Gentoo Archives: gentoo-server

From: Andrew Gaffney <agaffney@×××××××××××.com>
To: gentoo-server@l.g.o
Subject: Re: [gentoo-server] Distccd vulnerability ??
Date: Tue, 14 Sep 2004 03:30:23
Message-Id: 41466445.8040304@skylineaero.com
In Reply to: Re: [gentoo-server] Distccd vulnerability ?? by Lisa Seelye
1 Lisa Seelye wrote:
2 > On Mon, 2004-09-13 at 12:50, linux-lists@×××.de wrote:
3 >>I'm manging 6 clients and a server [nis, nfs, etc.] in an office.
4 >>today, while updating one client I found in
5 >>/tmp/.tmp an downloaded ftpd.tar and an unpacked openftpd-0.29.4.tar.gz
6 >>and additionally and ftproot which looks strongly like binary-sharing:
7 >
8 > Due to Evolution crashing and me losing an email I'm going to make this
9 > short and sweet:
10 >
11 > I highly suggest updating distcc to 2.17-r1 or at the very least take
12 > the config and init files from /usr/portage/sys-devel/distcc/files/2.17.
13 >
14 > They incorporate the --allow and --listen daemon flag settings to remind
15 > users that they /can/ tighten the security of their distcc daemons.
16
17 Also, if this machine is exposed to the internet, make sure that you have a
18 firewall blocking access the the distcc port.
19
20 --
21 Andrew Gaffney
22 Network Administrator
23 Skyline Aeronautics, LLC.
24 636-357-1548