有意思的新闻
http://computer.online.sh.cn/computer/gb/content/2004-07/01/content_888740.htm
你能相信一个连自己老窝都罩不住的操作系统吗?你能相信一群连自己老窝都守不住的人研制的内核吗?
哦,咳,咳,咳,听说了么?那个去年搞得GNU FTP差点彻底玩完,自己的bk服务器被人家添进奇怪代码的操作系统内核,又蹦出来拯救世界了!
http://computer.online.sh.cn/computer/gb/content/2004-07/01/content_888740.htm
你能相信一个连自己老窝都罩不住的操作系统吗?你能相信一群连自己老窝都守不住的人研制的内核吗?
哦,咳,咳,咳,听说了么?那个去年搞得GNU FTP差点彻底玩完,自己的bk服务器被人家添进奇怪代码的操作系统内核,又蹦出来拯救世界了!
Apparantly there is some sort of DDoS attack against www.FreeBSDChina.org. What was that? Some internal information told me that it was an intended test against www.freebsdchina.org. We have found some defects in the original website design and that should be corrected soon.
I have plugged a workaround to defeat the DDoS attack, now the load average fall from 70 to 0.65.
While I believe that proactive security practice is necessary for every consumers, the most conversave ones should argue that even a security update will possibly break compablity.
Now I am in trouble. With rsync 2.5.5 installed on a FreeBSD system, we know that it is possible to overflow its heap, however, shall we patch it, or just let it as-is because it is not exploitable on FreeBSD, unlike Linux’s silly brk(9) implementation?
Finally, yes, itojun has imported pf(4) into NetBSD. Having pf(4) in base indicates that NetBSD’s recognition of pf(4) related work, and as security officer of NetBSD, itojun-san’s import have some special meanings.
I have watched spurious SYN messages and apparantly this has affected beastie.frontfree.net’s networking subsystem, namely, its mail system. The attack is from 203.81.27.11.
Whois indicates 203.81.27.11 is:
I have added some SYNFLOOD proof packet filter rules for beastie.frontfree.net. Interestingly, the filter options seems to “forge” beastie.frontfree.net to be an OpenBSD box.
Let’s review what I have did years ago. I say, nothing can claim itself secure! Nothing, nothing, nothing!!
Not sure how did the corporation has designed the firewall system, it is simply - bogous and useless, and is fragile by design. All the design’s function is to keep the network out of being functional, not to make it a bit safer.
FreeBSD and OpenBSD’s inetd are based on a same codebase. However, they have different features and OpenBSD have some features that FreeBSD is lacking at present. For example, per-interface binding, etc.
刚刚想睡觉的时候收到了commit mail:
| |