Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #244606 > unrolled thread

Security

Started byPolyna-Maude Racicot-Summerside <debian@polynamaude.com>
First post2022-01-25 21:10 +0100
Last post2022-01-28 17:30 +0100
Articles 3 on this page of 23 — 10 participants

Back to article view | Back to linux.debian.user


Contents

  Security Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2022-01-25 21:10 +0100
    Re: Security Andy Smith <andy@strugglers.net> - 2022-01-25 21:50 +0100
      Re: Security Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2022-01-25 22:00 +0100
        Re: Security Nicholas Geovanis <nickgeovanis@gmail.com> - 2022-01-26 16:40 +0100
    Re: Security Nate Bargmann <n0nb@n0nb.us> - 2022-01-25 23:20 +0100
      Re: Security Andrei POPESCU <andreimpopescu@gmail.com> - 2022-01-26 19:40 +0100
        Re: Security Nicholas Geovanis <nickgeovanis@gmail.com> - 2022-01-28 04:50 +0100
          Re: Security Dan Ritter <dsr@randomstring.org> - 2022-01-28 14:20 +0100
            Re: Security Nicholas Geovanis <nickgeovanis@gmail.com> - 2022-01-28 17:20 +0100
              Re: Security Dan Ritter <dsr@randomstring.org> - 2022-01-28 19:00 +0100
          Re: Security Vincent Lefevre <vincent@vinc17.net> - 2022-01-28 16:20 +0100
            Re: Security Nicholas Geovanis <nickgeovanis@gmail.com> - 2022-01-28 17:30 +0100
            Re: Security Richard Hector <richard@walnut.gen.nz> - 2022-01-30 13:40 +0100
              Re: Security Reco <recoverym4n@enotuniq.net> - 2022-01-30 14:20 +0100
                Re: Security Andrei POPESCU <andreimpopescu@gmail.com> - 2022-01-30 14:40 +0100
                  Re: Security Reco <recoverym4n@enotuniq.net> - 2022-01-30 17:50 +0100
                    Re: Security Andrei POPESCU <andreimpopescu@gmail.com> - 2022-02-04 09:50 +0100
                      Re: Security Reco <recoverym4n@enotuniq.net> - 2022-02-04 10:20 +0100
                      Re: Security <tomas@tuxteam.de> - 2022-02-04 10:20 +0100
              Re: Security Vincent Lefevre <vincent@vinc17.net> - 2022-02-01 12:30 +0100
                Re: Security Richard Hector <richard@walnut.gen.nz> - 2022-02-02 02:00 +0100
                  Re: Security Vincent Lefevre <vincent@vinc17.net> - 2022-02-02 15:10 +0100
          Re: Security Andrei POPESCU <andreimpopescu@gmail.com> - 2022-01-28 17:30 +0100

Page 2 of 2 — ← Prev page 1 [2]


#244940

FromRichard Hector <richard@walnut.gen.nz>
Date2022-02-02 02:00 +0100
Message-ID<DMca5-7zr-1@gated-at.bofh.it>
In reply to#244904
On 2/02/22 00:26, Vincent Lefevre wrote:
> On 2022-01-31 01:36:06 +1300, Richard Hector wrote:
>> On 29/01/22 04:17, Vincent Lefevre wrote:
>> > Servers shouldn't have pkexec installed in the first place, anyway.
>> 
>> libvirt-daemon-system depends on policykit-1.
>> 
>> Should that not be on my (kvm) server either?
> 
> I don't need libvirt-daemon-system on my server. And I don't see
> why it would be needed in general. If I understand correctly,
> libvirt is used to manage VMs, but what is mostly exposed on the
> Internet (e.g. as a web server) is the VM itself, which doesn't
> need libvirt.

I guess it depends how you define a 'server'. I include the machine that 
hosts my VMs. And I certainly don't restrict it to what's exposed on the 
Internet.

I admit I haven't explored in depth exactly which bits of libvirt are 
required on the VM host; I rely to some extent on the recommendations in 
the packages.

Cheers,
Richard

[toc] | [prev] | [next] | [standalone]


#244953

FromVincent Lefevre <vincent@vinc17.net>
Date2022-02-02 15:10 +0100
Message-ID<DMouB-73E-5@gated-at.bofh.it>
In reply to#244940
On 2022-02-02 13:59:07 +1300, Richard Hector wrote:
> On 2/02/22 00:26, Vincent Lefevre wrote:
> > On 2022-01-31 01:36:06 +1300, Richard Hector wrote:
> > > On 29/01/22 04:17, Vincent Lefevre wrote:
> > > > Servers shouldn't have pkexec installed in the first place, anyway.
> > > 
> > > libvirt-daemon-system depends on policykit-1.
> > > 
> > > Should that not be on my (kvm) server either?
> > 
> > I don't need libvirt-daemon-system on my server. And I don't see
> > why it would be needed in general. If I understand correctly,
> > libvirt is used to manage VMs, but what is mostly exposed on the
> > Internet (e.g. as a web server) is the VM itself, which doesn't
> > need libvirt.
> 
> I guess it depends how you define a 'server'. I include the machine that
> hosts my VMs. And I certainly don't restrict it to what's exposed on the
> Internet.

I suppose that such a host runs a limited number of services, e.g.
it is not used as a webserver.

-- 
Vincent Lefèvre <vincent@vinc17.net> - Web: <https://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)

[toc] | [prev] | [next] | [standalone]


#244732

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2022-01-28 17:30 +0100
Message-ID<DKCim-7fX-15@gated-at.bofh.it>
In reply to#244705

[Multipart message — attachments visible in raw view] — view raw

On Jo, 27 ian 22, 21:44:07, Nicholas Geovanis wrote:
> On Wed, Jan 26, 2022, 12:39 PM Andrei POPESCU <andreimpopescu@gmail.com>
> >
> > And please don't bother to reply with "there are no other users on this
> > system I should worry about", the bad guys could still find ways to get
> > in, e.g. via a compromised browser, regardless if you are behind a
> > firewall or not[1].
> 
> Servers don't have browsers installed on them, for exactly this reason.

(already addressed by Vincent)
 
> I think your argument above that is a red herring. Because file attribute
> modification detection should be running regularly. On home machines as
> well as servers. Without that, "keeping the system up-to-date" will not
> prevent intrusion.

I'm missing the connection between this vulnerability and file attribute 
modification detection, please elaborate.

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [standalone]


Page 2 of 2 — ← Prev page 1 [2]

Back to top | Article view | linux.debian.user


csiph-web