Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.advocacy > #377146 > unrolled thread
| Started by | Jim Polaski <jpolaski@linuxmail.org> |
|---|---|
| First post | 2016-10-21 14:25 +0000 |
| Last post | 2016-10-22 12:24 +0000 |
| Articles | 20 on this page of 53 — 12 participants |
Back to article view | Back to comp.os.linux.advocacy
9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Jim Polaski <jpolaski@linuxmail.org> - 2016-10-21 14:25 +0000
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Peter Köhlmann <peter-koehlmann@t-online.de> - 2016-10-21 17:49 +0200
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Melzzzzz <mel@zzzzz.com> - 2016-10-21 22:45 +0200
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Jim Polaski <jpolaski@linuxmail.org> - 2016-10-21 20:51 +0000
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Melzzzzz <mel@zzzzz.com> - 2016-10-21 22:59 +0200
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Jim Polaski <jpolaski@linuxmail.org> - 2016-10-21 21:11 +0000
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Peter Köhlmann <peter-koehlmann@t-online.de> - 2016-10-21 23:14 +0200
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Jim Polaski <jpolaski@linuxmail.org> - 2016-10-21 21:20 +0000
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Peter Köhlmann <peter-koehlmann@t-online.de> - 2016-10-22 11:38 +0200
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Peter Köhlmann <peter-koehlmann@t-online.de> - 2016-10-21 23:13 +0200
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Jim Polaski <jpolaski@linuxmail.org> - 2016-10-21 21:17 +0000
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Peter Köhlmann <peter-koehlmann@t-online.de> - 2016-10-22 11:35 +0200
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Marek Novotny <marek.novotny@marspolar.com> - 2016-10-21 17:23 -0400
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Jim Polaski <jpolaski@linuxmail.org> - 2016-10-21 21:52 +0000
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Peter Köhlmann <peter-koehlmann@t-online.de> - 2016-10-22 11:33 +0200
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Chris Ahlstrom <OFeem1987@teleworm.us> - 2016-10-22 08:19 -0400
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Marek Novotny <marek.novotny@marspolar.com> - 2016-10-22 08:33 -0400
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Silver Slimer <.m@nsn.s> - 2016-10-22 09:23 -0400
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Peter Köhlmann <peter-koehlmann@t-online.de> - 2016-10-22 15:48 +0200
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Silver Slimer <.m@nsn.s> - 2016-10-22 10:02 -0400
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Peter Köhlmann <peter-koehlmann@t-online.de> - 2016-10-22 16:07 +0200
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. William Poaster <wp@dev.null> - 2016-10-22 16:46 +0100
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Silver Slimer <.m@nsn.s> - 2016-10-23 09:04 -0400
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Silver Slimer <.m@nsn.s> - 2016-10-22 14:34 -0400
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. -hh <recscuba_google@huntzinger.com> - 2016-10-22 12:45 -0700
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Steve Carroll <frelwizzen@gmail.com> - 2016-10-22 12:10 -0700
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. William Poaster <wp@dev.null> - 2016-10-21 23:05 +0100
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Marek Novotny <marek.novotny@marspolar.com> - 2016-10-21 18:09 -0400
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. -hh <recscuba_google@huntzinger.com> - 2016-10-22 04:35 -0700
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Silver Slimer <.m@nsn.s> - 2016-10-21 11:50 -0400
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Jim Polaski <jpolaski@linuxmail.org> - 2016-10-21 15:56 +0000
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Silver Slimer <.m@nsn.s> - 2016-10-21 12:46 -0400
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Jim Polaski <jpolaski@linuxmail.org> - 2016-10-21 20:16 +0000
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Silver Slimer <.m@nsn.s> - 2016-10-21 18:30 -0400
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Jim Polaski <jpolaski@linuxmail.org> - 2016-10-21 22:54 +0000
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Jim Polaski <jpolaski@linuxmail.org> - 2016-10-21 16:10 +0000
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. tmelmosfire <tmelmosfire@gmail.com> - 2016-10-21 09:34 -0700
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Melzzzzz <mel@zzzzz.com> - 2016-10-21 22:43 +0200
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Jim Polaski <jpolaski@linuxmail.org> - 2016-10-21 20:45 +0000
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Melzzzzz <mel@zzzzz.com> - 2016-10-21 22:47 +0200
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Jim Polaski <jpolaski@linuxmail.org> - 2016-10-21 20:52 +0000
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. GreyCloud <Cumulus@mist.com> - 2016-10-21 19:31 -0600
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Jim Polaski <jpolaski@linuxmail.org> - 2016-10-22 01:46 +0000
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Peter Köhlmann <peter-koehlmann@t-online.de> - 2016-10-22 11:30 +0200
A Flounder is as Flounder does Chris Ahlstrom <OFeem1987@teleworm.us> - 2016-10-22 08:12 -0400
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. GreyCloud <Cumulus@mist.com> - 2016-10-22 13:49 -0600
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. GreyCloud <Cumulus@mist.com> - 2016-10-21 19:31 -0600
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Jim Polaski <jpolaski@linuxmail.org> - 2016-10-22 01:44 +0000
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Melzzzzz <mel@zzzzz.com> - 2016-10-22 04:29 +0200
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Peter Köhlmann <peter-koehlmann@t-online.de> - 2016-10-22 11:30 +0200
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. GreyCloud <Cumulus@mist.com> - 2016-10-22 13:50 -0600
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Chris Ahlstrom <OFeem1987@teleworm.us> - 2016-10-22 08:11 -0400
Re: 9 Year Old Linux Kernel Exploit Discovered. This is a bad one. Godzilla <godzilla@lizardboss.invalid> - 2016-10-22 12:24 +0000
Page 2 of 3 — ← Prev page 1 [2] 3 Next page →
| From | Peter Köhlmann <peter-koehlmann@t-online.de> |
|---|---|
| Date | 2016-10-22 16:07 +0200 |
| Message-ID | <nufrr0$dn4$1@dont-email.me> |
| In reply to | #377285 |
Snit Slimeshit wrote: > On 2016-10-22 9:48 AM, Peter Köhlmann wrote: >> Snit Slimeshit wrote: >> >>> On 2016-10-22 8:33 AM, Marek Novotny wrote: >>>> On 2016-10-22, Chris Ahlstrom <OFeem1987@teleworm.us> wrote: >>>>> Peter Köhlmann wrote this copyrighted missive and expects royalties: >>>>> >>>>>> Well, when you posted it I *was* already informed. >>>>>> Not only that, I got an update shortly before >>>>>> Linux users generally don't need such a "service" from trolls like >>>>>> you >>>>> >>>>> It's the usual dance. A long-time bug finally surfaces, we here a lot >>>>> of corporate shills screeching about the DANGER DANGER DANGER, a lot >>>>> of dismissing of the "many eyes" that ignores just how few serious >>>>> bugs actually slip through the many-eyes gauntlet, the patches are >>>>> quickly issued, and it is forgotten until the next major bug. >>>> >>>> And zero comment on the 5 Zero Days on Windows from just last week. >>>> FIVE. So much for that proprietary software yielding good quality. LOL. >>> >>> No comments? Let me leave one. >>> >>> The 9 year-old Linux bug was actively exploited during that entire time >> >> Proof? *Any* at all? >> Thought so > > I'll provide it, knowing that your dumb ass will ignore it either way: > <http://arstechnica.com/security/2016/10/most-serious-linux-privilege-escalation-bug-ever-is-under-active-exploit/> > > First paragraph: "A serious vulnerability that has been present for nine > years in virtually all versions of the Linux operating system > is under *active exploit*, according to researchers who are advising > users to install a patch as soon as possible." > >>> and allowed hackers to compromise a large number of systems along the >>> way. >> >> Except it wasn't obviously a "large number" >> "Allowing" and having "actually being exploited" are different things > > Previous paragraph, Peter the Klöwn. Well, you certainly will be able to point us to the place in that article where it says that it is "activly being exploited the entire time", will you? *Your* claim Thought so. You are just making things up as they come along. A bug being present that time and a bug "being exploited the entire time" are not the same thing.
[toc] | [prev] | [next] | [standalone]
| From | William Poaster <wp@dev.null> |
|---|---|
| Date | 2016-10-22 16:46 +0100 |
| Message-ID | <27esdd-jo5.ln1@debian.machineone.org> |
| In reply to | #377288 |
On 22/10/2016 15:07 in comp.os.linux.advocacy, Peter Köhlmann posted: > Snit Slimeshit wrote: > >> On 2016-10-22 9:48 AM, Peter Köhlmann wrote: >>> Snit Slimeshit wrote: >>> >>>> On 2016-10-22 8:33 AM, Marek Novotny wrote: >>>>> On 2016-10-22, Chris Ahlstrom <OFeem1987@teleworm.us> wrote: >>>>>> Peter Köhlmann wrote this copyrighted missive and expects royalties: >>>>>> >>>>>>> Well, when you posted it I *was* already informed. >>>>>>> Not only that, I got an update shortly before >>>>>>> Linux users generally don't need such a "service" from trolls like >>>>>>> you >>>>>> >>>>>> It's the usual dance. A long-time bug finally surfaces, we here a lot >>>>>> of corporate shills screeching about the DANGER DANGER DANGER, a lot >>>>>> of dismissing of the "many eyes" that ignores just how few serious >>>>>> bugs actually slip through the many-eyes gauntlet, the patches are >>>>>> quickly issued, and it is forgotten until the next major bug. >>>>> >>>>> And zero comment on the 5 Zero Days on Windows from just last week. >>>>> FIVE. So much for that proprietary software yielding good quality. LOL. >>>> >>>> No comments? Let me leave one. >>>> >>>> The 9 year-old Linux bug was actively exploited during that entire time >>> >>> Proof? *Any* at all? >>> Thought so >> >> I'll provide it, knowing that your dumb ass will ignore it either way: >> <http://arstechnica.com/security/2016/10/most-serious-linux-privilege-escalation-bug-ever-is-under-active-exploit/> >> >> First paragraph: "A serious vulnerability that has been present for nine >> years in virtually all versions of the Linux operating system >> is under *active exploit*, according to researchers who are advising >> users to install a patch as soon as possible." >> >>>> and allowed hackers to compromise a large number of systems along the >>>> way. >>> >>> Except it wasn't obviously a "large number" >>> "Allowing" and having "actually being exploited" are different things >> >> Previous paragraph, Peter the Klöwn. > > Well, you certainly will be able to point us to the place in that article > where it says that it is "activly being exploited the entire time", will > you? *Your* claim > > Thought so. You are just making things up as they come along. > A bug being present that time and a bug "being exploited the entire time" > are not the same thing. Nope, & *nowhere* in that article does it say anything about being "exploited the entire time". Slimeball the Drama Queen -- Windows and Mac machines are mostly used for emails, writing procedures, creating document and drawings and storing/accessing them in various databases. Some of those databases are used directly for operations - timelines, flight notes, chits, etc. Critical facilities - Mission Control, training facilities, etc. - tend to use Redhat so that they can get some customer support if needed. -- James Nevik, 20+ years working at Johnson Space Center --
[toc] | [prev] | [next] | [standalone]
| From | Silver Slimer <.m@nsn.s> |
|---|---|
| Date | 2016-10-23 09:04 -0400 |
| Message-ID | <nuicg2$rha$1@dont-email.me> |
| In reply to | #377297 |
On 2016-10-22 11:46 AM, William Poaster wrote: > On 22/10/2016 15:07 in comp.os.linux.advocacy, Peter Köhlmann posted: > >> Snit Slimeshit wrote: >> >>> On 2016-10-22 9:48 AM, Peter Köhlmann wrote: >>>> Snit Slimeshit wrote: >>>> >>>>> On 2016-10-22 8:33 AM, Marek Novotny wrote: >>>>>> On 2016-10-22, Chris Ahlstrom <OFeem1987@teleworm.us> wrote: >>>>>>> Peter Köhlmann wrote this copyrighted missive and expects royalties: >>>>>>> >>>>>>>> Well, when you posted it I *was* already informed. >>>>>>>> Not only that, I got an update shortly before >>>>>>>> Linux users generally don't need such a "service" from trolls like >>>>>>>> you >>>>>>> >>>>>>> It's the usual dance. A long-time bug finally surfaces, we here a lot >>>>>>> of corporate shills screeching about the DANGER DANGER DANGER, a lot >>>>>>> of dismissing of the "many eyes" that ignores just how few serious >>>>>>> bugs actually slip through the many-eyes gauntlet, the patches are >>>>>>> quickly issued, and it is forgotten until the next major bug. >>>>>> >>>>>> And zero comment on the 5 Zero Days on Windows from just last week. >>>>>> FIVE. So much for that proprietary software yielding good quality. LOL. >>>>> >>>>> No comments? Let me leave one. >>>>> >>>>> The 9 year-old Linux bug was actively exploited during that entire time >>>> >>>> Proof? *Any* at all? >>>> Thought so >>> >>> I'll provide it, knowing that your dumb ass will ignore it either way: >>> <http://arstechnica.com/security/2016/10/most-serious-linux-privilege-escalation-bug-ever-is-under-active-exploit/> >>> >>> First paragraph: "A serious vulnerability that has been present for nine >>> years in virtually all versions of the Linux operating system >>> is under *active exploit*, according to researchers who are advising >>> users to install a patch as soon as possible." >>> >>>>> and allowed hackers to compromise a large number of systems along the >>>>> way. >>>> >>>> Except it wasn't obviously a "large number" >>>> "Allowing" and having "actually being exploited" are different things >>> >>> Previous paragraph, Peter the Klöwn. >> >> Well, you certainly will be able to point us to the place in that article >> where it says that it is "activly being exploited the entire time", will >> you? *Your* claim >> >> Thought so. You are just making things up as they come along. >> A bug being present that time and a bug "being exploited the entire time" >> are not the same thing. > > Nope, & *nowhere* in that article does it say anything about > being "exploited the entire time". Slimeball the Drama Queen A +1 from Wideload Porkster? I'm shocked! -- Silver Slimer Islam is a disease Gab.ai: @silverslimer
[toc] | [prev] | [next] | [standalone]
| From | Silver Slimer <.m@nsn.s> |
|---|---|
| Date | 2016-10-22 14:34 -0400 |
| Message-ID | <nugbeb$5fl$2@dont-email.me> |
| In reply to | #377288 |
On 2016-10-22 10:07 AM, Peter Köhlmann wrote: > Snit Slimeshit wrote: > >> On 2016-10-22 9:48 AM, Peter Köhlmann wrote: >>> Snit Slimeshit wrote: >>> >>>> On 2016-10-22 8:33 AM, Marek Novotny wrote: >>>>> On 2016-10-22, Chris Ahlstrom <OFeem1987@teleworm.us> wrote: >>>>>> Peter Köhlmann wrote this copyrighted missive and expects royalties: >>>>>> >>>>>>> Well, when you posted it I *was* already informed. >>>>>>> Not only that, I got an update shortly before >>>>>>> Linux users generally don't need such a "service" from trolls like >>>>>>> you >>>>>> >>>>>> It's the usual dance. A long-time bug finally surfaces, we here a lot >>>>>> of corporate shills screeching about the DANGER DANGER DANGER, a lot >>>>>> of dismissing of the "many eyes" that ignores just how few serious >>>>>> bugs actually slip through the many-eyes gauntlet, the patches are >>>>>> quickly issued, and it is forgotten until the next major bug. >>>>> >>>>> And zero comment on the 5 Zero Days on Windows from just last week. >>>>> FIVE. So much for that proprietary software yielding good quality. LOL. >>>> >>>> No comments? Let me leave one. >>>> >>>> The 9 year-old Linux bug was actively exploited during that entire time >>> >>> Proof? *Any* at all? >>> Thought so >> >> I'll provide it, knowing that your dumb ass will ignore it either way: >> <http://arstechnica.com/security/2016/10/most-serious-linux-privilege-escalation-bug-ever-is-under-active-exploit/> >> >> First paragraph: "A serious vulnerability that has been present for nine >> years in virtually all versions of the Linux operating system >> is under *active exploit*, according to researchers who are advising >> users to install a patch as soon as possible." >> >>>> and allowed hackers to compromise a large number of systems along the >>>> way. >>> >>> Except it wasn't obviously a "large number" >>> "Allowing" and having "actually being exploited" are different things >> >> Previous paragraph, Peter the Klöwn. > > Well, you certainly will be able to point us to the place in that article > where it says that it is "activly being exploited the entire time", will > you? *Your* claim Apparently, you're too dumb to understand what "actively" means. > Thought so. You are just making things up as they come along. > A bug being present that time and a bug "being exploited the entire time" > are not the same thing. You truly are an idiot, Peter the Klöwn. I enjoy every time you move the goal posts to prevent yourself from admitting what kind of a fool you are. -- Silver Slimer Islam is a disease Gab.ai: @silverslimer
[toc] | [prev] | [next] | [standalone]
| From | -hh <recscuba_google@huntzinger.com> |
|---|---|
| Date | 2016-10-22 12:45 -0700 |
| Message-ID | <9a874daa-07dd-42e6-b0b4-5ce876a2ae54@googlegroups.com> |
| In reply to | #377288 |
Peter Köhlmann wrote: > Snit Slimeshit wrote: > > On 2016-10-22 9:48 AM, Peter Köhlmann wrote: > >> [...] > >>>> > >>>> And zero comment on the 5 Zero Days on Windows from just last week. > >>>> FIVE. So much for that proprietary software yielding good quality. LOL. > >>> > >>> No comments? Let me leave one. > >>> > >>> The 9 year-old Linux bug was actively exploited during that entire time > >> > >> Proof? *Any* at all? > >> Thought so > > > > I'll provide it, knowing that your dumb ass will ignore it either way: > > > > <http://arstechnica.com/security/2016/10/most-serious-linux-privilege-escalation-bug-ever-is-under-active-exploit/> > > > > First paragraph: "A serious vulnerability that has been present for nine > > years in virtually all versions of the Linux operating system > > is under *active exploit*, according to researchers who are advising > > users to install a patch as soon as possible." > > > >>> and allowed hackers to compromise a large number of systems along the > >>> way. > >> > >> Except it wasn't obviously a "large number" > >> "Allowing" and having "actually being exploited" are different things > > > > Previous paragraph, Peter the Klöwn. > > Well, you certainly will be able to point us to the place in that article > where it says that it is "activly being exploited the entire time", will > you? *Your* claim The paragraph does explicitly state that exploits in the wild were being found. Were they literally the "entire time"? No data in that citation to say one way or the other. Granted, the statement from 'Slimer' might have been literary hyperbola, or pragmatically close enough to being 100% true... ... but regardless of if it was 9 days, 9 weeks, 9 months or 9 years, the fact remains that the citation does unambiguously state that exploits do exist in the wild. And that there were exploits does make this materially different than MS plugging some zero days where there's no smoking gun evidence that any of them were, or had ever been, exploited. > Thought so. You are just making things up as they come along. A > bug being present that time and a bug "being exploited the entire time" > are not the same thing. No, they're not -- and yet the citation did clearly say that the bug was confirmed as being exploited. Can't say for how long, but if one were to randomize it, the initial estimate would have been for the past ~5 years. -hh
[toc] | [prev] | [next] | [standalone]
| From | Steve Carroll <frelwizzen@gmail.com> |
|---|---|
| Date | 2016-10-22 12:10 -0700 |
| Message-ID | <c75d6fdb-402d-41a8-827f-96c93de65710@googlegroups.com> |
| In reply to | #377285 |
On Saturday, October 22, 2016 at 7:02:19 AM UTC-7, Silver Slimer wrote: > >> No comments? Let me leave one. > >> > >> The 9 year-old Linux bug was actively exploited during that entire time > > > > Proof? *Any* at all? > > Thought so > > I'll provide it, knowing that your dumb ass will ignore it either way: > <http://arstechnica.com/security/2016/10/most-serious-linux-privilege-escalation-bug-ever-is-under-active-exploit/> > > First paragraph: "A serious vulnerability that has been present for nine > years in virtually all versions of the Linux operating system > is under *active exploit*, according to researchers who are advising > users to install a patch as soon as possible." For your next trick, Snit, you can explain the difference between "is under" and "had been under". Your lack of reading comprehension gives you away every time.
[toc] | [prev] | [next] | [standalone]
| From | William Poaster <wp@dev.null> |
|---|---|
| Date | 2016-10-21 23:05 +0100 |
| Message-ID | <p1gqdd-lj1.ln1@debian.machineone.org> |
| In reply to | #377226 |
On 21/10/2016 22:23 in comp.os.linux.advocacy, Marek Novotny posted: > On 2016-10-21, Peter Köhlmann <peter-koehlmann@t-online.de> wrote: >> Jim Polaski wrote: >> >>> On 2016-10-21, Melzzzzz <mel@zzzzz.com> wrote: >>>> On Fri, 21 Oct 2016 17:49:06 +0200 >>>> Peter Köhlmann <peter-koehlmann@t-online.de> wrote: >>>> >>>>> Jim Polaski wrote: >>>>> >>>>> > http://arstechnica.com/security/2016/10/most-serious-linux-privilege-escalation-bug-ever-is-under-active-exploit/#p3 >>>>> > >>>>> > "Lurking in the kernel for nine years, flaw gives untrusted users >>>>> > unfettered root access." >>>>> > >>>>> > >>>>> >>>>> >>>>> It is a bad one. But only for server machines, not desktop >>>> >>>> It is 90% of work on Unix to overtake machine is to gain shell access... >>>> It was 15 years ago, I guess it is now true as well... >>> >>> Point is it took the many eyes 9 years to discover this exploit. >>> Not a good advertisement for the many eyes theory. >> >> It *was* discovered 9 years ago. Linux Torvalds himself patched it, but he >> did not do a good job according to himself. His patch was later removed and >> reverted to the original state > > I have to wonder if Jim made this much stink over the 5 zero days > Microsoft had to patch a week ago... > > https://threatpost.com/microsoft-patches-five-zero-days-under-attack/121211/ I doubt that he did. -- What IS remarkable, is that a well developed ape has come to realise that he lives on a planet, circling a sun, in a planetary system, within a galaxy, within a universe. - Professor Michio Kaku - Theoretical Physicist -
[toc] | [prev] | [next] | [standalone]
| From | Marek Novotny <marek.novotny@marspolar.com> |
|---|---|
| Date | 2016-10-21 18:09 -0400 |
| Message-ID | <mrudnWHnDomuD5fFnZ2dnUU7-UWdnZ2d@giganews.com> |
| In reply to | #377228 |
On 2016-10-21, William Poaster <wp@dev.null> wrote: > On 21/10/2016 22:23 in comp.os.linux.advocacy, Marek Novotny posted: > >> On 2016-10-21, Peter Köhlmann <peter-koehlmann@t-online.de> wrote: >>> Jim Polaski wrote: >>> >>>> On 2016-10-21, Melzzzzz <mel@zzzzz.com> wrote: >>>>> On Fri, 21 Oct 2016 17:49:06 +0200 >>>>> Peter Köhlmann <peter-koehlmann@t-online.de> wrote: >>>>> >>>>>> Jim Polaski wrote: >>>>>> >>>>>> > http://arstechnica.com/security/2016/10/most-serious-linux-privilege-escalation-bug-ever-is-under-active-exploit/#p3 >>>>>> > >>>>>> > "Lurking in the kernel for nine years, flaw gives untrusted users >>>>>> > unfettered root access." >>>>>> > >>>>>> > >>>>>> >>>>>> >>>>>> It is a bad one. But only for server machines, not desktop >>>>> >>>>> It is 90% of work on Unix to overtake machine is to gain shell access... >>>>> It was 15 years ago, I guess it is now true as well... >>>> >>>> Point is it took the many eyes 9 years to discover this exploit. >>>> Not a good advertisement for the many eyes theory. >>> >>> It *was* discovered 9 years ago. Linux Torvalds himself patched it, but he >>> did not do a good job according to himself. His patch was later removed and >>> reverted to the original state >> >> I have to wonder if Jim made this much stink over the 5 zero days >> Microsoft had to patch a week ago... >> >> https://threatpost.com/microsoft-patches-five-zero-days-under-attack/121211/ > > I doubt that he did. I wonder why that is... -- Marek Novotny https://github.com/marek-novotny
[toc] | [prev] | [next] | [standalone]
| From | -hh <recscuba_google@huntzinger.com> |
|---|---|
| Date | 2016-10-22 04:35 -0700 |
| Message-ID | <c1c08ed3-5c34-4378-9b16-42d140c9857a@googlegroups.com> |
| In reply to | #377157 |
Peter wrote: > It is a bad one. But only for server machines, not desktop As if Linux has any appreciable market share in "desktop", particularly since desktop market share discussions on COLA invariably get servers & supercomputers cited to try to claim that Linux hasn't been a failure. Good news that it has been patched, but it's history does illustrate, unfortunately, that the open source many eyes approach isn't the magical panacea for quality that it is often claimed by some of its fanboys. Basic lesson is that shit happens in every human endeavor process...something that's whacking Samsung this month too. -hh
[toc] | [prev] | [next] | [standalone]
| From | Silver Slimer <.m@nsn.s> |
|---|---|
| Date | 2016-10-21 11:50 -0400 |
| Message-ID | <nudden$iqk$1@dont-email.me> |
| In reply to | #377146 |
On 2016-10-21 10:25 AM, Jim Polaski wrote: > http://arstechnica.com/security/2016/10/most-serious-linux-privilege-escalation-bug-ever-is-under-active-exploit/#p3 > > "Lurking in the kernel for nine years, flaw gives untrusted users > unfettered root access." > > > "The in-the-wild attacks exploiting this specific vulnerability were > found by Linux developer Phil Oester, according to an informational site > dedicated to the vulnerability. It says Oester found the exploit using > an HTTP packet capture, but the site doesn't elaborate. Update: In > e-mails received about nine hours after this post went live, Oester > wrote: > > Any user can become root in < 5 seconds in my testing, very > reliably. Scary stuff. > > The vulnerability is easiest exploited with local access to a system > such as shell accounts. Less trivially, any web server/application > vulnerability which allows the attacker to upload a file to the impacted > system and execute it also works. > > The particular exploit which was uploaded to my system was compiled > with GCC 4.8.5 released 20150623, though this should not imply that the > vulnerability was not available earlier than that date given its > longevity. As to who is being targeted, anyone running Linux on a web > facing server is vulnerable. " The many eyes of the Linux community failed again. They were probably too busy masturbating to the thought of Wretched Stallman covering his nude body in barbecue sauce. -- Silver Slimer Islam is a disease Gab.ai: @silverslimer
[toc] | [prev] | [next] | [standalone]
| From | Jim Polaski <jpolaski@linuxmail.org> |
|---|---|
| Date | 2016-10-21 15:56 +0000 |
| Message-ID | <e6us4gFdl31U1@mid.individual.net> |
| In reply to | #377158 |
On 2016-10-21, Silver Slimer <> wrote: > On 2016-10-21 10:25 AM, Jim Polaski wrote: >> http://arstechnica.com/security/2016/10/most-serious-linux-privilege-escalation-bug-ever-is-under-active-exploit/#p3 >> >> "Lurking in the kernel for nine years, flaw gives untrusted users >> unfettered root access." >> >> >> "The in-the-wild attacks exploiting this specific vulnerability were >> found by Linux developer Phil Oester, according to an informational site >> dedicated to the vulnerability. It says Oester found the exploit using >> an HTTP packet capture, but the site doesn't elaborate. Update: In >> e-mails received about nine hours after this post went live, Oester >> wrote: >> >> Any user can become root in < 5 seconds in my testing, very >> reliably. Scary stuff. >> >> The vulnerability is easiest exploited with local access to a system >> such as shell accounts. Less trivially, any web server/application >> vulnerability which allows the attacker to upload a file to the impacted >> system and execute it also works. >> >> The particular exploit which was uploaded to my system was compiled >> with GCC 4.8.5 released 20150623, though this should not imply that the >> vulnerability was not available earlier than that date given its >> longevity. As to who is being targeted, anyone running Linux on a web >> facing server is vulnerable. " > > The many eyes of the Linux community failed again. They were probably > too busy masturbating to the thought of Wretched Stallman covering his > nude body in barbecue sauce. You fucking ruined my lunch with that one!! That disgusting slob is hideous. I'll bet the hookers he hires charge him combat pay because he is so repulsive.
[toc] | [prev] | [next] | [standalone]
| From | Silver Slimer <.m@nsn.s> |
|---|---|
| Date | 2016-10-21 12:46 -0400 |
| Message-ID | <nudgnj$uos$2@dont-email.me> |
| In reply to | #377161 |
On 2016-10-21 11:56 AM, Jim Polaski wrote: > On 2016-10-21, Silver Slimer <> wrote: >> On 2016-10-21 10:25 AM, Jim Polaski wrote: >>> http://arstechnica.com/security/2016/10/most-serious-linux-privilege-escalation-bug-ever-is-under-active-exploit/#p3 >>> >>> "Lurking in the kernel for nine years, flaw gives untrusted users >>> unfettered root access." >>> >>> >>> "The in-the-wild attacks exploiting this specific vulnerability were >>> found by Linux developer Phil Oester, according to an informational site >>> dedicated to the vulnerability. It says Oester found the exploit using >>> an HTTP packet capture, but the site doesn't elaborate. Update: In >>> e-mails received about nine hours after this post went live, Oester >>> wrote: >>> >>> Any user can become root in < 5 seconds in my testing, very >>> reliably. Scary stuff. >>> >>> The vulnerability is easiest exploited with local access to a system >>> such as shell accounts. Less trivially, any web server/application >>> vulnerability which allows the attacker to upload a file to the impacted >>> system and execute it also works. >>> >>> The particular exploit which was uploaded to my system was compiled >>> with GCC 4.8.5 released 20150623, though this should not imply that the >>> vulnerability was not available earlier than that date given its >>> longevity. As to who is being targeted, anyone running Linux on a web >>> facing server is vulnerable. " >> >> The many eyes of the Linux community failed again. They were probably >> too busy masturbating to the thought of Wretched Stallman covering his >> nude body in barbecue sauce. > > You fucking ruined my lunch with that one!! > That disgusting slob is hideous. > I'll bet the hookers he hires charge him combat pay because he is so > repulsive. He doesn't hire hookers because they aren't open-source. He only sleeps with the bodies of women that have been opened up and examined by "many eyes." -- Silver Slimer Islam is a disease Gab.ai: @silverslimer
[toc] | [prev] | [next] | [standalone]
| From | Jim Polaski <jpolaski@linuxmail.org> |
|---|---|
| Date | 2016-10-21 20:16 +0000 |
| Message-ID | <e6vbc6Fh70cU3@mid.individual.net> |
| In reply to | #377177 |
On 2016-10-21, Silver Slimer <> wrote: > On 2016-10-21 11:56 AM, Jim Polaski wrote: >> On 2016-10-21, Silver Slimer <> wrote: >>> On 2016-10-21 10:25 AM, Jim Polaski wrote: >>>> http://arstechnica.com/security/2016/10/most-serious-linux-privilege-escalation-bug-ever-is-under-active-exploit/#p3 >>>> >>>> "Lurking in the kernel for nine years, flaw gives untrusted users >>>> unfettered root access." >>>> >>>> >>>> "The in-the-wild attacks exploiting this specific vulnerability were >>>> found by Linux developer Phil Oester, according to an informational site >>>> dedicated to the vulnerability. It says Oester found the exploit using >>>> an HTTP packet capture, but the site doesn't elaborate. Update: In >>>> e-mails received about nine hours after this post went live, Oester >>>> wrote: >>>> >>>> Any user can become root in < 5 seconds in my testing, very >>>> reliably. Scary stuff. >>>> >>>> The vulnerability is easiest exploited with local access to a system >>>> such as shell accounts. Less trivially, any web server/application >>>> vulnerability which allows the attacker to upload a file to the impacted >>>> system and execute it also works. >>>> >>>> The particular exploit which was uploaded to my system was compiled >>>> with GCC 4.8.5 released 20150623, though this should not imply that the >>>> vulnerability was not available earlier than that date given its >>>> longevity. As to who is being targeted, anyone running Linux on a web >>>> facing server is vulnerable. " >>> >>> The many eyes of the Linux community failed again. They were probably >>> too busy masturbating to the thought of Wretched Stallman covering his >>> nude body in barbecue sauce. >> >> You fucking ruined my lunch with that one!! >> That disgusting slob is hideous. >> I'll bet the hookers he hires charge him combat pay because he is so >> repulsive. > > He doesn't hire hookers because they aren't open-source. He only sleeps > with the bodies of women that have been opened up and examined by "many > eyes." Sounds like a doctor I used to know. He and his wife were swingers. The scuttle butt around the hospital was that he whored his good looking wife out for gang bangs where anonymous men would fuck her without a condom and after the multiple men, like 20+ or more, were done with her, he would clean her out with his tongue and then be the last to fuck her. Word got around the hospital and he was fired. It was too bad because aside from his strange hobby, he was an excellent doctor. Go figure.
[toc] | [prev] | [next] | [standalone]
| From | Silver Slimer <.m@nsn.s> |
|---|---|
| Date | 2016-10-21 18:30 -0400 |
| Message-ID | <nue4sr$9dh$2@dont-email.me> |
| In reply to | #377207 |
On 2016-10-21 4:16 PM, Jim Polaski wrote: > On 2016-10-21, Silver Slimer <> wrote: >> On 2016-10-21 11:56 AM, Jim Polaski wrote: >>> On 2016-10-21, Silver Slimer <> wrote: >>>> On 2016-10-21 10:25 AM, Jim Polaski wrote: >>>>> http://arstechnica.com/security/2016/10/most-serious-linux-privilege-escalation-bug-ever-is-under-active-exploit/#p3 >>>>> >>>>> "Lurking in the kernel for nine years, flaw gives untrusted users >>>>> unfettered root access." >>>>> >>>>> >>>>> "The in-the-wild attacks exploiting this specific vulnerability were >>>>> found by Linux developer Phil Oester, according to an informational site >>>>> dedicated to the vulnerability. It says Oester found the exploit using >>>>> an HTTP packet capture, but the site doesn't elaborate. Update: In >>>>> e-mails received about nine hours after this post went live, Oester >>>>> wrote: >>>>> >>>>> Any user can become root in < 5 seconds in my testing, very >>>>> reliably. Scary stuff. >>>>> >>>>> The vulnerability is easiest exploited with local access to a system >>>>> such as shell accounts. Less trivially, any web server/application >>>>> vulnerability which allows the attacker to upload a file to the impacted >>>>> system and execute it also works. >>>>> >>>>> The particular exploit which was uploaded to my system was compiled >>>>> with GCC 4.8.5 released 20150623, though this should not imply that the >>>>> vulnerability was not available earlier than that date given its >>>>> longevity. As to who is being targeted, anyone running Linux on a web >>>>> facing server is vulnerable. " >>>> >>>> The many eyes of the Linux community failed again. They were probably >>>> too busy masturbating to the thought of Wretched Stallman covering his >>>> nude body in barbecue sauce. >>> >>> You fucking ruined my lunch with that one!! >>> That disgusting slob is hideous. >>> I'll bet the hookers he hires charge him combat pay because he is so >>> repulsive. >> >> He doesn't hire hookers because they aren't open-source. He only sleeps >> with the bodies of women that have been opened up and examined by "many >> eyes." > > Sounds like a doctor I used to know. He and his wife were swingers. The > scuttle butt around the hospital was that he whored his good looking > wife out for gang bangs where anonymous men would fuck her without a > condom and after the multiple men, like 20+ or more, were done with her, > he would clean her out with his tongue and then be the last to fuck her. > > Word got around the hospital and he was fired. > It was too bad because aside from his strange hobby, he was an excellent > doctor. > > Go figure. I can't imagine how a guy can be turned on watching his wife be treated like an object. That's pretty disgusting to say the least. -- Silver Slimer Islam is a disease Gab.ai: @silverslimer
[toc] | [prev] | [next] | [standalone]
| From | Jim Polaski <jpolaski@linuxmail.org> |
|---|---|
| Date | 2016-10-21 22:54 +0000 |
| Message-ID | <e6vkl9FjbotU1@mid.individual.net> |
| In reply to | #377234 |
On 2016-10-21, Silver Slimer <> wrote: > On 2016-10-21 4:16 PM, Jim Polaski wrote: >> On 2016-10-21, Silver Slimer <> wrote: >>> On 2016-10-21 11:56 AM, Jim Polaski wrote: >>>> On 2016-10-21, Silver Slimer <> wrote: >>>>> On 2016-10-21 10:25 AM, Jim Polaski wrote: >>>>>> http://arstechnica.com/security/2016/10/most-serious-linux-privilege-escalation-bug-ever-is-under-active-exploit/#p3 >>>>>> >>>>>> "Lurking in the kernel for nine years, flaw gives untrusted users >>>>>> unfettered root access." >>>>>> >>>>>> >>>>>> "The in-the-wild attacks exploiting this specific vulnerability were >>>>>> found by Linux developer Phil Oester, according to an informational site >>>>>> dedicated to the vulnerability. It says Oester found the exploit using >>>>>> an HTTP packet capture, but the site doesn't elaborate. Update: In >>>>>> e-mails received about nine hours after this post went live, Oester >>>>>> wrote: >>>>>> >>>>>> Any user can become root in < 5 seconds in my testing, very >>>>>> reliably. Scary stuff. >>>>>> >>>>>> The vulnerability is easiest exploited with local access to a system >>>>>> such as shell accounts. Less trivially, any web server/application >>>>>> vulnerability which allows the attacker to upload a file to the impacted >>>>>> system and execute it also works. >>>>>> >>>>>> The particular exploit which was uploaded to my system was compiled >>>>>> with GCC 4.8.5 released 20150623, though this should not imply that the >>>>>> vulnerability was not available earlier than that date given its >>>>>> longevity. As to who is being targeted, anyone running Linux on a web >>>>>> facing server is vulnerable. " >>>>> >>>>> The many eyes of the Linux community failed again. They were probably >>>>> too busy masturbating to the thought of Wretched Stallman covering his >>>>> nude body in barbecue sauce. >>>> >>>> You fucking ruined my lunch with that one!! >>>> That disgusting slob is hideous. >>>> I'll bet the hookers he hires charge him combat pay because he is so >>>> repulsive. >>> >>> He doesn't hire hookers because they aren't open-source. He only sleeps >>> with the bodies of women that have been opened up and examined by "many >>> eyes." >> >> Sounds like a doctor I used to know. He and his wife were swingers. The >> scuttle butt around the hospital was that he whored his good looking >> wife out for gang bangs where anonymous men would fuck her without a >> condom and after the multiple men, like 20+ or more, were done with her, >> he would clean her out with his tongue and then be the last to fuck her. >> >> Word got around the hospital and he was fired. >> It was too bad because aside from his strange hobby, he was an excellent >> doctor. >> >> Go figure. > > I can't imagine how a guy can be turned on watching his wife be treated > like an object. That's pretty disgusting to say the least. Me either but this was a thing both of them were into so I say whatever floats your boat.
[toc] | [prev] | [next] | [standalone]
| From | Jim Polaski <jpolaski@linuxmail.org> |
|---|---|
| Date | 2016-10-21 16:10 +0000 |
| Message-ID | <e6usvlFdl31U2@mid.individual.net> |
| In reply to | #377158 |
On 2016-10-21, Silver Slimer <> wrote: > On 2016-10-21 10:25 AM, Jim Polaski wrote: >> http://arstechnica.com/security/2016/10/most-serious-linux-privilege-escalation-bug-ever-is-under-active-exploit/#p3 >> >> "Lurking in the kernel for nine years, flaw gives untrusted users >> unfettered root access." >> >> >> "The in-the-wild attacks exploiting this specific vulnerability were >> found by Linux developer Phil Oester, according to an informational site >> dedicated to the vulnerability. It says Oester found the exploit using >> an HTTP packet capture, but the site doesn't elaborate. Update: In >> e-mails received about nine hours after this post went live, Oester >> wrote: >> >> Any user can become root in < 5 seconds in my testing, very >> reliably. Scary stuff. >> >> The vulnerability is easiest exploited with local access to a system >> such as shell accounts. Less trivially, any web server/application >> vulnerability which allows the attacker to upload a file to the impacted >> system and execute it also works. >> >> The particular exploit which was uploaded to my system was compiled >> with GCC 4.8.5 released 20150623, though this should not imply that the >> vulnerability was not available earlier than that date given its >> longevity. As to who is being targeted, anyone running Linux on a web >> facing server is vulnerable. " > > The many eyes of the Linux community failed again. They were probably > too busy masturbating to the thought of Wretched Stallman covering his > nude body in barbecue sauce. It took 9 years for those many eyes to discover the security problem. And when you think about it, the brightest and best of the Linux community are the ones working on the kernel, it only goes downhill from there regarding other parts of Linux.
[toc] | [prev] | [next] | [standalone]
| From | tmelmosfire <tmelmosfire@gmail.com> |
|---|---|
| Date | 2016-10-21 09:34 -0700 |
| Message-ID | <3e08d715-349f-438b-973a-5cf9da6c5377@googlegroups.com> |
| In reply to | #377164 |
On Friday, 21 October 2016 09:10:32 UTC-7, Jim Polaski wrote: > > The many eyes of the Linux community failed again. They were probably > > too busy masturbating to the thought of Wretched Stallman covering his > > nude body in barbecue sauce. > > It took 9 years for those many eyes to discover the security problem. > And when you think about it, the brightest and best of the Linux > community are the ones working on the kernel, it only goes downhill from > there regarding other parts of Linux. Twenty years and many eyes and not a single cult member can show KDE being of value.
[toc] | [prev] | [next] | [standalone]
| From | Melzzzzz <mel@zzzzz.com> |
|---|---|
| Date | 2016-10-21 22:43 +0200 |
| Message-ID | <20161021224302.7f8c8e62@maxa-pc.cpe.bvcom.net> |
| In reply to | #377164 |
On 21 Oct 2016 16:10:29 GMT Jim Polaski <jpolaski@linuxmail.org> wrote: Hi flatfish. -- press any key to continue or any other to quit
[toc] | [prev] | [next] | [standalone]
| From | Jim Polaski <jpolaski@linuxmail.org> |
|---|---|
| Date | 2016-10-21 20:45 +0000 |
| Message-ID | <e6vd3uFhlunU1@mid.individual.net> |
| In reply to | #377212 |
On 2016-10-21, Melzzzzz <mel@zzzzz.com> wrote: > On 21 Oct 2016 16:10:29 GMT > Jim Polaski <jpolaski@linuxmail.org> wrote: > > > Hi flatfish. Sorry but you are wrong. Very wrong. Of course that won't prevent the COLA Cabal from jumping on the bandwagon even though your statement has no factual basis. It's the way the COLA Linux Cabal works.
[toc] | [prev] | [next] | [standalone]
| From | Melzzzzz <mel@zzzzz.com> |
|---|---|
| Date | 2016-10-21 22:47 +0200 |
| Message-ID | <20161021224731.2db9309f@maxa-pc.cpe.bvcom.net> |
| In reply to | #377214 |
On 21 Oct 2016 20:45:50 GMT Jim Polaski <jpolaski@linuxmail.org> wrote: > On 2016-10-21, Melzzzzz <mel@zzzzz.com> wrote: > > On 21 Oct 2016 16:10:29 GMT > > Jim Polaski <jpolaski@linuxmail.org> wrote: > > > > > > Hi flatfish. > > Sorry but you are wrong. > Very wrong. > Of course that won't prevent the COLA Cabal from jumping on the > bandwagon even though your statement has no factual basis. > It's the way the COLA Linux Cabal works. > Ok, I'll call you Jim then, but don't change nick. Enough time as Jim and you will be Jim... -- press any key to continue or any other to quit
[toc] | [prev] | [next] | [standalone]
Page 2 of 3 — ← Prev page 1 [2] 3 Next page →
Back to top | Article view | comp.os.linux.advocacy
csiph-web