Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #18083 > unrolled thread
| Started by | Azathoth Hastur <azathothhaster@gmail.com> |
|---|---|
| First post | 2019-11-04 20:04 -0800 |
| Last post | 2022-07-08 06:45 -0700 |
| Articles | 20 on this page of 22 — 4 participants |
Back to article view | Back to comp.lang.php
scylldb and php? anyone building a site with them on archlinux? Azathoth Hastur <azathothhaster@gmail.com> - 2019-11-04 20:04 -0800
Re: scylldb and php? anyone building a site with them on archlinux? "J.O. Aho" <user@example.net> - 2019-11-05 07:03 +0100
Re: scylldb and php? anyone building a site with them on archlinux? Azathoth Hastur <azathothhaster@gmail.com> - 2019-11-04 22:14 -0800
Re: scylldb and php? anyone building a site with them on archlinux? "J.O. Aho" <user@example.net> - 2019-11-05 18:34 +0100
Re: scylldb and php? anyone building a site with them on archlinux? Azathoth Hastur <azathothhaster@gmail.com> - 2019-11-06 12:22 -0800
Re: scylldb and php? anyone building a site with them on archlinux? "J.O. Aho" <user@example.net> - 2019-11-07 06:57 +0100
Re: scylldb and php? anyone building a site with them on archlinux? Azathoth Hastur <azathothhaster@gmail.com> - 2019-11-07 05:35 -0800
Re: scylldb and php? anyone building a site with them on archlinux? "J.O. Aho" <user@example.net> - 2019-11-07 21:49 +0100
Re: scylldb and php? anyone building a site with them on archlinux? Azathoth Hastur <azathothhaster@gmail.com> - 2019-12-26 14:22 -0800
Re: scylldb and php? anyone building a site with them on archlinux? Arno Welzel <usenet@arnowelzel.de> - 2019-11-08 01:54 +0100
Re: scylldb and php? anyone building a site with them on archlinux? "J.O. Aho" <user@example.net> - 2019-11-08 06:46 +0100
Re: scylldb and php? anyone building a site with them on archlinux? Arno Welzel <usenet@arnowelzel.de> - 2019-11-09 17:03 +0100
Re: scylldb and php? anyone building a site with them on archlinux? "J.O. Aho" <user@example.net> - 2019-11-09 20:58 +0100
Re: scylldb and php? anyone building a site with them on archlinux? Arno Welzel <usenet@arnowelzel.de> - 2019-11-09 23:58 +0100
Re: scylldb and php? anyone building a site with them on archlinux? "J.O. Aho" <user@example.net> - 2019-11-10 10:26 +0100
Re: scylldb and php? anyone building a site with them on archlinux? Arno Welzel <usenet@arnowelzel.de> - 2019-11-10 10:59 +0100
Re: scylldb and php? anyone building a site with them on archlinux? "J.O. Aho" <user@example.net> - 2019-11-10 11:15 +0100
Re: scylldb and php? anyone building a site with them on archlinux? Azathoth Hastur <azathothhaster@gmail.com> - 2019-12-26 14:25 -0800
Re: scylldb and php? anyone building a site with them on archlinux? Azathoth Hastur <azathothhaster@gmail.com> - 2019-12-26 14:25 -0800
Re: scylldb and php? anyone building a site with them on archlinux? Arno Welzel <usenet@arnowelzel.de> - 2019-12-30 15:28 +0100
Re: scylldb and php? anyone building a site with them on archlinux? Azathoth Hastur <azathothhaster@gmail.com> - 2019-12-26 14:23 -0800
Re: scylldb and php? anyone building a site with them on archlinux? Härra Rabmo <he12091983@gmail.com> - 2022-07-08 06:45 -0700
Page 1 of 2 [1] 2 Next page →
| From | Azathoth Hastur <azathothhaster@gmail.com> |
|---|---|
| Date | 2019-11-04 20:04 -0800 |
| Subject | scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <4e081378-85fa-4ff5-88a5-b6580c9330b1@googlegroups.com> |
curious ha-proxy too
[toc] | [next] | [standalone]
| From | "J.O. Aho" <user@example.net> |
|---|---|
| Date | 2019-11-05 07:03 +0100 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <h2chl7Fp7dtU1@mid.individual.net> |
| In reply to | #18083 |
On 05/11/2019 05.04, Azathoth Hastur wrote: > scylldb and php I'm a bit too lazy and don't like the extra security work to keep a self compiled driver up to date. > anyone building a site with them on archlinux? I see the systemd as a security risk on a computer due of the many serious vulnerabilities in systemd over the last couple of years. Artix is a systemd free version that I think may be a better option. > curious ha-proxy too Not much of PHP there, so it's a bit off topic here, it's a good tool as long as your application handles shared sessions, or else you need to use sticky connections, which don't really provide a good loadbalancing. -- //Aho
[toc] | [prev] | [next] | [standalone]
| From | Azathoth Hastur <azathothhaster@gmail.com> |
|---|---|
| Date | 2019-11-04 22:14 -0800 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <fe639aa3-e9d1-49d1-9b26-8e52f12a4f4f@googlegroups.com> |
| In reply to | #18084 |
On Tuesday, November 5, 2019 at 1:03:26 AM UTC-5, J.O. Aho wrote: > On 05/11/2019 05.04, Azathoth Hastur wrote: > > scylldb and php > > I'm a bit too lazy and don't like the extra security work to keep a self > compiled driver up to date. > > > > anyone building a site with them on archlinux? > > I see the systemd as a security risk on a computer due of the many > serious vulnerabilities in systemd over the last couple of years. > > Artix is a systemd free version that I think may be a better option. > > > > curious ha-proxy too > > Not much of PHP there, so it's a bit off topic here, it's a good tool as > long as your application handles shared sessions, or else you need to > use sticky connections, which don't really provide a good loadbalancing. > > -- > > //Aho artix looks good, I had not heard systemd is that bad before.... I like freebsd.org what do you think? openbsd best for security? oh the scylladb php driver is compiled? thats ez though probably... how do you make the app handle shared sessions?
[toc] | [prev] | [next] | [standalone]
| From | "J.O. Aho" <user@example.net> |
|---|---|
| Date | 2019-11-05 18:34 +0100 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <h2dq4gF31dqU1@mid.individual.net> |
| In reply to | #18085 |
On 05/11/2019 07.14, Azathoth Hastur wrote: > artix looks good, I had not heard systemd is that bad before.... If I remember it right, systemd had somewhere around 56 security vulnerabilities (including remote code execution) the last couple of years, that is far more than the other init systems combined in their entire lifespans. Sure there are some good features in systemd, but the big code base makes it quite vulnerable to new security issues. > I like freebsd.org what do you think? openbsd best for security? It's been years sine I run BSD, I don't have anything negative to say about it. When I used BSD it was mainly NetBSD, mainly for they had the best platform support back when I still used a variety of different platforms. I would go for OpenBSD for anything that was accessible from the internet. > oh the scylladb php driver is compiled? thats ez though probably... It's not much work to compile the driver, it's just that you need to keep an eye on their website/maillist so you know when there is a security vulnerability and you should update to a new fixed version. > how do you make the app handle shared sessions? Simplest is to have a common storage like a database of some sort that all the web-servers (application servers) can access, you store the session data in the database. In php this requires you to write a custom session handler and use it. You can of course use the scylladb as the database to store the session data in. If you have this working, then you can use round robbin on the ha-proxy without the user gets logged out. Of course you should include a check on load to see to which machines you should send the traffic to. I don't think you need ha-proxy for the sculladb itself, I guess it do have some fail over feature built in it's always-on availability, so you will be able to get data from a working node. -- //Aho
[toc] | [prev] | [next] | [standalone]
| From | Azathoth Hastur <azathothhaster@gmail.com> |
|---|---|
| Date | 2019-11-06 12:22 -0800 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <daf12ce9-d017-4b0e-ae17-40fca8541082@googlegroups.com> |
| In reply to | #18086 |
On Tuesday, November 5, 2019 at 12:34:14 PM UTC-5, J.O. Aho wrote: > On 05/11/2019 07.14, Azathoth Hastur wrote: > > > artix looks good, I had not heard systemd is that bad before.... > > If I remember it right, systemd had somewhere around 56 security > vulnerabilities (including remote code execution) the last couple of > years, that is far more than the other init systems combined in their > entire lifespans. > > Sure there are some good features in systemd, but the big code base > makes it quite vulnerable to new security issues. > > > > I like freebsd.org what do you think? openbsd best for security? > > It's been years sine I run BSD, I don't have anything negative to say > about it. When I used BSD it was mainly NetBSD, mainly for they had the > best platform support back when I still used a variety of different > platforms. I would go for OpenBSD for anything that was accessible from > the internet. > > > > oh the scylladb php driver is compiled? thats ez though probably... > > It's not much work to compile the driver, it's just that you need to > keep an eye on their website/maillist so you know when there is a > security vulnerability and you should update to a new fixed version. > > > > how do you make the app handle shared sessions? > > Simplest is to have a common storage like a database of some sort that > all the web-servers (application servers) can access, you store the > session data in the database. In php this requires you to write a custom > session handler and use it. > You can of course use the scylladb as the database to store the session > data in. > If you have this working, then you can use round robbin on the ha-proxy > without the user gets logged out. Of course you should include a check > on load to see to which machines you should send the traffic to. > > I don't think you need ha-proxy for the sculladb itself, I guess it do > have some fail over feature built in it's always-on availability, so you > will be able to get data from a working node. > > -- > > //Aho I heard that session in the DB is slow.... Are you a hardcore web developer? What site? DO you ever use postgreql? or what db? I am software architect with tcl haskell lisp smalltalk gnoga.com and forth and maybe picolisp when I can get time....or swi prolog web..... I think fortran.io and c web framework look interesting too for performance.... I wonder why the archlinux people themselves have not questioned systemd....
[toc] | [prev] | [next] | [standalone]
| From | "J.O. Aho" <user@example.net> |
|---|---|
| Date | 2019-11-07 06:57 +0100 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <h2hq1fFsedoU1@mid.individual.net> |
| In reply to | #18087 |
On 06/11/2019 21.22, Azathoth Hastur wrote: > I heard that session in the DB is slow.... Depends on what DB you use in the background, a popular option lately has been key value databases, other alternatives are memcache. > Are you a hardcore web developer? Nowadays mainly backend for me. > What site? Under NDA. > DO you ever use postgreql? > or what db? I haven't really used postgresql on a site, the main databases I have been using the last years are Transact-SQL like Sybase and MS-SQL. If you go for postresql, I would recommend version 12 as it has better performance than the older versions and I would look forward for version 13 which will improve data encryption. > I wonder why the archlinux people themselves have not questioned systemd.... They look more at the "cool features" and to lessen the amount of work to maintain two alternatives (earlier you had two init system to pick from). I sometimes which ArchLinux/Artix could go a bit more like Gentoo on packages default options. -- //Aho
[toc] | [prev] | [next] | [standalone]
| From | Azathoth Hastur <azathothhaster@gmail.com> |
|---|---|
| Date | 2019-11-07 05:35 -0800 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <f334322e-dc1b-4b7d-a6e6-a034304c2cf3@googlegroups.com> |
| In reply to | #18089 |
On Thursday, November 7, 2019 at 12:57:10 AM UTC-5, J.O. Aho wrote: > On 06/11/2019 21.22, Azathoth Hastur wrote: > > > I heard that session in the DB is slow.... > > Depends on what DB you use in the background, a popular option lately > has been key value databases, other alternatives are memcache. > > > > Are you a hardcore web developer? > > Nowadays mainly backend for me. > > > What site? > > Under NDA. > > > > DO you ever use postgreql? > > or what db? > > I haven't really used postgresql on a site, the main databases I have > been using the last years are Transact-SQL like Sybase and MS-SQL. > > If you go for postresql, I would recommend version 12 as it has better > performance than the older versions and I would look forward for version > 13 which will improve data encryption. > > > > I wonder why the archlinux people themselves have not questioned systemd.... > > They look more at the "cool features" and to lessen the amount of work > to maintain two alternatives (earlier you had two init system to pick from). > > I sometimes which ArchLinux/Artix could go a bit more like Gentoo on > packages default options. > > -- > > //Aho archlinux and freebsd are best 2 I have tied netbsd also good openbsd crashes browser when I open too many tab, by design I jsut find it cumbersom on desktop I run frebsd 12 now so you have a real website up and running or are you just a kid?
[toc] | [prev] | [next] | [standalone]
| From | "J.O. Aho" <user@example.net> |
|---|---|
| Date | 2019-11-07 21:49 +0100 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <h2je9sF8kcoU1@mid.individual.net> |
| In reply to | #18092 |
On 07/11/2019 14.35, Azathoth Hastur wrote: > archlinux and freebsd are best 2 I have tied I tried Arch, but it had tendencies to get into a state where you can't boot with it, the problem seemed to be related to systemd and sadly the systemd developers didn't figure out how to fix it. Nowadays I have used Artix, it's ok and is more or less as Arch except you can choose to use openrc or runit as the init systems. I do have to say I think Gentoo/Funtoo are better, better default settings for apps and allow you to customize things a lot, but of course with the cost of everything takes time to install as you have to build every package. I haven't used freebsd, but if I would use BSD for desktop, then I would look more at DragonFly BSD or maybe at PC-BSD. > openbsd crashes browser when I open too many tab, by design OpenBSD I would run as a headless server and at most use wget/curl and in really rare cases maybe use elinks. > so you have a real website up and running or are you just a kid? Don't think kids signs that many NDA's. -- //Aho
[toc] | [prev] | [next] | [standalone]
| From | Azathoth Hastur <azathothhaster@gmail.com> |
|---|---|
| Date | 2019-12-26 14:22 -0800 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <9b0c3fd6-2c89-42a1-826f-8489ff2307d7@googlegroups.com> |
| In reply to | #18094 |
On Thursday, November 7, 2019 at 3:49:07 PM UTC-5, J.O. Aho wrote: > On 07/11/2019 14.35, Azathoth Hastur wrote: > > > archlinux and freebsd are best 2 I have tied > > I tried Arch, but it had tendencies to get into a state where you can't > boot with it, the problem seemed to be related to systemd and sadly the > systemd developers didn't figure out how to fix it. > Nowadays I have used Artix, it's ok and is more or less as Arch except > you can choose to use openrc or runit as the init systems. > > I do have to say I think Gentoo/Funtoo are better, better default > settings for apps and allow you to customize things a lot, but of course > with the cost of everything takes time to install as you have to build > every package. > > > I haven't used freebsd, but if I would use BSD for desktop, then I would > look more at DragonFly BSD or maybe at PC-BSD. > > > > > openbsd crashes browser when I open too many tab, by design > > OpenBSD I would run as a headless server and at most use wget/curl and > in really rare cases maybe use elinks. > > > > > so you have a real website up and running or are you just a kid? > > Don't think kids signs that many NDA's. > > > -- > > //Aho Artix seems cool with the new s3 system they are going to use. I am unclear if thier current install ISO supports that. I did a install of arch few days ago. Painful. I am using systemd-networkd and the DNS was ? but now all working.... I think thier docs need a little love... Linux so many options. I remember netctl being easier maybe that was my mistake. I also flounder when dns tool and net toosl are not defautl but I guess you can build anythgin fro gournd up with arch. I am excited to try pharo smalltalk again and have all latest stuff. All my external USB 4T 5T disks are ext4 so now I can look at all my archives of games and books and funny stuff... gnoga.com scylladb+tcl or php postgresql +tcl or php so many great free software web and data tools swi prolog lisp haskell forth my oh my
[toc] | [prev] | [next] | [standalone]
| From | Arno Welzel <usenet@arnowelzel.de> |
|---|---|
| Date | 2019-11-08 01:54 +0100 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <h2jsmoFbed2U1@mid.individual.net> |
| In reply to | #18084 |
J.O. Aho: [...] > I see the systemd as a security risk on a computer due of the many > serious vulnerabilities in systemd over the last couple of years. Many? Serious? Where? <https://www.cvedetails.com/product/38088/Freedesktop-Systemd.html?vendor_id=7971> Compared to PHP this does not look too bad: <https://www.cvedetails.com/product/128/PHP-PHP.html?vendor_id=74> What did I miss? -- Arno Welzel https://arnowelzel.de
[toc] | [prev] | [next] | [standalone]
| From | "J.O. Aho" <user@example.net> |
|---|---|
| Date | 2019-11-08 06:46 +0100 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <h2kdorFembeU1@mid.individual.net> |
| In reply to | #18095 |
On 08/11/2019 01.54, Arno Welzel wrote: > J.O. Aho: > > [...] >> I see the systemd as a security risk on a computer due of the many >> serious vulnerabilities in systemd over the last couple of years. > > Many? Serious? Where? > > <https://www.cvedetails.com/product/38088/Freedesktop-Systemd.html?vendor_id=7971> > > Compared to PHP this does not look too bad: > > <https://www.cvedetails.com/product/128/PHP-PHP.html?vendor_id=74> > > What did I miss? That not so many do use php as an init system. -- //Aho
[toc] | [prev] | [next] | [standalone]
| From | Arno Welzel <usenet@arnowelzel.de> |
|---|---|
| Date | 2019-11-09 17:03 +0100 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <h2o6b0F8712U1@mid.individual.net> |
| In reply to | #18096 |
J.O. Aho: > On 08/11/2019 01.54, Arno Welzel wrote: >> J.O. Aho: >> >> [...] >>> I see the systemd as a security risk on a computer due of the many >>> serious vulnerabilities in systemd over the last couple of years. >> >> Many? Serious? Where? >> >> <https://www.cvedetails.com/product/38088/Freedesktop-Systemd.html?vendor_id=7971> >> >> Compared to PHP this does not look too bad: >> >> <https://www.cvedetails.com/product/128/PHP-PHP.html?vendor_id=74> >> >> What did I miss? > > That not so many do use php as an init system. If a vulnerability allows code execution it does not matter, if PHP is used as an init system or not. The attacker does not need to gain full access over a system to compromise a website and abuse it for his own purposes. -- Arno Welzel https://arnowelzel.de
[toc] | [prev] | [next] | [standalone]
| From | "J.O. Aho" <user@example.net> |
|---|---|
| Date | 2019-11-09 20:58 +0100 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <h2ok2bFb335U1@mid.individual.net> |
| In reply to | #18102 |
On 09/11/2019 17.03, Arno Welzel wrote: > If a vulnerability allows code execution it does not matter, if PHP is > used as an init system or not. The attacker does not need to gain full > access over a system to compromise a website and abuse it for his own > purposes. Sure, a code execution vulnerability is a serious problem no matter which application has the vulnerability, but when it's process number 1 which has this vulnerability the problem is a lot worse than a process that is run as a none privileged user. A none privileged user can do less damage to the system than the one root user which has power over them all (even worse than run a vulnerable php as root user). -- //Aho
[toc] | [prev] | [next] | [standalone]
| From | Arno Welzel <usenet@arnowelzel.de> |
|---|---|
| Date | 2019-11-09 23:58 +0100 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <h2oulfFd6g4U1@mid.individual.net> |
| In reply to | #18106 |
J.O. Aho: > On 09/11/2019 17.03, Arno Welzel wrote: > >> If a vulnerability allows code execution it does not matter, if PHP is >> used as an init system or not. The attacker does not need to gain full >> access over a system to compromise a website and abuse it for his own >> purposes. > > Sure, a code execution vulnerability is a serious problem no matter > which application has the vulnerability, but when it's process number 1 > which has this vulnerability the problem is a lot worse than a process > that is run as a none privileged user. A none privileged user can do > less damage to the system than the one root user which has power over > them all (even worse than run a vulnerable php as root user). Sure - but what vulnerability of systemd could be exploited remotely so it is problem for webservers? I don't remember any. -- Arno Welzel https://arnowelzel.de
[toc] | [prev] | [next] | [standalone]
| From | "J.O. Aho" <user@example.net> |
|---|---|
| Date | 2019-11-10 10:26 +0100 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <h2q3eiFk8p5U1@mid.individual.net> |
| In reply to | #18108 |
On 09/11/2019 23.58, Arno Welzel wrote: > J.O. Aho: > >> On 09/11/2019 17.03, Arno Welzel wrote: >> >>> If a vulnerability allows code execution it does not matter, if PHP is >>> used as an init system or not. The attacker does not need to gain full >>> access over a system to compromise a website and abuse it for his own >>> purposes. >> >> Sure, a code execution vulnerability is a serious problem no matter >> which application has the vulnerability, but when it's process number 1 >> which has this vulnerability the problem is a lot worse than a process >> that is run as a none privileged user. A none privileged user can do >> less damage to the system than the one root user which has power over >> them all (even worse than run a vulnerable php as root user). > > Sure - but what vulnerability of systemd could be exploited remotely so > it is problem for webservers? I don't remember any. Here is a example of remote code execution vulnerability that systemd had a couple of years ago: https://www.openwall.com/lists/oss-security/2017/06/27/8 Sure it's not a simple attack, but if you have managed to get hold of a machine in the network, some arp poisoning and you are able to start execute code on machines which not up to date. You also have this one from last year: https://meterpreter.org/cve-2018-15688-systemd-remote-code-execution/ Also you would need taken control of a machine in the network. If you compare with any other init system, they never have had this kind of security vulnerabilities, as they do not handle other things than initialize the system and those do not have the capability of sending receiving data from an external source. The only thing I can compare systemd when it comes to potential future vulnerabilities is the worst of microsoft windows xp vulnerabilities, where someone could become a super-administrator (there been this kind of vulnerabilities in later versions of microsoft windows, but far less and there are some built in measures to try to prevent these which completely lacks in systemd). -- //Aho
[toc] | [prev] | [next] | [standalone]
| From | Arno Welzel <usenet@arnowelzel.de> |
|---|---|
| Date | 2019-11-10 10:59 +0100 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <h2q5ceFkkf5U1@mid.individual.net> |
| In reply to | #18110 |
J.O. Aho: > On 09/11/2019 23.58, Arno Welzel wrote: [...] >> Sure - but what vulnerability of systemd could be exploited remotely so >> it is problem for webservers? I don't remember any. > > Here is a example of remote code execution vulnerability that systemd > had a couple of years ago: > > https://www.openwall.com/lists/oss-security/2017/06/27/8 > > Sure it's not a simple attack, but if you have managed to get hold of a > machine in the network, some arp poisoning and you are able to start > execute code on machines which not up to date. > > > You also have this one from last year: > > https://meterpreter.org/cve-2018-15688-systemd-remote-code-execution/ > > Also you would need taken control of a machine in the network. Thanks for the references. Indeed, this looks not good - but as you said: it's not a simple attack as the first vulnerability can only be exploited by having a server to communicate with a malicious nameserver of the attacker. Usually public servers just don't to that and even desktop machines of end users often just use the nameserver of the ISP or the router. The second one is more critical but as I understand it also not relevant for public servers. > If you compare with any other init system, they never have had this kind > of security vulnerabilities, as they do not handle other things than > initialize the system and those do not have the capability of sending > receiving data from an external source. Sure. > The only thing I can compare systemd when it comes to potential future > vulnerabilities is the worst of microsoft windows xp vulnerabilities, > where someone could become a super-administrator (there been this kind > of vulnerabilities in later versions of microsoft windows, but far less > and there are some built in measures to try to prevent these which > completely lacks in systemd). Even Microsoft learned their lessons and I dont't see why systemd should get worse than it is. -- Arno Welzel https://arnowelzel.de
[toc] | [prev] | [next] | [standalone]
| From | "J.O. Aho" <user@example.net> |
|---|---|
| Date | 2019-11-10 11:15 +0100 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <h2q6a5FkqgjU1@mid.individual.net> |
| In reply to | #18111 |
On 10/11/2019 10.59, Arno Welzel wrote: > J.O. Aho: > >> On 09/11/2019 23.58, Arno Welzel wrote: > [...] >>> Sure - but what vulnerability of systemd could be exploited remotely so >>> it is problem for webservers? I don't remember any. >> >> Here is a example of remote code execution vulnerability that systemd >> had a couple of years ago: >> >> https://www.openwall.com/lists/oss-security/2017/06/27/8 >> >> Sure it's not a simple attack, but if you have managed to get hold of a >> machine in the network, some arp poisoning and you are able to start >> execute code on machines which not up to date. >> >> >> You also have this one from last year: >> >> https://meterpreter.org/cve-2018-15688-systemd-remote-code-execution/ >> >> Also you would need taken control of a machine in the network. > > Thanks for the references. > > Indeed, this looks not good - but as you said: it's not a simple attack > as the first vulnerability can only be exploited by having a server to > communicate with a malicious nameserver of the attacker. Usually public > servers just don't to that and even desktop machines of end users often > just use the nameserver of the ISP or the router. With some arp poisoning and your server would start talking with a malicious nameserver, as you server will most likely be in a DC where you may have a number of other machines in the same network, just one of those needs to be compromised first and that way it could spread. Even if this ain't rocket-science, it won't be a script kid who would preform this kind of attack. > The second one is more critical but as I understand it also not relevant > for public servers. This is quite relevant for virtual machines, which gets their ip from the dhcp service, as this is the simplest way to administrate the ip addresses in a cloudplatform. >> If you compare with any other init system, they never have had this kind >> of security vulnerabilities, as they do not handle other things than >> initialize the system and those do not have the capability of sending >> receiving data from an external source. > > Sure. > >> The only thing I can compare systemd when it comes to potential future >> vulnerabilities is the worst of microsoft windows xp vulnerabilities, >> where someone could become a super-administrator (there been this kind >> of vulnerabilities in later versions of microsoft windows, but far less >> and there are some built in measures to try to prevent these which >> completely lacks in systemd). > > Even Microsoft learned their lessons and I dont't see why systemd should > get worse than it is. systemd keeps on eating up other projects, so systemd grows and gets more potential attack vectors. Had it avoided to handle network traffic, time keeping, name lookup, it would be more safe even if there was vulnerabilities as then you would need to be local user. -- //Aho
[toc] | [prev] | [next] | [standalone]
| From | Azathoth Hastur <azathothhaster@gmail.com> |
|---|---|
| Date | 2019-12-26 14:25 -0800 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <9e5b903e-149f-43ec-bc84-dfdb3d797ef6@googlegroups.com> |
| In reply to | #18112 |
On Sunday, November 10, 2019 at 5:15:38 AM UTC-5, J.O. Aho wrote: > On 10/11/2019 10.59, Arno Welzel wrote: > > J.O. Aho: > > > >> On 09/11/2019 23.58, Arno Welzel wrote: > > [...] > >>> Sure - but what vulnerability of systemd could be exploited remotely so > >>> it is problem for webservers? I don't remember any. > >> > >> Here is a example of remote code execution vulnerability that systemd > >> had a couple of years ago: > >> > >> https://www.openwall.com/lists/oss-security/2017/06/27/8 > >> > >> Sure it's not a simple attack, but if you have managed to get hold of a > >> machine in the network, some arp poisoning and you are able to start > >> execute code on machines which not up to date. > >> > >> > >> You also have this one from last year: > >> > >> https://meterpreter.org/cve-2018-15688-systemd-remote-code-execution/ > >> > >> Also you would need taken control of a machine in the network. > > > > Thanks for the references. > > > > Indeed, this looks not good - but as you said: it's not a simple attack > > as the first vulnerability can only be exploited by having a server to > > communicate with a malicious nameserver of the attacker. Usually public > > servers just don't to that and even desktop machines of end users often > > just use the nameserver of the ISP or the router. > > With some arp poisoning and your server would start talking with a > malicious nameserver, as you server will most likely be in a DC where > you may have a number of other machines in the same network, just one of > those needs to be compromised first and that way it could spread. > > Even if this ain't rocket-science, it won't be a script kid who would > preform this kind of attack. > > > > The second one is more critical but as I understand it also not relevant > > for public servers. > > This is quite relevant for virtual machines, which gets their ip from > the dhcp service, as this is the simplest way to administrate the ip > addresses in a cloudplatform. > > > >> If you compare with any other init system, they never have had this kind > >> of security vulnerabilities, as they do not handle other things than > >> initialize the system and those do not have the capability of sending > >> receiving data from an external source. > > > > Sure. > > > >> The only thing I can compare systemd when it comes to potential future > >> vulnerabilities is the worst of microsoft windows xp vulnerabilities, > >> where someone could become a super-administrator (there been this kind > >> of vulnerabilities in later versions of microsoft windows, but far less > >> and there are some built in measures to try to prevent these which > >> completely lacks in systemd). > > > > Even Microsoft learned their lessons and I dont't see why systemd should > > get worse than it is. > > systemd keeps on eating up other projects, so systemd grows and gets > more potential attack vectors. Had it avoided to handle network traffic, > time keeping, name lookup, it would be more safe even if there was > vulnerabilities as then you would need to be local user. > > -- > > //Aho https://artixlinux.org/ Support for the s6 init system is now official 2019-11-21 We are pleased to announce that, after a moderate period of testing, the s6 process supervision suit has come out of [gremlins]. People willing to install (or convert to) this init system, are encouraged to read the upstream documentation and related posts in our forum. Most s6 service init files are also provided in [world] and [galaxy].
[toc] | [prev] | [next] | [standalone]
| From | Azathoth Hastur <azathothhaster@gmail.com> |
|---|---|
| Date | 2019-12-26 14:25 -0800 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <eeafbd70-19ec-4261-b82f-563050654706@googlegroups.com> |
| In reply to | #18154 |
On Thursday, December 26, 2019 at 5:25:11 PM UTC-5, Azathoth Hastur wrote: > On Sunday, November 10, 2019 at 5:15:38 AM UTC-5, J.O. Aho wrote: > > On 10/11/2019 10.59, Arno Welzel wrote: > > > J.O. Aho: > > > > > >> On 09/11/2019 23.58, Arno Welzel wrote: > > > [...] > > >>> Sure - but what vulnerability of systemd could be exploited remotely so > > >>> it is problem for webservers? I don't remember any. > > >> > > >> Here is a example of remote code execution vulnerability that systemd > > >> had a couple of years ago: > > >> > > >> https://www.openwall.com/lists/oss-security/2017/06/27/8 > > >> > > >> Sure it's not a simple attack, but if you have managed to get hold of a > > >> machine in the network, some arp poisoning and you are able to start > > >> execute code on machines which not up to date. > > >> > > >> > > >> You also have this one from last year: > > >> > > >> https://meterpreter.org/cve-2018-15688-systemd-remote-code-execution/ > > >> > > >> Also you would need taken control of a machine in the network. > > > > > > Thanks for the references. > > > > > > Indeed, this looks not good - but as you said: it's not a simple attack > > > as the first vulnerability can only be exploited by having a server to > > > communicate with a malicious nameserver of the attacker. Usually public > > > servers just don't to that and even desktop machines of end users often > > > just use the nameserver of the ISP or the router. > > > > With some arp poisoning and your server would start talking with a > > malicious nameserver, as you server will most likely be in a DC where > > you may have a number of other machines in the same network, just one of > > those needs to be compromised first and that way it could spread. > > > > Even if this ain't rocket-science, it won't be a script kid who would > > preform this kind of attack. > > > > > > > The second one is more critical but as I understand it also not relevant > > > for public servers. > > > > This is quite relevant for virtual machines, which gets their ip from > > the dhcp service, as this is the simplest way to administrate the ip > > addresses in a cloudplatform. > > > > > > >> If you compare with any other init system, they never have had this kind > > >> of security vulnerabilities, as they do not handle other things than > > >> initialize the system and those do not have the capability of sending > > >> receiving data from an external source. > > > > > > Sure. > > > > > >> The only thing I can compare systemd when it comes to potential future > > >> vulnerabilities is the worst of microsoft windows xp vulnerabilities, > > >> where someone could become a super-administrator (there been this kind > > >> of vulnerabilities in later versions of microsoft windows, but far less > > >> and there are some built in measures to try to prevent these which > > >> completely lacks in systemd). > > > > > > Even Microsoft learned their lessons and I dont't see why systemd should > > > get worse than it is. > > > > systemd keeps on eating up other projects, so systemd grows and gets > > more potential attack vectors. Had it avoided to handle network traffic, > > time keeping, name lookup, it would be more safe even if there was > > vulnerabilities as then you would need to be local user. > > > > -- > > > > //Aho > > > https://artixlinux.org/ > > Support for the s6 init system is now official > > 2019-11-21 > > We are pleased to announce that, after a moderate period of testing, the s6 process supervision suit has come out of [gremlins]. > People willing to install (or convert to) this init system, are encouraged to read the upstream documentation and related posts in our forum. Most s6 service init files are also provided in [world] and [galaxy]. I can't find the howto or the ISO to use? This seems best wow never knew related to qmail and daemontools by dan bernstein
[toc] | [prev] | [next] | [standalone]
| From | Arno Welzel <usenet@arnowelzel.de> |
|---|---|
| Date | 2019-12-30 15:28 +0100 |
| Subject | Re: scylldb and php? anyone building a site with them on archlinux? |
| Message-ID | <h6ufruFtfb1U2@mid.individual.net> |
| In reply to | #18155 |
Azathoth Hastur: > On Thursday, December 26, 2019 at 5:25:11 PM UTC-5, Azathoth Hastur wrote: [...] >> https://artixlinux.org/ >> >> Support for the s6 init system is now official >> >> 2019-11-21 >> >> We are pleased to announce that, after a moderate period of testing, the s6 process supervision suit has come out of [gremlins]. >> People willing to install (or convert to) this init system, are encouraged to read the upstream documentation and related posts in our forum. Most s6 service init files are also provided in [world] and [galaxy]. > > I can't find the howto or the ISO to use? https://artixlinux.org/download.php -- Arno Welzel https://arnowelzel.de
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | comp.lang.php
csiph-web