Re: security reviewed at all?
Hunter Matthews <[email protected]>
| Newsgroups | gmane.network.up2date.current.devel |
|---|---|
| Message-ID | <[email protected]> |
And if you have specific areas that can be fixed, naturally John and I would do our best to do so. Patches are even more welcome. On Wed, 2002-07-10 at 08:05, John Berninger wrote: > In a word, no. We have not done any security testing at all; I'm fairly > confident that there are multiple, even trivial ways, to exploit or DOS > a Current server, especially a 1.0 series server. We haven't tried to > purposely create security holes, but we've been more focused on "get > this thing working" than on "fix the security holes". > > I'd ber /very/ careful of how widely available you make this server; but > I will admit to curiosity about how well it performs and how many users > start hitting it... > > On Wed, 10 Jul 2002, Ingo T. Storm wrote: > > > Hi, > > > > I intend to set up a current server open to the internet. Has anyone > > ever bothered about possible attacks against a current server, be it > > DOS or possible compromises? > > > > Thanks, > > Ingo > > > > _______________________________________________ > > Current-server mailing list > > [email protected] > > http://lists.dulug.duke.edu/mailman/listinfo/current-server > > -- > Thank you, > John Berninger > > Systems Administrator [email protected] > Department of Mathematics Box 8205, Harrelson Hall > NC State University Raleigh, NC 27695 > Phone: (919)515-6315 Fax: (919)515-3798 > > GPG Key ID: A8C1D45C > Fingerprint: B1BB 90CB 5314 3113 CF22 66AE 822D 42A8 A8C1 D45C > > "Non illegitimi carborundum." > -- > _______________________________________________ > Current-server mailing list > [email protected] > http://lists.dulug.duke.edu/mailman/listinfo/current-server > > -- Hunter Matthews Unix / Network Administrator Office: BioScience 145/244 Duke Univ. Biology Department Key: F0F88438 / FFB5 34C0 B350 99A4 BB02 9779 A5DB 8B09 F0F8 8438 Never take candy from strangers. Especially on the internet.