Cigar Asylum Cigar Forum  

Go Back   Cigar Asylum Cigar Forum > Non Cigar Specialty Forums > Misc > General Discussion

Reply
 
Thread Tools Display Modes
Old 12-20-2014, 10:27 AM   #1
markem
Bunion
 
markem's Avatar
16
 
Join Date: Oct 2008
First Name: Mark
Location: Second Star on the Right
Posts: 22,625
Trading: (47)
HUpmann
markem has disabled reputation
Default Potentially serious security flaw in fundamental Internet SW

If you have a computer the odds are really good that you have a clock that uses the NTP (network time protocol). While the problem is about the part of the server that is on the time server, the security flaw can be used to create all sorts of security havoc.

Here is a pointer to the article.

http://support.ntp.org/bin/view/Main/SecurityNotice

For those is Internet facing servers, make sure that you either upgrade as soon as possible or ensure that NTP is disabled. This may create some issues for those who only get their network time from a single source.

Use this Google string if you want to find out more: ntp security issues
__________________
I refuse to belong to any organization that would have me as a member.
~ Groucho Marx
markem is offline   Reply With Quote
Old 12-20-2014, 07:36 PM   #2
8zeros
What's this button do?
 
8zeros's Avatar
 
Join Date: Dec 2013
First Name: Roger
Location: Far from everything
Posts: 268
Trading: (0)
8zeros will become famous soon enough
Default Re: Potentially serious security flaw in fundamental Internet SW

It may take a while for firmware devices like routers to get an update. Do you think NTP should be disabled on these boxes until then?
__________________
8zeros is offline   Reply With Quote
Old 12-20-2014, 08:19 PM   #3
markem
Bunion
 
markem's Avatar
16
 
Join Date: Oct 2008
First Name: Mark
Location: Second Star on the Right
Posts: 22,625
Trading: (47)
HUpmann
markem has disabled reputation
Default Re: Potentially serious security flaw in fundamental Internet SW

Quote:
Originally Posted by 8zeros View Post
It may take a while for firmware devices like routers to get an update. Do you think NTP should be disabled on these boxes until then?
The flaw is mostly a serious issues for servers running 'ntpd'. I would encourage people to contact their router vendor. I have no opinion on whether or not NTP should be silenced. Lots of bad things can happen if you lose clock synchronization. Very bad things.
__________________
I refuse to belong to any organization that would have me as a member.
~ Groucho Marx
markem is offline   Reply With Quote
Old 12-20-2014, 08:42 PM   #4
The Poet
Il megglior fabbro
 
The Poet's Avatar
 
Join Date: Jun 2009
First Name: Thomas
Location: Hickory, NC
Posts: 8,420
Trading: (2)
The Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud of
Default Re: Potentially serious security flaw in fundamental Internet SW

I'm pretty sure I have a computer, but I have no idea what any of this means.
__________________
Ninety percent of everything is crap - Theodore Sturgeon.
The Poet is offline   Reply With Quote
Old 12-20-2014, 10:52 PM   #5
icehog3
Admiral Douchebag
 
icehog3's Avatar
15
 
Join Date: Oct 2008
First Name: Tom
Location: Clermont, Kentucky
Posts: 71,440
Trading: (60)
HUpmann
icehog3 has disabled reputation
Default Re: Potentially serious security flaw in fundamental Internet SW

Quote:
Originally Posted by The Poet View Post
I'm pretty sure I have a computer, but I have no idea what any of this means.
Unplug your clock radio and you should be fine.
__________________


Thanks Dave, Julian, James, Kelly, Peter, Gerry, Dave, Mo, Frank, Týr and Mr. Mark!
icehog3 is offline   Reply With Quote
Old 12-21-2014, 06:39 AM   #6
The Poet
Il megglior fabbro
 
The Poet's Avatar
 
Join Date: Jun 2009
First Name: Thomas
Location: Hickory, NC
Posts: 8,420
Trading: (2)
The Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud of
Default Re: Potentially serious security flaw in fundamental Internet SW

Quote:
Originally Posted by icehog3 View Post
Unplug your clock radio and you should be fine.
Thanks, man. That I can do.
__________________
Ninety percent of everything is crap - Theodore Sturgeon.
The Poet is offline   Reply With Quote
Old 12-21-2014, 07:21 AM   #7
Porch Dweller
Life is for living
 
Porch Dweller's Avatar
11
 
Join Date: Oct 2012
First Name: James
Location: Mississippi Gulf Coast
Posts: 8,461
Trading: (24)
Bolivar AirForce (Retired)
Porch Dweller is a splendid one to beholdPorch Dweller is a splendid one to beholdPorch Dweller is a splendid one to beholdPorch Dweller is a splendid one to beholdPorch Dweller is a splendid one to beholdPorch Dweller is a splendid one to beholdPorch Dweller is a splendid one to beholdPorch Dweller is a splendid one to behold
Default Re: Potentially serious security flaw in fundamental Internet SW

Quote:
Originally Posted by icehog3 View Post
Unplug your clock radio and you should be fine.
I stopped the pendulum on my Grandfather clock just to be on the safe side.
__________________
A 1911 in the hand is faster than 911 on the phone
Porch Dweller is offline   Reply With Quote
Old 12-21-2014, 09:49 AM   #8
markem
Bunion
 
markem's Avatar
16
 
Join Date: Oct 2008
First Name: Mark
Location: Second Star on the Right
Posts: 22,625
Trading: (47)
HUpmann
markem has disabled reputation
Default Re: Potentially serious security flaw in fundamental Internet SW

Quote:
Originally Posted by Porch Dweller View Post
I stopped the pendulum on my Grandfather clock just to be on the safe side.
wrong, wrong, wrong! You need to readjust it so that it only swings to the right.
__________________
I refuse to belong to any organization that would have me as a member.
~ Groucho Marx
markem is offline   Reply With Quote
Old 12-21-2014, 10:49 AM   #9
icehog3
Admiral Douchebag
 
icehog3's Avatar
15
 
Join Date: Oct 2008
First Name: Tom
Location: Clermont, Kentucky
Posts: 71,440
Trading: (60)
HUpmann
icehog3 has disabled reputation
Default Re: Potentially serious security flaw in fundamental Internet SW

It don't mean a thing, if it don't have that swing, do da da do da
__________________


Thanks Dave, Julian, James, Kelly, Peter, Gerry, Dave, Mo, Frank, Týr and Mr. Mark!
icehog3 is offline   Reply With Quote
Old 12-21-2014, 10:53 AM   #10
The Poet
Il megglior fabbro
 
The Poet's Avatar
 
Join Date: Jun 2009
First Name: Thomas
Location: Hickory, NC
Posts: 8,420
Trading: (2)
The Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud ofThe Poet has much to be proud of
Default Re: Potentially serious security flaw in fundamental Internet SW

Quote:
Originally Posted by markem View Post
wrong, wrong, wrong! You need to readjust it so that it only swings to the right.
Or just switch to tighty-whities, so it doesn't swing at all.
__________________
Ninety percent of everything is crap - Theodore Sturgeon.
The Poet is offline   Reply With Quote
Old 12-21-2014, 11:24 AM   #11
badbriar
Guest
 
Posts: n/a
Default Re: Potentially serious security flaw in fundamental Internet SW

Quote:
Originally Posted by Porch Dweller View Post
I stopped the pendulum on my Grandfather clock just to be on the safe side.
Yeah, but Grandmother clock will be pissed at you for disabling his pendulum!
  Reply With Quote
Old 12-21-2014, 01:55 PM   #12
Subvet642
Bilge Rat
 
Subvet642's Avatar
1
 
Join Date: Nov 2009
First Name: Darren
Location: Torpedo Room Bilge
Posts: 2,997
Trading: (13)
LFdC Navy (Served With Honor)
Subvet642 is a name known to allSubvet642 is a name known to allSubvet642 is a name known to allSubvet642 is a name known to allSubvet642 is a name known to allSubvet642 is a name known to all
Default Re: Potentially serious security flaw in fundamental Internet SW

__________________
"Man's mind is his basic tool of survival. Life is given to him, survival is not." -John Galt
Subvet642 is offline   Reply With Quote
Old 12-21-2014, 02:11 PM   #13
Ogre
****CENSORED****
 
Ogre's Avatar
7
 
Join Date: Apr 2010
First Name: Larry
Location: Central Florida
Posts: 12,068
Trading: (46)
Montecristo
Ogre has a brilliant futureOgre has a brilliant futureOgre has a brilliant futureOgre has a brilliant futureOgre has a brilliant futureOgre has a brilliant futureOgre has a brilliant futureOgre has a brilliant futureOgre has a brilliant futureOgre has a brilliant futureOgre has a brilliant future
Default Re: Potentially serious security flaw in fundamental Internet SW

__________________
Ogre is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -6. The time now is 10:38 AM.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
All content is copyrighted jointly by Cigar Asylum and the content provider.