Re: 4.0 Release -> 4.2-Stable should be ok ? via cvsup ?

2001-02-11 Thread Kent Stewart



Warner Losh wrote:
> 
> In message <[EMAIL PROTECTED]> Andrew 
>Gordon writes:
> : I hope that's _late_ Feb 4th sources if your firewall uses ipfw: ipfw was
> : substantially broken from  2001/02/01 20:25:09  to 2001/02/04 05:48:59
> : (/sys/netinet/ip_fw.c rev 1.131.2.13 is the bad version).
> :
> : We were upgrading our firewall around that time and were dismayed to find
> : it wide-open after the upgrade!
> 
> Yes.  Since I'm on the security-officer's list still, I had planned
> the upgrade for a day earlier, but put things off until the fixes were
> committed.

Thanks for this thread because of it, I found that I could telnet in
from the outside world. Something that was supposed to be completely
turned off. I was still logging the activity but was really kind of
shocked.

Kent

> 
> Warner
> 
> To Unsubscribe: send mail to [EMAIL PROTECTED]
> with "unsubscribe freebsd-stable" in the body of the message

-- 
Kent Stewart
Richland, WA

mailto:[EMAIL PROTECTED]
http://kstewart.urx.com/kstewart/index.html
FreeBSD News http://daily.daemonnews.org/


To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-stable" in the body of the message



Re: 4.0 Release -> 4.2-Stable should be ok ? via cvsup ?

2001-02-11 Thread Warner Losh

In message <[EMAIL PROTECTED]> Andrew 
Gordon writes:
: I hope that's _late_ Feb 4th sources if your firewall uses ipfw: ipfw was
: substantially broken from  2001/02/01 20:25:09  to 2001/02/04 05:48:59
: (/sys/netinet/ip_fw.c rev 1.131.2.13 is the bad version).
: 
: We were upgrading our firewall around that time and were dismayed to find
: it wide-open after the upgrade!

Yes.  Since I'm on the security-officer's list still, I had planned
the upgrade for a day earlier, but put things off until the fixes were
committed.

Warner


To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-stable" in the body of the message



Re: 4.0 Release -> 4.2-Stable should be ok ? via cvsup ?

2001-02-11 Thread Andrew Gordon


On Sat, 10 Feb 2001, Warner Losh wrote:
> 
> Yes.  I've done this with Feb 4th sources on our 4.0-RELEASE
> firewall.  Well, I'm waiting for a time to do the make
> installworld/installkernel since the machine isn't at my house and I'm
> nervous about doing it remotely since I screw 4 people if something
> goes wrong.

I hope that's _late_ Feb 4th sources if your firewall uses ipfw: ipfw was
substantially broken from  2001/02/01 20:25:09  to 2001/02/04 05:48:59
(/sys/netinet/ip_fw.c rev 1.131.2.13 is the bad version).

We were upgrading our firewall around that time and were dismayed to find
it wide-open after the upgrade!




To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-stable" in the body of the message