![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 | |
Confirmed User
Join Date: Feb 2005
Posts: 482
|
![]() Quote:
http://blog.ksplice.com/2010/09/cve-2010-3081/
__________________
I am NOT Godaddy! Most excellent Domains & Cheap Hosting “Buy an iPad, kill a Chinaman” - Brendan O’Neill |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Beer Money Baron
Industry Role:
Join Date: Jan 2001
Location: brujah / gmail
Posts: 22,157
|
It's a very sloppy update too, one of my servers anyway.... /tmp is noexec, and it failed to exec the configs for it as a result.
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 | |
Confirmed User
Join Date: Feb 2005
Posts: 482
|
![]() Quote:
![]()
__________________
I am NOT Godaddy! Most excellent Domains & Cheap Hosting “Buy an iPad, kill a Chinaman” - Brendan O’Neill |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Industry Role:
Join Date: Aug 2001
Posts: 832
|
thanks for sharing this
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 | |
It's 42
Industry Role:
Join Date: Jun 2010
Location: Global
Posts: 18,083
|
It doesn't even say what kernels are vulnerable ... |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Join Date: Feb 2005
Posts: 482
|
ALL 64-Bit kernels.
__________________
I am NOT Godaddy! Most excellent Domains & Cheap Hosting “Buy an iPad, kill a Chinaman” - Brendan O’Neill |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 | |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
why "ALL" 64-bit kernels... it states:
Quote:
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
Rofl. Do you realize how many of these are found each and every day? And how many stay hidden for years? Lol@sticky this
![]()
__________________
agentGFY *at* gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 | ||
Confirmed User
Join Date: Feb 2005
Posts: 482
|
Quote:
Quote:
https://www.ksplice.com/uptrack/cve-2010-3081
__________________
I am NOT Godaddy! Most excellent Domains & Cheap Hosting “Buy an iPad, kill a Chinaman” - Brendan O’Neill |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 | |
Confirmed User
Join Date: Feb 2005
Posts: 482
|
Quote:
LOL@youbeenhackedby this.
__________________
I am NOT Godaddy! Most excellent Domains & Cheap Hosting “Buy an iPad, kill a Chinaman” - Brendan O’Neill |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Join Date: Aug 2002
Posts: 1,844
|
i use yum to update my kernel but there's no updates showing on any of the repositories that i use yet.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 | |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Quote:
Although this doesn't suggest your system hasn't been compromised already, if exploited, a reboot will close the holes. Kind of like closing the stable door after the horse went for a piss, but still. to me looks like .18 kernels are fine?
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 | |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Quote:
Someone released a patch for my kernel - https://bugzilla.redhat.com/show_bug.cgi?id=634457#c20 when it gets approved, I'll load it on, whether the .18 kernel is vulnerable or not
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Confirmed User
Join Date: Feb 2005
Posts: 482
|
__________________
I am NOT Godaddy! Most excellent Domains & Cheap Hosting “Buy an iPad, kill a Chinaman” - Brendan O’Neill |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | ||
Confirmed User
Join Date: Feb 2005
Posts: 482
|
Quote:
Quote:
__________________
I am NOT Godaddy! Most excellent Domains & Cheap Hosting “Buy an iPad, kill a Chinaman” - Brendan O’Neill |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Confirmed User
Join Date: Jan 2004
Posts: 1,238
|
Doesn't look like it affects CentOS that much:
$ ./diagnose-2010-3081 Diagnostic tool for public CVE-2010-3081 exploit -- Ksplice, Inc. (see http://www.ksplice.com/uptrack/cve-2010-3081) $$$ Kernel release: 2.6.18-194.11.1.el5xen $$$ Backdoor in LSM (1/3): not available. $$$ Backdoor in timer_list_fops (2/3): not available. $$$ Backdoor in IDT (3/3): checking...not present. Your system is free from the backdoors that would be left in memory by the published exploit for CVE-2010-3081. $ cat /etc/redhat-release CentOS release 5.5 (Final)
__________________
Managed US/NL Hosting [ [Reality Check Network ] Dell XEON Servers + 1/2/3 TB Packages ICQ: 4-930-562 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Well this exploit can be resolved simply by adding ip restriction to ssh.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 | |
Confirmed User
Industry Role:
Join Date: Aug 2007
Posts: 6,697
|
https://access.redhat.com/kb/docs/DOC-40265
Note that they need to gain access to a local account before it is of any use to an attacker. Also: Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
Confirmed User
Join Date: Apr 2003
Posts: 121
|
I've seen today a server with Centos being hacked this way through an old install of oscommerce
as usual, the atacker uploaded a phpshell and downloaded the exploit to gain root, after that defaced all sites on server Server was running Centos 5 64bit with kernel 2.6.18-194.8.1 attacker overwrote every index* file, when atacker was discovered, tried to rm -rf * whole drive, luckily we caught it on time. Centos 5 IS vulnerable now |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 | |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Quote:
Code:
kernel x86_64 2.6.18-194.11.4.el5 updates 19 M kernel-devel x86_64 2.6.18-194.11.4.el5 updates 5.4 M http://lwn.net/Articles/406414/
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 | |
Confirmed User
Join Date: Aug 2002
Posts: 1,844
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Don't forget to reboot after kernel update....
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
Confirmed User
Join Date: Aug 2002
Posts: 1,844
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |