From owner-freebsd-questions@FreeBSD.ORG Fri Dec 11 11:33:06 2009 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 3E251106568F for ; Fri, 11 Dec 2009 11:33:06 +0000 (UTC) (envelope-from a.spinella@rfc1925.net) Received: from joy.rfc1925.net (static-217-133-230-42.clienti.tiscali.it [217.133.230.42]) by mx1.freebsd.org (Postfix) with ESMTP id CE5878FC16 for ; Fri, 11 Dec 2009 11:33:05 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by joy.rfc1925.net (Postfix) with ESMTP id 43D4E125449; Fri, 11 Dec 2009 12:31:29 +0100 (CET) X-Virus-Scanned: amavisd-new at rfc1925.net Received: from joy.rfc1925.net ([127.0.0.1]) by localhost (joy.rfc1925.net [127.0.0.1]) (amavisd-new, port 10024) with LMTP id 4CkqHARTOUT6; Fri, 11 Dec 2009 12:31:21 +0100 (CET) Received: from zeta (unknown [194.246.127.221]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) (Authenticated sender: a.spinella@rfc1925.net) by joy.rfc1925.net (Postfix) with ESMTPSA id 56ADB12544F; Fri, 11 Dec 2009 12:29:49 +0100 (CET) Content-Type: text/plain; charset=us-ascii; format=flowed; delsp=yes To: "Anton Shterenlikht" , freebsd-questions@freebsd.org, freebsd-current@freebsd.org References: <20091210144141.GB834@mech-cluster241.men.bris.ac.uk> Date: Fri, 11 Dec 2009 12:29:44 +0100 MIME-Version: 1.0 Content-Transfer-Encoding: 7bit From: $witch Message-ID: In-Reply-To: <20091210144141.GB834@mech-cluster241.men.bris.ac.uk> User-Agent: Opera Mail/10.10 (FreeBSD) Cc: Subject: Re: Root exploit for FreeBSD X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 11 Dec 2009 11:33:06 -0000 On Thu, 10 Dec 2009 15:41:41 +0100, Anton Shterenlikht wrote: >> From my information security manager: > > FreeBSD isn't much used within the University (I understand) and has a > (comparatively) poor security record. ...... > > Hi, almost all of you remark how FreeBSD is more-secure-than-others-OS, will add nothing to varius comments. but i look in syslogs of some FreeBSD internet server and there is a great evidence that some "botnets" are (again) tryng simple combination of uid/pwd. starting from Dec 8 01:00:34 (CET) hundreds of zombies are looking for a valid username. it mean that most of the matter is our; the FreeBSD users. we are the only ones that will (or will not) patch the systems; i love the FreeBSD security while it is MOSTLY based on KNOWLEDGE of users than on a PERFECT code. cheers Alessandro -- "If 386BSD had been available when I started on Linux, Linux would probably never had happened." Linus Torvalds