• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Linux Kernel Exploit Wreaking Havoc

HardOCP News

[H] News
Joined
Dec 31, 1969
Messages
0
This isn’t good at all. If you are a Linux user, I recommend you read this as soon as possible. Thanks to everyone that sent this one in.

This vulnerability was introduced into the Linux kernel in April 2008, and so essentially every distribution is affected, including RHEL, CentOS, Debian, Ubuntu, Parallels Virtuozzo Containers, OpenVZ, CloudLinux, and SuSE, among others. A few vendors have released kernels that fix the vulnerability if you reboot, but other vendors, including Red Hat, are still working on releasing an updated kernel.
 
Anyone care to post "FFFFFFUUUUUUUU" pics?

I don't keep up with Linux a whole lot but is this the largest security issue thus far?
 
Anyone care to post "FFFFFFUUUUUUUU" pics?

I don't keep up with Linux a whole lot but is this the largest security issue thus far?

naw they have had kernel exploits like this in the past too. They just cover it up as fast as possible and pretend it never happened.
 
This has been tremendously overblown by ksplice in the interest of furthering the sales of their product. It's a local exploit, which means the attacker has to already be logged in to your box. It's not a remote exploit.

Oh, and by the way, after looking for the source code for their "detection tool", there is no way in hell I'm running it. It's copy+paste of the original exploit code, and there are some things in it that are very very difficult to verify the safety of (like embedded machine code)
 
How many Linux users here run a multi-user system where the users you allow are not someone you already know?
 
How many Linux users here run a multi-user system where the users you allow are not someone you already know?

I have the same question. We leave the horde to f#$k up windows not even come close to our linux machines. We MIGHT have 4 users on our "router"
 
I don't think you understand my question. It requires local access to a box already. How many people give unknown people shells on their box?

Anyone who pays for webhosting services? I have a webhost account that has SSH Shell Access.
 
It's not a remote vulnerability, but a privilege escalation. It's not the first one and they have never been "hidden".

Some people are not even affected — most people running with the grsec patchset, 32 bit kernels, and 64 bit kernels without 32 bit compatibility enabled.
 
I don't think you understand my question. It requires local access to a box already. How many people give unknown people shells on their box?

Sorry, I thought I did, but you are right. I'm thinking stuff like free web hosts where anyone can get an account (and exploit the server therefore), but for companies you're correct.
 
Anyone who pays for webhosting services? I have a webhost account that has SSH Shell Access.

That's exactly what I was thinking, but I was implying big companies, none of which would be that easily exploited (unless that's just what they do :p).
 
Sorry, I thought I did, but you are right. I'm thinking stuff like free web hosts where anyone can get an account (and exploit the server therefore), but for companies you're correct.

I was gonna say the same... you are correct that with free/pay web hosts that give you a shell, you are probably right.

Totally forgot about that since I pretty much host my own stuff.

When people want hosting from me, I generally give them a vm...(and there aren't many of those).
 
I have the same question. We leave the horde to f#$k up windows not even come close to our linux machines. We MIGHT have 4 users on our "router"

So...what you are saying is Linux achieves security by making the OS such a pain to use that there will never be more than 4 people using it? That I can believe. :D
 
That's exactly what I was thinking, but I was implying big companies, none of which would be that easily exploited (unless that's just what they do :p).

It'd be nice if one of our local linux guys would comment on this. I'm no linux guy, but my web host uses it, and all users have shell accounts.

So could a bad guy get an account, elevate then pwn the entire service?
 
It'd be nice if one of our local linux guys would comment on this. I'm no linux guy, but my web host uses it, and all users have shell accounts.

So could a bad guy get an account, elevate then pwn the entire service?

I've done a fair bit of Linux stuff, and my biggest problem ATM is I don't know the details of this exploit. However, if it is what I think it is, then yes, that exact scenario is the fear. Please correct me if I'm wrong!
 
When i try to run the compiled binairy i get this message: bash: ./diag: Permission denied

Is that normal?
 
So...what you are saying is Linux achieves security by making the OS such a pain to use that there will never be more than 4 people using it? That I can believe. :D

The "easier" something is to use, the "easier" it is to get into it.
 
The "easier" something is to use, the "easier" it is to get into it.
This is why my computer is secured by Eighty-Feet-Deep Concrete Bunker™ 2011 Beta. It takes three hours to open all the blast doors and can only be opened at undisclosed times of day.
 
Back
Top