Got r00t'ed?
I am not sure how many guys here are much into linux, i visit sites often but since i regular mostly computer based forums, i havent posted here a lot
has the latest kernel exploit affected any of you guys? man the recent exploit has really shaken the linux based web hosts and people like me who work a lot on it, although root exploits have always been there, i never expected the latest kernel relesae to be so vulnerable..
some of the biggies like hostgator and many many were also exploited and had to rely on incremental backups.
i tried myself on fedora8 and vmware, vmsplice really does the job, although i am checking out the patches, its not easy being a web host and rebooting the systems
i think kernels 2.6.17 - 2.6.24.1 are affected by this exploit..
qatman, no i dont much know whether many companies here deploy linux, though i think some of them use linux boxes as basic firewalls,
well the server's i manage actually are not here locally but in DC's in US. Savvis, LayeredTech etc,
i doubt that even any webhosting companies are based here, im not sure if there is a DC here, though i think i read in news before that there was a new one...
most of the webhosting companies based here are based Off US DC's and or hosting companies leasing VPS.
Got it right now Thanks! I was referring to the older one. I though there are not many linux servers in use Doha in the production and was wondering Why?
oh and forgot to add..check this thread,
http://www.webhostingtalk.com/showthread.php?t=670497
qatman i am not sure if the exploit yiou are talking about is the same one..i am talking about Vmsplice
and this is a recent one if i m not wrong..
heres redhats' bugzila link
https://bugzilla.redhat.com/show_bug.cgi?id=432251
and these two
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0009
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0010
and no i wasnt trying out for anything but patching up, has anyone got any distro patched properly?
mostly the server's i work on are either CentOS, or Fedora/Redhat
some of the older kernels arent affected IF patched properly, although patching is not one of my favorite linux jobs lol..
The vulnerability was discovered way back in 2006 and goes on to prove no OS is secure. It has been referenced as CVE-2006-2451 and it exists in Linux Kernel 2.6.13 up to 2.6.17http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2451 Are you trying out the exploit?