Re: security reviewed at all?

John Berninger <[email protected]>
Newsgroups gmane.network.up2date.current.devel
Message-ID <[email protected]>
In a word, no.  We have not done any security testing at all; I'm fairly
confident that there are multiple, even trivial ways, to exploit or DOS
a Current server, especially a 1.0 series server.  We haven't tried to
purposely create security holes, but we've been more focused on "get
this thing working" than on "fix the security holes".

I'd ber /very/ careful of how widely available you make this server; but
I will admit to curiosity about how well it performs and how many users
start hitting it...

On Wed, 10 Jul 2002, Ingo T. Storm wrote:

> Hi,
> 
> I intend to set up a current server open to the internet. Has anyone
> ever bothered about possible attacks against a current server, be it
> DOS or possible compromises?
> 
> Thanks,
> Ingo
> 
> _______________________________________________
> Current-server mailing list
> [email protected]
> http://lists.dulug.duke.edu/mailman/listinfo/current-server

-- 
Thank you,
John Berninger

Systems Administrator		[email protected]
Department of Mathematics	Box 8205, Harrelson Hall
NC State University		Raleigh, NC 27695
Phone:  (919)515-6315		Fax:	(919)515-3798

GPG Key ID: A8C1D45C
        Fingerprint: B1BB 90CB 5314 3113 CF22  66AE 822D 42A8 A8C1 D45C

"Non illegitimi carborundum."
--
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.