LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Ubuntu
User Name
Password
Ubuntu This forum is for the discussion of Ubuntu Linux.

Notices


Reply
  Search this Thread
Old 11-01-2010, 12:42 PM   #1
mrmnemo
Member
 
Registered: Aug 2009
Distribution: linux
Posts: 527

Rep: Reputation: 51
multiple exploits listed with debsecan


Hi,

I recently re0instralled and update ubuntu 10.04 LTS. After installing and running debsecan, I found ALOT of problems. Does anyone have experiance with this tool?
 
Old 11-02-2010, 05:56 AM   #2
stress_junkie
Senior Member
 
Registered: Dec 2005
Location: Massachusetts, USA
Distribution: Ubuntu 10.04 and CentOS 5.5
Posts: 3,873

Rep: Reputation: 335Reputation: 335Reputation: 335Reputation: 335
After reading your post I ran debsecan on my Ubuntu 10.04 machine. It listed many vulnerabilities. I find that very disappointing.

My response is to:
- use a gateway/router with a firewall and to use a firewall on the machine
- avoid downloading material such as pictures, PDF files, and other exploitable material
- use a dedicated user account for recreational use and another user account for personal stuff
- harden the file system security on my machine
- and other stuff.

The list of vulnerabilities listed in debsecan is troubling. The question is whether any other operating system provides better security. Some claim to do that such as OpenBSD but I'm not convinced.

The sad fact is that if you want to use exploitable software such as streaming audio players and PDF viewers and Java applications then the best approach is to try to limit the extent that these problems can cause harm. I believe that Linux is good at doing that but I feel like I'm just whistling past a graveyard.
 
Old 11-02-2010, 10:15 AM   #3
mrmnemo
Member
 
Registered: Aug 2009
Distribution: linux
Posts: 527

Original Poster
Rep: Reputation: 51
not sure what the graveyard analogy refers to. However, the odd thing is that if you look at the debian security listings, you will see that many of these have been patched. What I couldnt make sense of was the versions of packages.
I had thought that ubuntu pulled updates from the debian patches as well. Am I wrong?
 
  


Reply

Tags
debsecan issues



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
multiple users but not listed ncicovic Linux - Security 7 04-10-2009 04:22 AM
Listed partition in cfdisk, but not listed in /dev? Erik_the_Red Linux - Newbie 7 08-05-2005 11:44 PM
Multiple /dev/hda1 's listed after a 'df' command (up to 50-60) hmschouten Linux - General 4 04-02-2004 03:07 PM
Exploits sopiaz57 Linux - Security 1 11-05-2003 08:41 PM
how to use exploits virusx Slackware 5 08-24-2003 01:08 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Ubuntu

All times are GMT -5. The time now is 05:13 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration