Re: BIG INFORMIX I-SPY SECURITY HOLE
Posted in 2004
David Williams said: > > "Jonathan Leffler" <jleffler@earthlink.net> wrote in message > news:40D91278.3030401@earthlink.net... >> nobody wrote: >> > David Williams wrote: >> >> "nobody" <nobody@devnull.org> wrote: >> >>> Obnoxio The Clown wrote: >> >>>> David Williams said: >> >>>>> Install i-spy into /opt/ispy... >> >>> [SNIP] >> >>>>> Welcome to the sos zone..you've been hacked!! >> >>>> Presumably you have reported this to IBM and given them time >> >>>> to fix it? >> >> No. It would have been nice to have time to at least develop a >> workaround, which isn't actually all that hard. In fairness, David did >> copy me on the information when he posted it, as I asked him to, and I >> didn't formally ask him not to post it until we had a chance to do >> something about it. But it is common courtesy and normal practice in >> the more experienced parts of the security community to report the >> problem privately and wait for a response. > > True, but I found it in less than 10 minutes. I assumed anyone with > bad intentions would also be able to find it that fast. So if you are > vunerable and someone wanted to you've probably already been > hacked! Better to stop anyone else installing it! Big assumption. :-( -- Bye now, Obnoxio "C'est pas parce qu'on n'a rien ' dire qu'il faut fermer sa gueule" - Coluche "I'm trying to see things your way, but I can't get my head up my ass" - JCH "Ogni uomo mi guarda come se fossi una testa di cazzo" - Marco http://www.catb.org/~esr/faqs/smart-questions.html sending to informix-list