lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <1070304420.16497.30.camel@tantor.nuclearelephant.com> From: jonathan at nuclearelephant.com (Jonathan A. Zdziarski) Subject: automated vulnerability testing > Quite a flaw in logic there, I'm sure you meant; Actually I was referring to the general laziness of sysadmins who would rather throw up a firewall in lieu of (instead of in addition to): - Performing general OS hardening - Reconfiguring daemons that don't need to run as root - Chroot'ing processes such as pop3 and rpcbind - Shutting down processes that don't need to run at all - Installing IDS and local filtering - Running tools such as tripwire to make sure their system hasn't already been hacked - Performing any type of system auditing the list goes on