create account

RE: The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems by full-steem-ahead

View this thread on: hive.blogpeakd.comecency.com

Viewing a response to: @robrigo/the-stack-clash-patch-this-critical-vulnerability-affecting-all-linux-operating-systems

· @full-steem-ahead ·
$5.85
I want to emphasize this is only an issue if an attacker manages to gain login access to your system. Although I totally agree this vulnerability should be given a high priority & fixed by applying the appropriate patches, it would be more concerning to learn login access to my systems were possible that are a prerequisite for the "stack-clash" exploit to be performed.

Additionally it may take a few days for your distro to provide the patch for your OS version. 

Let this be a wakeup call to those of you who haven't secured your systems by A) denying root ssh access and B) allowing only public key logins. Those of course are only 2 of the many other precautions all node operators should have in place. Make sure all unessential network listeners are disabled, and you use fail2ban on any open ports. 

I also highly recommend you employ the api_access control for your cli_wallet, and only expose the rpc-endpoint to the network through a proxy or not at all externally.
👍  ,
properties (23)
authorfull-steem-ahead
permlinkre-robrigo-the-stack-clash-patch-this-critical-vulnerability-affecting-all-linux-operating-systems-20170619t233501743z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2017-06-19 23:35:00
last_update2017-06-19 23:35:00
depth1
children0
last_payout2017-06-26 23:35:00
cashout_time1969-12-31 23:59:59
total_payout_value4.394 HBD
curator_payout_value1.460 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length980
author_reputation30,177,498,572,933
root_title"The Stack Clash: Patch this critical vulnerability affecting all Linux operating systems"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id5,304,178
net_rshares313,470,465,714
author_curate_reward""
vote details (2)