Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Software flaw threatens Linux servers
C|Net ^ | November 28, 2001, 1:50 p.m. PT | Robert Lemos

Posted on 11/28/2001 1:28:10 PM PST by Don Joe

Software flaw threatens Linux servers
By Robert Lemos
Staff Writer, CNET News.com
November 28, 2001, 1:50 p.m. PT

A vulnerability in the most widely used FTP server program for Linux has left numerous sites open to online attackers, a situation worsened when Red Hat mistakenly released information on the flaw early, leaving other Linux companies scrambling to get a fix out.

"Other vendors didn't have a patch," said Alfred Huger, vice president of engineering for network security information provider SecurityFocus. The company has been working with vendors to fix the vulnerability after computer security company Core Security Technologies alerted them to the problem Nov. 14.

"The fix is not rocket science," Huger said. "But we weren't working at a breakneck pace to get a patch out, because everyone was working together."

The software flaw affects all versions of wu-FTP, a program originally created at Washington University at St. Louis for servers running FTP (file transfer protocol) functions for transferring files over the Internet.

While the exact number of active FTP servers on the Internet is not known, the software is the most commonly installed file server and accompanies most major Linux distributions, including those from Red Hat, SuSE, Caldera International, Turbolinux, Connectiva, Cobalt Networks, MandrakeSoft and Wirex.

The problem, known in security circles as the wu-FTP Globbing Heap Corruption Vulnerability, allows attackers to get remote access to all files on a server, provided they can access the FTP service. Since most such servers provide anonymous access to anyone on the Internet, a great number will be vulnerable.

Huger called the flaw "serious."

The impact of the software vulnerability was exacerbated because many Linux software companies were caught flat-footed by a surprise early release of information regarding the vulnerability.

While the group that discovered the flaw, Core ST, informed Linux software companies and the open-source group that manages development for wu-FTP of the flaw, Red Hat mistakenly released a security advisory to its customers on Tuesday.

Normally, an advisory is a good thing, but other Linux software sellers had expected any advisories to be published Dec. 3, giving them time to work on fixes. Instead, the surprise announcement left the customers of other companies' products vulnerable.

"We were releasing some advisories on the same day, and an overzealous administrator pushed this out as well," said Mark Cox, senior engineering director for Red Hat. The company is adding new safeguards to its publishing system to avoid similar problems in the future, he said.

"We put a stop to this," Cox said. "This will not happen again. It was a bad mistake."


TOPICS: Culture/Society; Front Page News; News/Current Events
KEYWORDS:
Navigation: use the links below to view more comments.
first previous 1-20 ... 41-6061-8081-100 ... 341-354 next last
To: oc-flyfish
I know it's one server...but I get hundreds of those a day.
61 posted on 11/28/2001 2:31:25 PM PST by B Knotts
[ Post Reply | Private Reply | To 58 | View Replies]

To: Bush2000
Hey, Knotts: "IIS isn't part of Windows. It's an add-on component." Sound familiar?

Don't forget Outlook.

The funny thing is that if the MS bashers got their way and had MS split up, they wouldn't be able to claim that the Windows OS had flaws.

62 posted on 11/28/2001 2:31:48 PM PST by danneskjold
[ Post Reply | Private Reply | To 59 | View Replies]

To: Don Joe
Well, with all the anti-MS rants about things found in IIS, and everyone saying to dump IIS because of them, perhaps everyone should dump Linux,now?
63 posted on 11/28/2001 2:32:21 PM PST by PatrioticAmerican
[ Post Reply | Private Reply | To 1 | View Replies]

To: oc-flyfish
Free hint: it's not an IIS log.
64 posted on 11/28/2001 2:32:44 PM PST by B Knotts
[ Post Reply | Private Reply | To 60 | View Replies]

To: danneskjold
Don't forget Outlook. The funny thing is that if the MS bashers got their way and had MS split up, they wouldn't be able to claim that the Windows OS had flaws.

Yep. I love to hear them twist and moan on their own petard.
65 posted on 11/28/2001 2:33:12 PM PST by Bush2000
[ Post Reply | Private Reply | To 62 | View Replies]

To: B Knotts
Yes and so do I. If you go through your logs you will find the hundreds of entries probably are coming from less than a dozen servers.

Nimda is a very nasty virus that sends out tons of attack attempts. That is why you see so many of them.

66 posted on 11/28/2001 2:33:24 PM PST by oc-flyfish
[ Post Reply | Private Reply | To 61 | View Replies]

To: PatrioticAmerican
Well, people should definitely dump wu-ftpd. I have no argument with that.
67 posted on 11/28/2001 2:33:33 PM PST by B Knotts
[ Post Reply | Private Reply | To 63 | View Replies]

To: B Knotts
I stand corrected.
68 posted on 11/28/2001 2:34:54 PM PST by oc-flyfish
[ Post Reply | Private Reply | To 64 | View Replies]

To: oc-flyfish
Yes, and these buffer overflows are the same reason why IIS gets hammered. Of course, then we hear "Microsoft makes crappy code".

That's exactly right. Buffer overflows are a problem on any platform that doesn't have some kind of hardware stack protection built in to the CPU. Neither Unix nor Windows is free from security problems, generally speaking.

69 posted on 11/28/2001 2:35:34 PM PST by Liberal Classic
[ Post Reply | Private Reply | To 56 | View Replies]

To: B Knotts
Well, people should definitely dump wu-ftpd. I have no argument with that.

I think the problem here is that many Windows users have gotten accustomed to seeing Linux sycophants slamming Windows for flaws in components such as IIS, Outlook, etc which aren't even technically part of the operating system. And then they have the gall to turn around and insist that bugs in components such as wu-FTP aren't part of Linux. I don't mind acceptiing that argument ... but fair is fair. You can't have it both ways and slam Windows for the same kinds of bugs.
70 posted on 11/28/2001 2:36:57 PM PST by Bush2000
[ Post Reply | Private Reply | To 67 | View Replies]

To: B Knotts
Well, people should definitely dump wu-ftpd. I have no argument with that.

No bashing on this but a serious question: If wu-ftpd is open source why wasn't the bug discovered earlier? Or is it a commericial product?

71 posted on 11/28/2001 2:37:06 PM PST by oc-flyfish
[ Post Reply | Private Reply | To 67 | View Replies]

To: Bush2000
Yep. I love to hear them twist and moan on their own petard.

Man, you sound bitter. What's your problem?

72 posted on 11/28/2001 2:37:51 PM PST by Liberal Classic
[ Post Reply | Private Reply | To 65 | View Replies]

To: Justa; MadIvan; Die Zaubertuba; dennisw; Terriergal; Dominic Harr; 2 Kool 2 Be 4-Gotten; kd5cts
What's the matter, people? Cat got your FTP server?
73 posted on 11/28/2001 2:38:11 PM PST by Bush2000
[ Post Reply | Private Reply | To 64 | View Replies]

To: Liberal Classic
Neither Unix nor Windows is free from security problems, generally speaking.

This has been my point all along. I am not a Windows zealot, but I truely detest the Unix/Linux/Solaris/etc crowd that believes that their OS is the best thing since sliced bread and NEVER has problems like Windows.

Glad we agree on this.

74 posted on 11/28/2001 2:40:00 PM PST by oc-flyfish
[ Post Reply | Private Reply | To 69 | View Replies]

To: oc-flyfish
Over three days:

sh-2.05a# grep root.exe access_log|awk {'print $1'}|uniq|wc -l
     40

40 different machines with root.exe alone.

75 posted on 11/28/2001 2:41:48 PM PST by B Knotts
[ Post Reply | Private Reply | To 66 | View Replies]

To: Bush2000
What's the matter, people? Cat got your FTP server?

Hey, you violated your own rule about not feeding the trolls! :-)

76 posted on 11/28/2001 2:41:58 PM PST by oc-flyfish
[ Post Reply | Private Reply | To 73 | View Replies]

To: oc-flyfish
Hey, you violated your own rule about not feeding the trolls! :-)

I think this one was too good to pass up.

77 posted on 11/28/2001 2:42:35 PM PST by danneskjold
[ Post Reply | Private Reply | To 76 | View Replies]

To: B Knotts
Oops. My mistake. That should be 33. Forgot to 'sort' first. Doh.

Still a lot.

78 posted on 11/28/2001 2:43:14 PM PST by B Knotts
[ Post Reply | Private Reply | To 75 | View Replies]

To: B Knotts
40 different machines with root.exe alone.

Which proves my point. Roughly 13 servers a day (ok, technically I said less than a dozen but pretty close).

79 posted on 11/28/2001 2:45:07 PM PST by oc-flyfish
[ Post Reply | Private Reply | To 75 | View Replies]

To: danneskjold; oc-flyfish
Hey, you violated your own rule about not feeding the trolls! :-)

Just sharin' the love, sharin' the love...
80 posted on 11/28/2001 2:45:43 PM PST by Bush2000
[ Post Reply | Private Reply | To 77 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-20 ... 41-6061-8081-100 ... 341-354 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson