<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kostas&#039; random thoughts &#187; Security</title>
	<atom:link href="http://www.atreides.org.uk/blog/topics/sysadmin/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.atreides.org.uk/blog</link>
	<description>Μη μου τους κύκλους τάρατε</description>
	<lastBuildDate>Mon, 24 Dec 2007 17:36:53 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>glexec or why changing suexec is a bad idea</title>
		<link>http://www.atreides.org.uk/blog/2007/06/05/glexec-or-why-changing-suexec-is-a-bad-idea/</link>
		<comments>http://www.atreides.org.uk/blog/2007/06/05/glexec-or-why-changing-suexec-is-a-bad-idea/#comments</comments>
		<pubDate>Tue, 05 Jun 2007 10:23:07 +0000</pubDate>
		<dc:creator>Kostas Georgiou</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Work]]></category>

		<guid isPermaLink="false">http://www.atreides.org.uk/blog/2007/06/05/glexec-or-why-changing-suexec-is-a-bad-idea/</guid>
		<description><![CDATA[I can not really believe that the LHC grid people want to use glexec in every batch system. The thought of thousands of machines running this really scares me.
The suexec sources+documentation say it clearly but I am going to repeat it one more time &#8220;Do not make any changes in the source code unless you [...]]]></description>
			<content:encoded><![CDATA[<p>I can not really believe that the LHC grid people want to use <a href="http://jra1mw.cvs.cern.ch:8180/cgi-bin/jra1mw.cgi/org.glite.security.glexec/src/">glexec</a> in every batch system. The thought of thousands of machines running this really scares me.</p>
<p>The suexec sources+documentation say it clearly but I am going to repeat it one more time <strong>&#8220;Do not make any changes in the source code unless you really know what you are doing&#8221;</strong>. Just count the security holes introduced in <a href="http://jra1mw.cvs.cern.ch:8180/cgi-bin/jra1mw.cgi/org.glite.security.glexec/src/">glexec</a> for an example on what not to do.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.atreides.org.uk/blog/2007/06/05/glexec-or-why-changing-suexec-is-a-bad-idea/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wordpress upgrade</title>
		<link>http://www.atreides.org.uk/blog/2007/03/04/wordpress-upgrade/</link>
		<comments>http://www.atreides.org.uk/blog/2007/03/04/wordpress-upgrade/#comments</comments>
		<pubDate>Sun, 04 Mar 2007 01:01:58 +0000</pubDate>
		<dc:creator>Kostas Georgiou</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.atreides.org.uk/blog/2007/03/04/wordpress-upgrade/</guid>
		<description><![CDATA[Upgraded to 2.1.2 today since 2.1.1 was tainted. There is nothing in the logs to suggest an exploit attempt and with SELinux in enforcing mode it is unlikely that it an attempt would have been succesful but I really need to audit the machine to make sure that everything is OK.
]]></description>
			<content:encoded><![CDATA[<p>Upgraded to 2.1.2 today since 2.1.1 was tainted. There is nothing in the logs to suggest an exploit attempt and with SELinux in enforcing mode it is unlikely that it an attempt would have been succesful but I really need to audit the machine to make sure that everything is OK.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.atreides.org.uk/blog/2007/03/04/wordpress-upgrade/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
