which say:
User=7up
with root privileges?

Didn't want to mention that one ;-)

ROFLMAO

Never assume, and sanitise your inputs

Obligatory xkcd for Mr Poettering

https://www.xkcd.com/327/
...
1. Read the Manual
2. Read the Wiki
3. Don't ask for support on Unsupported versions of software
4. I have a job, wife, and kids and do this in my spare time. If you want something fixed, please help.

Bugs are easier than you think: http://wiki.contribs.org/Bugzilla_Help

If you love SME and don't want to lose it, join in: http://wiki.contribs.org/Koozali_Foundation

Offline brianr

  • *
  • 988
  • +2/-0
Brian j Read
(retired, for a second time, still got 2 installations though)
The instrument I am playing is my favourite Melodeon.
.........