Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [OT] Re: [tlug] Sorry to Hijack a thread but whats wrong with LILO
- Date: Wed, 26 Feb 2003 09:37:12 -0500
- From: Josh Glover <jmglov@example.com>
- Subject: Re: [OT] Re: [tlug] Sorry to Hijack a thread but whats wrong with LILO
- References: <20030225044543.GA8866@example.com> <E18ncST-000193-00@example.com> <20030225111641.GE4192@example.com> <20030225140054.GC8351@example.com> <20030225231349.463804af.mike@example.com> <20030225141905.GD8351@example.com> <20030225142714.GQ1495@example.com>
- User-agent: Mutt/1.4i
Quoth Martin Baehr (Tue 2003-02-25 03:27:14PM +0100): > > was it this list or another where the argument was made that there are > hardly any exploitable kernelbugs out there. Not this list, I think. > if there is a security problem, it's always userland. I disagree. Case in point: newer kernels in the 2.4.x series (at least, the ones packaged by Gentoo and Red Hat--I cannot comment on the vanilla tree) allow you to add zlib support *to the kernel*! Needless to say (so why am I saying it?), I avoid such stupidity. I also avoid things like Tux. If you run a webserver in kernel mode, expect buffer overflows, chunking exploits, etc to bite you in the arse, and hard. Anyway, getting back to zlib, anyone who reads BugTraq knows that zlib has had a bad six months or so. If you have that code in your kernel, voila: you have a kernel vuln. In a perfect world, Martin, you *should* be right. In BSD, for example, kernel bugs are less frequent, due to the BSD developers being able to resist the stupid urge to drop the kitchen sink in the bloody kernel. In the Linux world, you are flat wrong. -- Josh Glover <jmglov@example.com> Associate Systems Administrator INCOGEN, Inc. http://www.incogen.com/ GPG keyID 0x62386967 (7479 1A7A 46E6 041D 67AE 2546 A867 DBB1 6238 6967) gpg --keyserver pgp.mit.edu --recv-keys 62386967Attachment: pgp00108.pgp
Description: PGP signature
- Follow-Ups:
- Re: [OT] Re: [tlug] Sorry to Hijack a thread but whats wrong with LILO
- From: Martin Baehr
- Re: [OT] Re: [tlug] Sorry to Hijack a thread but whats wrong with LILO
- From: Matt Doughty
- Re: [OT] Re: [tlug] Sorry to Hijack a thread but whats wrong with LILO
- From: Martin Baehr
- [tlug] Re: [OT] Re: Sorry to Hijack a thread but whats wrong with LILO
- From: Tobias Diedrich
- References:
- Re: [tlug] Sorry to Hijack a thread but whats wrong with LILO
- From: Martin Baehr
- Re: [tlug] Sorry to Hijack a thread but whats wrong with LILO
- From: Jonathan Byrne
- Re: [tlug] Sorry to Hijack a thread but whats wrong with LILO
- From: Scott Robbins
- Re: [tlug] Sorry to Hijack a thread but whats wrong with LILO
- From: Josh Glover
- [OT] Re: [tlug] Sorry to Hijack a thread but whats wrong with LILO
- From: Mike Gauthier
- Re: [OT] Re: [tlug] Sorry to Hijack a thread but whats wrong with LILO
- From: Josh Glover
- Re: [OT] Re: [tlug] Sorry to Hijack a thread but whats wrong with LILO
- From: Martin Baehr
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] Sorry to Hijack a thread but whats wrong with LILO
- Next by Date: Re: [OT] Re: [tlug] Sorry to Hijack a thread but whats wrong with LILO
- Previous by thread: Re: [OT] Re: [tlug] Sorry to Hijack a thread but whats wrong with LILO
- Next by thread: Re: [OT] Re: [tlug] Sorry to Hijack a thread but whats wrong with LILO
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links