看板FB_security
標 題Re: Recent security announcement and csup/cvsup?
發信站NCTU CS FreeBSD Server (Sun Nov 18 01:07:16 2012)
轉信站ptt!csnews.cs.nctu!news.cs.nctu!.cs.nctucs.nctu!.org!ownorg!owner-free
Hi,
> Can someone explain why the cvsup/csup infrastructure is considered
> insecure [...]
Speaking of cvsup security -- correct me if I'm wrong, but as far as I
know cvsup is generally vulnerable to man-in-the-attacks[0]. Hence I'd
be very happy about more and more people moving over to the portsnap
camp.
Best,
mel
[0]
http://en.wikipedia.org/wiki/Portsnap
http://unix.derkeiler.com/Mailing-Lists/FreeBSD/stable/2003-11/0287.html
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"