On Sun, 26 Apr 1998, Rama Kant wrote: > As far as the DOD's sites are concerned, there is a rumor that one of the > Solaris vulnerability was exploited. > Does anyone know of any details of the exploited Solaris vulnerability? Is it still a rumor? I read (forget where, perhaps here) that the bug was in statd. Does statd ever run without NFS? Were they really running NFS on an Internet-connected host? As if that wasn't bad enough I've seen large government contractors (3,000+ employees) with even worse firewall security. If the FBI is serious about "cyberterrorism" the first place they should start, IMHO, is with federal contractors. Roger Marquis Roble Systems Consulting http://www.roble.com/consulting
This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 12:56:51 PDT