Olympus-OM
[Top] [All Lists]

[OM] Linux security query, was: Nasty iOS and OS X security bug

Subject: [OM] Linux security query, was: Nasty iOS and OS X security bug
From: Chuck Norcutt <chucknorcutt@xxxxxxxxxxxxxxxx>
Date: Wed, 26 Feb 2014 11:56:12 -0500
There is a new Win7 laptop for my wife scheduled to arrive tomorrow. 
Her old Dell XP machine will be re-purposed as a Linux machine whose 
only (deliberate) exposure to the outside world will be the four 
websites where we conduct our financial business (2 banks and 2 
investment houses).

However, this machine will be on a LAN with two Win7 machines and a 
printer attached to one of the Win7 machines.

How is the Linux machine vulnerable across the LAN and how can I 
mitigate it?

Thanks,
Chuck Norcutt


On 2/26/2014 6:39 AM, SwissPace wrote:
> I believe OSX has now been patched 10.9.2 is available and I recommend
> updating asap.
>
> On a secondary note I inadvertenly left a door open and some "kid" from
> spain managed to access one of our linux servers - they are not immune
> and I recommend running clamav and rkhunter if you are running linux as
> a desktop. It seems nothing is immune. as for me after 2 weeks of
> forensics it seems no harm was done and its all cleaned up but it
> shocked me how easy it was to gain access and I have been busy beefing
> up defences.
>
>
>
> On 24/02/2014 14:44, Chuck Norcutt wrote:
>> This is a nasty one that has apparently been there for a long time on
>> both systems.  The iOS bug has been patched so be sure to get the update
>> but the OS X fix is yet to come.  Since the bug affects Safari the
>> suggestion is to use Chrome or Firefox until OS X is fixed.
>>
>> <http://krebsonsecurity.com/2014/02/ios-update-quashes-dangerous-ssl-bug/>
>>
>> For a deeper dive see:
>> <http://www.zdnet.com/apple-and-the-ssltls-bug-open-questions-7000026628/>
>>
>> If you're a programmer check this
>> <https://www.imperialviolet.org/2014/02/22/applebug.html>
>> It's amazing that this was not caught in code inspection during development.
>>
>> Chuck Norcutt
>
-- 
_________________________________________________________________
Options: http://lists.thomasclausen.net/mailman/listinfo/olympus
Archives: http://lists.thomasclausen.net/mailman/private/olympus/
Themed Olympus Photo Exhibition: http://www.tope.nl/

<Prev in Thread] Current Thread [Next in Thread>
Sponsored by Tako
Impressum | Datenschutz