Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #210166

Re: Exim latest update reports to world as 4.89, which the world thinks is vulnerable.

From Brian <ad44@cityscape.co.uk>
Newsgroups linux.debian.user
Subject Re: Exim latest update reports to world as 4.89, which the world thinks is vulnerable.
Date 2019-06-20 21:50 +0200
Message-ID <ybbei-2EX-11@gated-at.bofh.it> (permalink)
References <yb5iy-7ue-1@gated-at.bofh.it> <yb5Lz-7F3-5@gated-at.bofh.it> <yb9Pb-1U7-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Fri 21 Jun 2019 at 04:15:35 +1000, Andrew McGlashan wrote:

> On 20/6/19 11:57 pm, Brian wrote:
> > On Thu 20 Jun 2019 at 23:26:08 +1000, Andrew McGlashan wrote:
> > 
> >> # dpkg-query -l|grep \ exim|awk '{print $2,$3}'|column -t exim4
> >> 4.89-2+deb9u4 exim4-base          4.89-2+deb9u4 exim4-config
> >> 4.89-2+deb9u4 exim4-daemon-heavy  4.89-2+deb9u4 exim4-doc-html
> >> 4.89-1
> >> 
> >> Is there a way to provide version of "4.92" easily or some other
> >> text to stop the likelihood of outsiders trying to pound on and
> >> exploit the server? Even though they won't be able to do
> >> successfully due to up to date patch status.
> > 
> > You really, really think changing a version number increases or 
> > decreases the likelihood of automated server probes happening?
> 
> Yes, if "candidates" are chosen and then advertised to bots to go and
> do the work, instead of doing the work against any and every server,
> for sure.  If this was a quick and simple exploit, the answer would be
> no, but this exploit takes considerable time before a result is known
> or attained from the attempt.

At least 2000,000,0000 hosts on the internet. You reckon you will be in
the first tranche of targets? That's apart from the completely inept and
unintelligent type of exploitation attack that is run.
> 
> > Doesn't doing this qualify as security through obscurity?
> 
> Yes, but sometimes that simply works.

How can it? As you say

 > Even though they won't be able to do successfully due to up to 
 > date patch status.

You acknowledge your mail server is safe. Are you in the business of
serving up FUD in spite of your updating and declaring the server to
be protected against this particular bug?

By all means alter smtp_banner. Much good will it do.

-- 
Brian.

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Exim latest update reports to world as 4.89, which the world thinks  is vulnerable. Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2019-06-20 15:30 +0200
  Re: Exim latest update reports to world as 4.89, which the world  thinks is vulnerable. Greg Wooledge <wooledg@eeg.ccf.org> - 2019-06-20 15:50 +0200
  Re: Exim latest update reports to world as 4.89, which the world  thinks is vulnerable. Reco <recoverym4n@enotuniq.net> - 2019-06-20 15:50 +0200
    Re: Exim latest update reports to world as 4.89, which the world  thinks is vulnerable. Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2019-06-20 20:50 +0200
      Re: Exim latest update reports to world as 4.89, which the world  thinks is vulnerable. Reco <recoverym4n@enotuniq.net> - 2019-06-20 21:00 +0200
        Re: Exim latest update reports to world as 4.89, which the world  thinks is vulnerable. Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2019-06-20 21:50 +0200
          Re: Exim latest update reports to world as 4.89, which the world  thinks is vulnerable. Reco <recoverym4n@enotuniq.net> - 2019-06-20 22:00 +0200
            Re: Exim latest update reports to world as 4.89, which the world  thinks is vulnerable. Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2019-06-20 22:40 +0200
              Re: Exim latest update reports to world as 4.89, which the world  thinks is vulnerable. Brian <ad44@cityscape.co.uk> - 2019-06-21 00:00 +0200
                Re: Exim latest update reports to world as 4.89, which the world  thinks is vulnerable. Michael Stone <mstone@debian.org> - 2019-06-21 00:00 +0200
              Re: Exim latest update reports to world as 4.89, which the world  thinks is vulnerable. Reco <recoverym4n@enotuniq.net> - 2019-06-21 08:10 +0200
                Re: Exim latest update reports to world as 4.89, which the world  thinks is vulnerable. Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2019-06-21 13:20 +0200
                Re: Exim latest update reports to world as 4.89, which the world  thinks is vulnerable. Brian <ad44@cityscape.co.uk> - 2019-06-21 21:00 +0200
  Re: Exim latest update reports to world as 4.89, which the world  thinks is vulnerable. Brian <ad44@cityscape.co.uk> - 2019-06-20 16:00 +0200
    Re: Exim latest update reports to world as 4.89, which the world  thinks is vulnerable. Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2019-06-20 20:20 +0200
      Re: Exim latest update reports to world as 4.89, which the world  thinks is vulnerable. Brian <ad44@cityscape.co.uk> - 2019-06-20 21:50 +0200
        Re: Exim latest update reports to world as 4.89, which the world  thinks is vulnerable. Andy Smith <andy@strugglers.net> - 2019-06-22 21:10 +0200

csiph-web