LxCenter HyperVM & Kloxo Support

Forum



Members   Search      Help    Register    Login    Home
Home » Archive » Fixed Bugs, Security Issues and Implemented Features » 08/25/2009 - public HyperVM vuln
Re: 08/25/2009 - public HyperVM vuln [message #70431 is a reply to message #70330] Fri, 28 August 2009 12:01 Go to previous messageGo to next message
_GrG_ is currently offline _GrG_  Italy
Messages: 14
Registered: June 2009
Member
Done Very Happy
Re: 08/25/2009 - public HyperVM vuln [message #70457 is a reply to message #70330] Fri, 28 August 2009 17:59 Go to previous messageGo to next message
arthurthornton is currently offline arthurthornton  United States
Messages: 2120
Registered: August 2007
Location: Virginia
Grandmaster
LxCenter Staff

This vulnerability affects Xen vms (I just tested it).

I am working on a working patch for Xen.


[Updated on: Fri, 28 August 2009 18:46]

Report message to a moderator

Re: 08/25/2009 - public HyperVM vuln [message #70458 is a reply to message #70330] Fri, 28 August 2009 18:09 Go to previous messageGo to next message
yourweb is currently offline yourweb  Netherlands
Messages: 61
Registered: May 2009
Valuable Member
Before there is any new discussion starting about releasing the source:
- There has been choosen to fix the security problems before releasing the code. As far as I know the code will be released, the only problem is that when the code will be released before HyperVM has been released that security problems can be fixed, but it can take some time before every HyperVM server has updated his software and there will be a lot updates. In the mean time the hackers can hack easily a HyperVM cluster or node using the published exploit
- The family and other volunteers have choossen to not release the code until HyperVM is safe again as far as possible with the current code. The only thing they may want to do is update HyperVM at maximum every day with new secured code.
- My opinion: I'm happy that Danny and others are working for free on this system. The code isn't safe and isn't the best, so it is hard to secure the code. HyperVM is a great system, but the code isn't. After the secured version of HyperVM is released they will probably start on V3.0: a version with probably much better code.
Re: 08/25/2009 - public HyperVM vuln [message #70472 is a reply to message #70458] Sat, 29 August 2009 01:11 Go to previous messageGo to next message
heyhey is currently offline heyhey  United States
Messages: 9
Registered: June 2009
Member
yourweb wrote on Fri, 28 August 2009 18:09
Before there is any new discussion starting about releasing the source:
- There has been choosen to fix the security problems before releasing the code. As far as I know the code will be released, the only problem is that when the code will be released before HyperVM has been released that security problems can be fixed, but it can take some time before every HyperVM server has updated his software and there will be a lot updates. In the mean time the hackers can hack easily a HyperVM cluster or node using the published exploit
- The family and other volunteers have choossen to not release the code until HyperVM is safe again as far as possible with the current code. The only thing they may want to do is update HyperVM at maximum every day with new secured code.



Can you explain:
- why not releasing the code first is increasing security here?
- why it was choosen to fix issue before releasing? What's the goal?
- don't you think with the help of others, it would go faster?
- don't you think that others will see new mistakes (everyone does some)?
- when you release, what license will you choose? This one is very important.
Re: 08/25/2009 - public HyperVM vuln [message #70473 is a reply to message #70330] Sat, 29 August 2009 02:20 Go to previous messageGo to next message
testbot is currently offline testbot  United States
Messages: 27
Registered: August 2009
Location: chicago
Member
can you discuss the release of the code and anything else not directly related to the vulnerability in another thread please?

i'm sure i'm not the only one that doesn't want to receive an email you girls post a new reply about who should get what.

i'm only interested in security.

thank you.
Re: 08/25/2009 - public HyperVM vuln [message #70851 is a reply to message #70457] Mon, 07 September 2009 00:20 Go to previous messageGo to next message
bliss is currently offline bliss  United Kingdom
Messages: 288
Registered: July 2008
Senior Member
arthurthornton wrote on Fri, 28 August 2009 22:59
This vulnerability affects Xen vms (I just tested it).

I am working on a working patch for Xen.


Anywhere closer with a patch for Xen yet?

Would be usedul.

Regards

Jane
Re: 08/25/2009 - public HyperVM vuln [message #70857 is a reply to message #70851] Mon, 07 September 2009 00:52 Go to previous messageGo to next message
arthurthornton is currently offline arthurthornton  United States
Messages: 2120
Registered: August 2007
Location: Virginia
Grandmaster
LxCenter Staff

I am still trying at this and I anticipate having a patch today.

[Updated on: Mon, 07 September 2009 01:19]

Report message to a moderator

Re: 08/25/2009 - public HyperVM vuln [message #70984 is a reply to message #70330] Fri, 11 September 2009 08:44 Go to previous messageGo to next message
Danny is currently offline Danny  Ireland
Messages: 57
Registered: March 2008
Valuable Member
Bump!
Re: 08/25/2009 - public HyperVM vuln [message #71047 is a reply to message #70984] Mon, 14 September 2009 06:17 Go to previous messageGo to next message
LxCenter_Danny is currently offline LxCenter_Danny  Netherlands
Messages: 2068
Registered: July 2007
Location: Netherlands
Grandmaster
LxCenter Core Team Member
LxCenter Representative

The deadline for adding a fix to the source/public has passed.
The next opensourced release (maybe october) is without fix!
I hope current Developers learned their lesson Smile
They must focus now on the next tasks with deadlines.

So after opensourced version is released and you know a good fix for both Xen and OpenVZ... enjoy to commit them.




LxCenter - System Operations
Re: 08/25/2009 - public HyperVM vuln [message #71063 is a reply to message #70330] Tue, 15 September 2009 06:06 Go to previous messageGo to next message
markhard is currently offline markhard  Netherlands
Messages: 288
Registered: May 2007
Location: Netherlands
Senior Member
so it will be open sourced on october?

HalfDedi • Simplifying Web Hosting
VPS Hosting and Shared Web Hosting Solution
http://www.halfdedi.com
Re: 08/25/2009 - public HyperVM vuln [message #71072 is a reply to message #71063] Tue, 15 September 2009 12:41 Go to previous messageGo to next message
lordlex is currently offline lordlex  Romania
Messages: 8
Registered: September 2009
Member
Yes, open source. And he said MAYBE. As many people here, i can't wait for this release, and i hope it will be next month.
Re: 08/25/2009 - public HyperVM vuln [message #71092 is a reply to message #70330] Tue, 15 September 2009 18:30 Go to previous message
cyberneticos is currently offline cyberneticos  Spain
Messages: 55
Registered: July 2009
Location: Cadiz, Spain
Valuable Member
+1


Previous Topic:Update your bind version
Goto Forum:
  


Current Time: Tue May 21 14:48:17 EDT 2013

Total time taken to generate the page: 0.01359 seconds
.:: Contact :: Home :: Privacy ::.

Click here to lend your support to: LxCenter and make a donation at www.pledgie.com !

Powered by: FUDforum 3.0.2.
Copyright ©2001-2010 FUDforum Bulletin Board Software