Skip to main content

标 题: Re: 大家更新一下网站open ssl ,严重漏洞

发信人: mitbbs2715 (好吃不懒做), 信区: Programming
标  题: Re: 大家更新一下网站open ssl ,严重漏洞
发信站: BBS 未名空间站 (Tue Apr  8 19:11:27 2014, 美东)

9x年的时候就爆出很多开源安全项目的审核和核心贡献者在一个神
秘的美国谍报部门领
钱故意植入大量漏洞, 现在当然知道这就是NSA

这就是为何后来openBSD对核心代码贡献者非常挑剔, 审核也异常严格.

可以想见的open SSL还有很多这种漏洞, 并且以后还会不断加入新的漏洞.

新警察们都不知道这一出戏 :D, 老警察要么不care了, 要么也领钱了

我们这些没有能力看全所有代码的人(就算看全了又怎样?很多漏洞不是光看就能看出来
的), 能做的只能是频繁更新密钥, 将可能的损失降到最低
 
http://gengwg.blogspot.com/

Comments

Popular posts from this blog

CKA Simulator Kubernetes 1.22

  https://killer.sh Pre Setup Once you've gained access to your terminal it might be wise to spend ~1 minute to setup your environment. You could set these: alias k = kubectl                         # will already be pre-configured export do = "--dry-run=client -o yaml"     # k get pod x $do export now = "--force --grace-period 0"   # k delete pod x $now Vim To make vim use 2 spaces for a tab edit ~/.vimrc to contain: set tabstop=2 set expandtab set shiftwidth=2 More setup suggestions are in the tips section .     Question 1 | Contexts Task weight: 1%   You have access to multiple clusters from your main terminal through kubectl contexts. Write all those context names into /opt/course/1/contexts . Next write a command to display the current context into /opt/course/1/context_default_kubectl.sh , the command should use kubectl . Finally write a second command doing the same thing into ...

OWASP Top 10 Threats and Mitigations Exam - Single Select

Last updated 4 Aug 11 Course Title: OWASP Top 10 Threats and Mitigation Exam Questions - Single Select 1) Which of the following consequences is most likely to occur due to an injection attack? Spoofing Cross-site request forgery Denial of service   Correct Insecure direct object references 2) Your application is created using a language that does not support a clear distinction between code and data. Which vulnerability is most likely to occur in your application? Injection   Correct Insecure direct object references Failure to restrict URL access Insufficient transport layer protection 3) Which of the following scenarios is most likely to cause an injection attack? Unvalidated input is embedded in an instruction stream.   Correct Unvalidated input can be distinguished from valid instructions. A Web application does not validate a client’s access to a resource. A Web action performs an operation on behalf of the user without checkin...