Subject: "FYI Solaris Telnet Vulnerability" Previous topic | Next topic
Printer-friendly copy Email this topic to a friend CF Website
Top Non-CF Discussion "What Does RL Stand For?" Topic #1003
Show all folders

TacMon 12-Feb-07 11:59 AM
Member since 15th Nov 2005
2050 posts
Click to send email to this author Click to send private message to this author Click to view this author's profile Click to add this author to your buddy list
#1003, "FYI Solaris Telnet Vulnerability"


          

I don't know if it applies to the box CF is on, but here is where I first heard... http://it.slashdot.org/it/07/02/12/1118248.shtml which is of course slashdot. I'm sure you can find more info in the linked article.

  

Alert | IP Printer Friendly copy | Reply | Reply with quote | Top

EskelianMon 12-Feb-07 01:07 PM
Member since 04th Mar 2003
2023 posts
Click to send email to this author Click to send private message to this author Click to view this author's profile Click to add this author to your buddy list
#1004, "RE: FYI Solaris Telnet Vulnerability"
In response to Reply #0


          

Telnet is a stand alone application similar to SSH. Its not quite the same thing as what CF uses, AFAIK.

  

Alert | IP Printer Friendly copy | Reply | Reply with quote | Top

    
IsildurMon 12-Feb-07 01:35 PM
Member since 04th Mar 2003
5969 posts
Click to send email to this author Click to send private message to this author Click to view this author's profile Click to add this author to your buddy list
#1005, "RE: FYI Solaris Telnet Vulnerability"
In response to Reply #1


          

Telnet is a protocol, which CF's server implements (to some degree). Like you said, it's not the same as the telnet daemon that comes with Solaris, which is what this bug relates to. However, if that isn't fixed on the machine on which CF runs, then someone could theoretically gain root access and wreak havoc with CF's files. It's really an issue for CF's hosting company, not the staff per se.

  

Alert | IP Printer Friendly copy | Reply | Reply with quote | Top

        
TacMon 12-Feb-07 01:42 PM
Member since 15th Nov 2005
2050 posts
Click to send email to this author Click to send private message to this author Click to view this author's profile Click to add this author to your buddy list
#1006, "IIRC"
In response to Reply #2


          

CF owns it's own box, which was originally purchased by Jullias. It's possible that only CF accepts telnet connections, and as such avoids this, but I thought I'd send a heads up either way. I'm sure that IMPS/IMMS connect through ssh or something similar, but telnet is at least marginally open to the internet (via CF) and it might be something to double check. *shrug*

  

Alert | IP Printer Friendly copy | Reply | Reply with quote | Top

        
EskelianMon 12-Feb-07 11:48 PM
Member since 04th Mar 2003
2023 posts
Click to send email to this author Click to send private message to this author Click to view this author's profile Click to add this author to your buddy list
#1007, "RE: FYI Solaris Telnet Vulnerability"
In response to Reply #2


          

The duality in meaning is annoying yes.

Telnet is a protocol in general.
Its also shorthand for both telnet clients and telnet server applications. IE, Telnet service on windows = telnet. Telnet client that connects to CF? Telnet. Protocol they both use? Telnet. Its like they just got tired of naming things.

Point being though that telnet protocol in general, in reference to using it for remote shells, doesn't do any encryption. So I doubt the CF imms are using it for remote admin.

  

Alert | IP Printer Friendly copy | Reply | Reply with quote | Top

Top Non-CF Discussion "What Does RL Stand For?" Topic #1003 Previous topic | Next topic