The Inquirer-Home
Comments
ntp as a threat vector

you don't regard the NTP service running as root to be a threat? it's been the target of plenty of successful remote overflow exploits that can lead to the execution of arbitrary code. running it as root is ridiculous...

google ntp+exploit and you'll find plenty out there that might suggest you'd want this process running as something less dangerous.

posted by : amb, 01 November 2007 Complain about this comment
My test results are much more positive...

I get the impression that the guy who wrote the original firewall review article was intentionally looking for a way to make the firewall look bad. I'm pretty OS agnostic, and am convinced that you can have a decent on-host firewall for any OS, and that you can also misconfigure it to offer little protection. Following are my test results, performed using nmap on the same LAN as a Macbook running OS X 10.5. The Macbook had no sharing of any kind enabled, but was using many SMB shares and other network applications.

http://padilla.net/osx-10.5_firewall_test

posted by : Len, 31 October 2007 Complain about this comment
anti-mac fud?

curious how the report gets reported on by yahoo news via eweek: 

http://news.yahoo.com/s/zd/20071030/tc_zd/218378;_ylt=AmPNn9HdEdO83HSRvf8fkbFX.3QA

posted by : Chris, 31 October 2007 Complain about this comment
the beeb says

I quote "Upgrading to the latest version of Apple's operating system, might make a Mac less secure, say experts."

they say experts but only quote one source.


posted by : Andrew, 31 October 2007 Complain about this comment

Bloke says Leopard's firewall is pants

aboutus
Advertisement
Subscribe to INQ newsletters
Advertisement
INQ Poll

Authorities in several countries raided Megaupload recently, shut down all of its services, seized hundreds of servers and arrested several of its executives on criminal charges.

Do you think the move was justified?