Path: csiph.com!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail From: Arno Welzel Newsgroups: comp.lang.php Subject: Re: scylldb and php? anyone building a site with them on archlinux? Date: Sun, 10 Nov 2019 10:59:39 +0100 Lines: 55 Message-ID: References: <4e081378-85fa-4ff5-88a5-b6580c9330b1@googlegroups.com> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-Trace: individual.net TD5g8AeCCRa3yo5oSQAEDwZFvGbybX7jH7qyUBQBuspiV0HNaS Cancel-Lock: sha1:EDqYOYx3va806MBeodqE6cANX1E= In-Reply-To: Xref: csiph.com comp.lang.php:18111 J.O. Aho: > On 09/11/2019 23.58, Arno Welzel wrote: [...] >> Sure - but what vulnerability of systemd could be exploited remotely so >> it is problem for webservers? I don't remember any. > > Here is a example of remote code execution vulnerability that systemd > had a couple of years ago: > > https://www.openwall.com/lists/oss-security/2017/06/27/8 > > Sure it's not a simple attack, but if you have managed to get hold of a > machine in the network, some arp poisoning and you are able to start > execute code on machines which not up to date. > > > You also have this one from last year: > > https://meterpreter.org/cve-2018-15688-systemd-remote-code-execution/ > > Also you would need taken control of a machine in the network. Thanks for the references. Indeed, this looks not good - but as you said: it's not a simple attack as the first vulnerability can only be exploited by having a server to communicate with a malicious nameserver of the attacker. Usually public servers just don't to that and even desktop machines of end users often just use the nameserver of the ISP or the router. The second one is more critical but as I understand it also not relevant for public servers. > If you compare with any other init system, they never have had this kind > of security vulnerabilities, as they do not handle other things than > initialize the system and those do not have the capability of sending > receiving data from an external source. Sure. > The only thing I can compare systemd when it comes to potential future > vulnerabilities is the worst of microsoft windows xp vulnerabilities, > where someone could become a super-administrator (there been this kind > of vulnerabilities in later versions of microsoft windows, but far less > and there are some built in measures to try to prevent these which > completely lacks in systemd). Even Microsoft learned their lessons and I dont't see why systemd should get worse than it is. -- Arno Welzel https://arnowelzel.de