LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 10-24-2016, 11:08 AM   #1
Darth Vader
Senior Member
 
Registered: May 2008
Location: Romania
Distribution: DARKSTAR Linux 2008.1
Posts: 2,727

Rep: Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247
Any guy able to exploit a Wordpress, Joomla, Drupal from a Slackware Server can get easily root access. How do you comment, Mr. Volkerding?


You know, is all about the Dirty COW...

All the Slackware versions released on the last nine years looks like are affected, and the Internet is full of easy rooting solutions based on this Kernel flaw, fixed only since 4.4.26 and similar versions.

How do you comment, Mr. Volkerding?

Last edited by Darth Vader; 10-24-2016 at 12:53 PM.
 
Old 10-24-2016, 11:17 AM   #2
anscal
Member
 
Registered: Apr 2011
Distribution: Slackware, RHEL
Posts: 31

Rep: Reputation: 15
How do you know Mr. Volkerding won't issue a patch?

And why did you omit the fact that all linux distributions were affected?

Last edited by anscal; 10-24-2016 at 11:24 AM.
 
Old 10-24-2016, 11:25 AM   #3
Darth Vader
Senior Member
 
Registered: May 2008
Location: Romania
Distribution: DARKSTAR Linux 2008.1
Posts: 2,727

Original Poster
Rep: Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247
Quote:
Originally Posted by anscal View Post
How do you know Mr. Volkerding won't issue a patch?
I do not question that. The question is WHEN?

Meantime, the Slackware servers are at mercy of whatever illustrious unknown haxxors, because Mr. Linus Torvalds hidden the dirt under table for nine years...

Quote:
Originally Posted by anscal View Post
And why did you omit the fact that all linux distributions were affected?
I can't blame Mr. Volkerding about what happen on the SuSE Enterprise Linux, right?

Last edited by Darth Vader; 10-24-2016 at 11:27 AM.
 
2 members found this post helpful.
Old 10-24-2016, 11:45 AM   #4
jpollard
Senior Member
 
Registered: Dec 2012
Location: Washington DC area
Distribution: Fedora, CentOS, Slackware
Posts: 4,912

Rep: Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513
The patch was released several days ago, and has nothing to do with Slackware.

You have the ability to replace your kernel anytime you want.
 
6 members found this post helpful.
Old 10-24-2016, 11:48 AM   #5
jpollard
Senior Member
 
Registered: Dec 2012
Location: Washington DC area
Distribution: Fedora, CentOS, Slackware
Posts: 4,912

Rep: Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513
Quote:
Originally Posted by Darth Vader View Post
I do not question that. The question is WHEN?
The kernel was patched several days ago (at least a week now)
Quote:
Meantime, the Slackware servers are at mercy of whatever illustrious unknown haxxors, because Mr. Linus Torvalds hidden the dirt under table for nine years...
You can update your kernel any time you want.
Quote:

I can't blame Mr. Volkerding about what happen on the SuSE Enterprise Linux, right?
No, but it sure looks like you are trying to.
 
2 members found this post helpful.
Old 10-24-2016, 11:48 AM   #6
number22
Member
 
Registered: Sep 2006
Location: Earth
Distribution: Slackware 14.1 Slackware64-current multilib
Posts: 278
Blog Entries: 7

Rep: Reputation: Disabled
Danger is real but fear is a choice, you can patch it yourself, stop whining.
Clearly you don't understand software; and general computer business model.
 
4 members found this post helpful.
Old 10-24-2016, 11:50 AM   #7
anscal
Member
 
Registered: Apr 2011
Distribution: Slackware, RHEL
Posts: 31

Rep: Reputation: 15
And you are prevented from compiling a new kernel by exactly what? Compiling a new kernel is standard practice for slackware machines. You know, slackware uses an unpatched kernel.org kernel and Mr. Volkerding has graciuosly provided a .config for you...
 
3 members found this post helpful.
Old 10-24-2016, 12:02 PM   #8
Skaendo
Senior Member
 
Registered: Dec 2014
Location: West Texas, USA
Distribution: Slackware64-14.2
Posts: 1,445

Rep: Reputation: Disabled
Quote:
Originally Posted by Darth Vader View Post
You know, is all about the Dirty COW...

All the Slackware versions released on the last nine years looks like are affected, and the Internet is full of easy rooting solutions based on this Kernel flaw, fixed only since 4.4.26 and similar versions.

How you comment, Mr. Volkerding?
You know that there are other operating systems out there you can use if you don't like the way Slackware is maintained. Maybe you haven't noticed, but it was Pat's birthday the other day and maybe he is taking a few well deserved days off. I would suggest that you find a different OS, because you clearly don't like how this one is ran. Maybe Ubuntu or Debian is more to your taste.
 
5 members found this post helpful.
Old 10-24-2016, 12:24 PM   #9
e5150
Member
 
Registered: Oct 2005
Location: Sweden
Distribution: Slackware and Alpine
Posts: 132

Rep: Reputation: 100Reputation: 100
This sort of thing is the reason I don't outright recommend slackware, even though it's the only distribution I'd use myself for my main OS. I couldn't tell my arch-using brother to switch over if I'd have to add the caveat “Oh, and by the way, don't expect security patches in a timely manner, you'll have to check forums and the obfuscated kernel changelog and fix those things yourself”. As much as I want to view slackware as a system that you set-it-up-once-and-forget-about-it, it ain't, not until security updates are consistently provided. Preferably with a delay inversly correlated to the severity of the issue.
 
3 members found this post helpful.
Old 10-24-2016, 12:26 PM   #10
justwantin
Member
 
Registered: Aug 2003
Location: Melbourne, Australia
Distribution: Slackware, Slackwarearm
Posts: 878

Rep: Reputation: 120Reputation: 120
Quote:
How you comment, Mr. Volkerding?
I'm taking a guess that English is not your first language. That should have been "How do you comment ...." Perhaps you may also be uninformed about the difference between polite and informed questions and to arrogant demands.
 
Old 10-24-2016, 12:32 PM   #11
ponce
LQ Guru
 
Registered: Aug 2004
Location: Pisa, Italy
Distribution: Slackware
Posts: 7,125

Rep: Reputation: 4200Reputation: 4200Reputation: 4200Reputation: 4200Reputation: 4200Reputation: 4200Reputation: 4200Reputation: 4200Reputation: 4200Reputation: 4200Reputation: 4200
you should also patch joomla, wordpress and joomla to their latest versions in the first place to avoid issues (and their extensions/plugins and php and apache and so on...).

if you do this for work and not as an hobby it's your daily job to be sure everything is ok, kernel included and not anybody else's.

EDIT: well, thinking about it again, also if you do it as an hobby.

Last edited by ponce; 10-24-2016 at 12:34 PM.
 
2 members found this post helpful.
Old 10-24-2016, 12:54 PM   #12
Darth Vader
Senior Member
 
Registered: May 2008
Location: Romania
Distribution: DARKSTAR Linux 2008.1
Posts: 2,727

Original Poster
Rep: Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247
Quote:
Originally Posted by justwantin View Post
I'm taking a guess that English is not your first language. That should have been "How do you comment ...." Perhaps you may also be uninformed about the difference between polite and informed questions and to arrogant demands.
Thanks for your notes, I'm not a native English speaker, BTW.
 
Old 10-24-2016, 12:58 PM   #13
Darth Vader
Senior Member
 
Registered: May 2008
Location: Romania
Distribution: DARKSTAR Linux 2008.1
Posts: 2,727

Original Poster
Rep: Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247
Quote:
Originally Posted by anscal View Post
And you are prevented from compiling a new kernel by exactly what? Compiling a new kernel is standard practice for slackware machines. You know, slackware uses an unpatched kernel.org kernel and Mr. Volkerding has graciuosly provided a .config for you...
Nothing stop me to compile a kernel as I like, and I believe that I have some experience on that after all those years.

Sadly, not all servers using Slackware are mine. So, more than probably there are thousands administrators expecting official security patches. Because this way are done the things, you know...

Last edited by Darth Vader; 10-30-2016 at 07:28 AM.
 
3 members found this post helpful.
Old 10-24-2016, 01:02 PM   #14
dugan
LQ Guru
 
Registered: Nov 2003
Location: Canada
Distribution: distro hopper
Posts: 11,249

Rep: Reputation: 5323Reputation: 5323Reputation: 5323Reputation: 5323Reputation: 5323Reputation: 5323Reputation: 5323Reputation: 5323Reputation: 5323Reputation: 5323Reputation: 5323
We already have a Dirty cow kernel exploit thread.
 
Old 10-24-2016, 01:04 PM   #15
Darth Vader
Senior Member
 
Registered: May 2008
Location: Romania
Distribution: DARKSTAR Linux 2008.1
Posts: 2,727

Original Poster
Rep: Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247Reputation: 1247
Quote:
Originally Posted by number22 View Post
Danger is real but fear is a choice, you can patch it yourself, stop whining.
I do not whining. I just point to a Linus Torvalds failtrocity which affect hypothetically any Slackware server on use, while Slackware does NOT released YET a security patch, after a whole week.

Quote:
Originally Posted by number22 View Post
Clearly you don't understand software; and general computer business model.
I agree, I have only 20 years on this domain and every one have to learn until retirement. Tell me more, Teacher!

Last edited by Darth Vader; 10-30-2016 at 07:27 AM.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Preference: Drupal vs Joomla vs WordPress Train Linux - Server 6 04-28-2014 11:29 AM
LXer: Drupal, Joomla and WordPress face challenges in Germany LXer Syndicated Linux News 0 03-14-2012 03:50 PM
Guy got root directory access from my FTP server... how can I fix this? bripage Linux - General 16 10-02-2002 10:12 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 05:19 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration