sean finney on Thu, 3 Oct 2002 20:14:08 -0400


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] hacking attempt


On Thu, Oct 03, 2002 at 07:43:43PM -0400, Dan Roberts wrote:
> so what's the solution? just dont run NFS?

well, yeah.  or at the least, if if he really does need it, it shouldn't
be running on the external interface of something directly connected
to the internet.  buffer overflows aside, nfs is inherently insecure
in how it works (no or little authentication, let alone encryption).
he should have that stuff firewalled off if he really needs it on.

--sean

Attachment: pgp2Re2KPuFDq.pgp
Description: PGP signature