On mySimon: Activision DJ Hero Bundle with Turntable
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 25 of 35:
Next »
« Previous
OS vs app flaws.
An OS flaw is a flaw that causes an OS or its kernel to fail.

An app flaw is one that causes an app to fail. If the app causes the OS kernel to fail then it may arguably be called an OS flaw.

This flaw is in the SAMBA app and it allows malicious users on the network to launch a DOS attack by flooding the server with requests. The server actually answers all of the requests and so it does its job.

The server does not crash but gets extremely busy at what it was meant to do. Stop the app, the problem goes away. The OS is not flawed.

The latest MS jpeg flaw is another issue. It may be an app flaw as it affects apps that use the GDI API and interprets jpeg files. However, the flaw can allow a malicious user to take over your system so that it stops doing what it was meant to do and start doing anything that the maluser wishes it to.

This now becomes an OS flaw manifested through an app vulnerability because the OS allows the app to execute malicious code, bypassing security, granting access and control to persona non grata.

Now, the app flaw in SAMBA affects every OS it is loaded on. SAMBA is not loaded by default on every Linux desktop instalation. Gentoo, Mandrake and Red Hat do not. They all ask you if you want or need the service --well the versions that I have used of them anyway.

FreeBSD also asks. At least it asked me the last two times I loaded FBSD. Therefore it cannot be a Linux flaw but if you insist on calling it so then it must be a FBSD flaw also.

Now if you are saying that Linux distro's that autoload SAMBA are flawed, (not that I am aware of any that do but I do not dooubt that they exists), then you are incorrect. They are not flawed since the flawed app does not crash the OS but they posses a vulnerability that may make ineffecient at what they do.

Take away your peripheral firewall and every OS has a vulnerability, even those with built-in firewalls because the blocked TCP/UDP package still travels across the ethernet to the OS and still chews bandwidth and still can cripple the network services.

So, you were saying?
Posted by: The King's Servant   Posted on: 09/15/04 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Patchs for everyone!  No_Ax_to_Grind | 09/14/04
And no OS upgrade required either!  Zogg | 09/14/04
Haha...Yes, pretty much.  Linux_Developer | 09/14/04
I got a Samba server.  doe_z | 09/14/04
It would appear...  Fred Fredrickson | 09/14/04
Point taken  Michael Kelly | 09/15/04
I had these patches installed yesterday...  ickusslime@... | 09/14/04
Samba servers vulnerable to denial-of-service attacks  Loverock Davidson | 09/14/04
Hello! Clue for the moron  Linux User 147560 | 09/14/04
Clue for you  balsover | 09/14/04
It includes Loverock.  Linux_Developer | 09/15/04
Him? BSD?  balsover | 09/15/04
Him? BSD?  Loverock Davidson | 09/15/04
So you use SFU (Services For Unix)?  B.O.F.H. | 09/15/04
so he claims...  ryusen | 09/15/04
Ha! But don't worry, Loverock. The flaw isn't very serious. (NT)  Linux_Developer | 09/15/04
Clue for the moron? Must be for you then.  Loverock Davidson | 09/15/04
Re: Linux is so secure  Linux_Developer | 09/15/04
The fact of the matter is  balsover | 09/14/04
Nah, it barely registers.  doe_z | 09/15/04
Nah, it barely registers.  Loverock Davidson | 09/15/04
But it's not a Linux / OS  Linux User 147560 | 09/15/04
It is  Loverock Davidson | 09/15/04
First some facts  Linux User 147560 | 09/15/04
OS vs app flaws.  The King's Servant | 09/15/04
YOu really don't know jack about Unix, Linux or BSD, do you?  B.O.F.H. | 09/15/04
Ho Hum  Loverock Davidson | 09/15/04
You really need to learn how to spell  AmusedAtItAll | 09/15/04
You really need to learn how to spell  Loverock Davidson | 09/15/04
Hey, FreeBSD fanboy!  The King's Servant | 09/15/04
SaMBa runs on BSD!  B.O.F.H. | 09/15/04
Whew, patched already.. back to helping all the silly Windows users  Xunil_Sierutuf | 09/15/04
Helping yourself are you?  No_Ax_to_Grind | 09/15/04
I am sure he can help you next!  B.O.F.H. | 09/15/04
Thank goodness Apple servers are the future  FilledOut | 09/16/04

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

SmartPlanet

Click Here