TIP: Click on subject to list as thread! ANSI
echo: linuxhelp
to: Geo.
from: Tony Williams
date: 2002-11-30 15:07:14
subject: Re: Most Unsecure OS? Yep, It`s Linux

From: Tony Williams 

Geo. wrote:
> "Tony Williams"  wrote in message
> news:3de9007f$1{at}w3.nls.net...
>
>
>>>are the same people who widely scrutinized the original module that has
>
> the
>
>>>"security exploit" going to be doing the scrutinizing
of the fix?
>>>
>>
>>I would think so, as well as others who know their track record...
>
>
> What motivation do they have to do a good job, does their livelyhood depend
> upon the reputation of this code?

Thier pride does, and that can be a more powerful motivator. To some extent
their livelihood can depend on it; not all open source coders do it in
their spare time.

> I can go on and on with this but the net result is that from my pov,
> security wise there is little difference between open and closed source
> programs. As proof, check the CERT top ten list and determine which of the
> top 7 are open/closed source.

I started out agreeing that the number of exploits is more or less the
same. My point is that the fixes to open-source apps are made available to
the end users more quickly.

--
Tony

> http://www.sans.org/topten.htm
>
> 1. BIND
> 2. Vulnerable CGI programs and application extensions (e.g., ColdFusion)
> installed on web servers.
> 3. Remote Procedure Call (RPC) weaknesses in rpc.ttdbserverd (ToolTalk),
> rpc.cmsd (Calendar Manager), and rpc.statd that allow immediate root
> compromise
> 4. RDS security hole in the Microsoft Internet Information Server (IIS)
> 5. Sendmail and MIME buffer overflows as well as pipe attacks that allow
> immediate root compromise.
> 6. sadmind and mountd
> 7. Global file sharing and inappropriate information sharing via NetBIOS and
> Windows NT ports 135->139 (445 in Windows2000), or UNIX NFS exports on port
> 2049, or Macintosh Web sharing or AppleShare/IP on ports 80, 427, and 548.
>
> seems open/closed source makes no difference to me..
>
> Geo.
>
>

--- BBBS/NT v4.01 Flag-4
* Origin: Barktopia BBS Site http://HarborWebs.com:8081 (1:379/1.45)
SEEN-BY: 3/2 10 106/1 120/544 123/500 379/1 633/260 267 270 285 774/0 605
SEEN-BY: 2432/200 7105/1
@PATH: 379/1 106/1 123/500 774/605 633/260 285 267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.