Daemons and Firewalling
Sam & Diane were intermittently unreachable from noon to 2pm Sat May 29
as I looked into an unsuccessful breakin attempt.
The breakin attempt was facilitated by a UNet user who had tried to set up
a covert chat server on Sam. The server he was trying to run has a
well-known bug that would have allowed anyone with a fourth grade reading
level to break in to his account (but not anyone else's) if we were
running a normal Linux kernel.
Because we are running a hardened kernel, the attack was detected and
blocked. If you are running a Linux system, I strongly recommend Solar
Designer's patches, which can be found at http://www.false.com/security/
Sam and Diane are now running kernel firewalling. It is now impossible for
anyone to run a server I did not install. I apologize for the
inconvenience this causes the very few users with legitimate reasons to
test a daemon on UNet, but this is the only way to protect the system as a
whole from clueless or malicious users who wish to run unsafe software.
The use of supported software like pine, talk, and finger is not affected.