看板FB_security
標 題Re: NTP security hole CVE-2013-5211?
發信站NCTU CS FreeBSD Server (Thu Jan 9 23:12:19 2014)
轉信站ptt!csnews.cs.nctu!news.cednctu!FreeBSD.cs.nctu!.POSTED!freebsd.org!ow
--Apple-Mail=_72276C91-126B-4117-B38D-102D6A7876C7
Content-Transfer-Encoding: 7bit
Content-Type: text/plain;
charset=us-ascii
9 jan 2014 kl. 15:08 skrev Eugene Grosbein <
[email protected]>:
> On 09.01.2014 19:38, Palle Girgensohn wrote:
>> They recommend at least 4.2.7. Any thoughts about this?
>
> Other than updating ntpd, you can filter out requests to 'monlist' command
> with 'restrict ... noquery' option that disables some queries for
> the internal ntpd status, including 'monlist'.
>
> See http://support.ntp.org/bin/view/Support/AccessRestrictions for details.
Yes. But shouldn't there be a security advisory for FreeBSD specifically?
--Apple-Mail=_72276C91-126B-4117-B38D-102D6A7876C7
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
filename=signature.asc
Content-Type: application/pgp-signature;
name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail
-----BEGIN PGP SIGNATURE-----
Comment: GPGTools -
http://gpgtools.org
iQEcBAEBAgAGBQJSzq5DAAoJEIhV+7FrxBJDRz4H/1zm3zUNJ1gqBoWPg+s/BcMs
N2fxza4iqjsVL/1RMctTlotXkasnS5UR+yJi13L85tfMLK4W7n5n/7/PsybDDcJO
Vs8F0OkUChZ4PhXzi/UHACIjhzzCq7YcuFcwdFYixvxrt7hD0/xTRzPKijT+WfFI
Anus7Sx1J1kHkmPXOEkafPQUeLZHMvhbzEXL9rR2sn7uTN6dEtFpArFP3yGGRNlt
en/EBSrkQHD4yIeNbpLcTTLwCYS8pi+ucKnGzggTONk4h2PkYko1ZpybCFAEDlo8
DZDqtbVbUuYQBe2CCoWamwYUKzn4ykP9L3K9lsBcDIUhg/PdLn8Eia4Ns0qyTBA=
=qwhC
-----END PGP SIGNATURE-----
--Apple-Mail=_72276C91-126B-4117-B38D-102D6A7876C7--