[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [cobalt-users] RE: Security Hardening Update RaQ4
- Subject: RE: [cobalt-users] RE: Security Hardening Update RaQ4
- From: aljuhani <aljuhani@xxxxxxxxx>
- Date: Tue Oct 29 05:38:01 2002
- List-id: Mailing list for users to share thoughts on Sun Cobalt products. <cobalt-users.list.cobalt.com>
Hello,
Cobalt SHP for RaQ4 has many probelms:
1. It creat a possiblity of Denial of Service attacks!!.
2. It fills your /var partion!!.
3. There is no un-install files!!.
Cobalt promised some updates/fix on Aug 2000 but nothing upto now. See the
cobalt announce message below:
http://list.cobalt.com/pipermail/cobalt-announce/2002-August/000125.html
The SHP-Manual (pdf) is still there on the sun-cobalt website:
http://www.sun.com/hardware/serverappliances/pdfs/manuals/manual.raq4-SHP.pdf
to read more check the link below:
http://www.nobaloney.net/wpCobaltRaqSHP.html
Al-Juhani
aljuhani@xxxxxxxxx
>===== Original Message From cobalt-users@xxxxxxxxxxxxxxx =====
>> > "Security Hardening patch for the Sun Cobalt RaQ 4 server appliance.
>> > Includes port scan detection and buffer overflow detection."
>> >
>> > <http://sunsolve.sun.com/patches/cobalt/raq4.eng.html>
>> >
>> > I haven't cracked it open yet to look at it and don't think Cobalt has
>> > announced it either. Any insight?
>> </snip>
>
>
>Can this still be downloaded or is included in another patch
>
>Thanks
>
>Mark Roebuck
>www.bikers-engine.com