URGENT SECURITY ALERT:
The following servers have been compromised and should be de-peered immediately:
i2pn2.org
novabbs.com
novabbs.org
novalink.us
rocksolidbbs.com
If you are currently peering with any of these servers, please
disconnect immediately to protect your systems and users.
If you are currently peering with any of these servers, please
disconnect immediately to protect your systems and users.
On 28.06.2025 00:00 Uhr NovaBBS / RockSolid Security Team wrote:
If you are currently peering with any of these servers, please
disconnect immediately to protect your systems and users.
Which security impact does have an infected NNTP server to a peer?
It can generate any message and offer it to the peer. Where is the real security problem?
On 28.06.2025 00:00 Uhr NovaBBS / RockSolid Security Team wrote:
If you are currently peering with any of these servers, please
disconnect immediately to protect your systems and users.
Which security impact does have an infected NNTP server to a peer?
It can generate any message and offer it to the peer. Where is the real >security problem?
--
kind regards
Marco
Send spam to 1751061600muell@stinkedores.dorfdsl.de
Marco Moock <mm@dorfdsl.de> writes:
On 28.06.2025 00:00 Uhr NovaBBS / RockSolid Security Team wrote:
If you are currently peering with any of these servers, please
disconnect immediately to protect your systems and users.
Which security impact does have an infected NNTP server to a peer?
It can generate any message and offer it to the peer. Where is the real
security problem?
If the adversary is aware of an (undisclosed) vulnerablity in the peer’s >NNTP implementation, they could exploit it.
In this case however the OP hasn’t given any detail, nor any explanation >why anyone should listen to them. If they’re the operator of novabbs etc >they could just shut it down themselve. If not then they need to explain
why any of novabbs’s peers should pay attention.
I don’t peer with novabbs but I wouldn’t disable a peer just because of >an unauthenticated and unsupported claim on Usenet.
--
https://www.greenend.org.uk/rjk/
I don't peer with novabbs but I wouldn't disable a peer just because of
an unauthenticated and unsupported claim on Usenet.
May I ask a perhaps related question given in the past two days, someone/something has been spamming the crap out of the text newsgroups. Could it be related?
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 546 |
Nodes: | 16 (2 / 14) |
Uptime: | 13:11:57 |
Calls: | 10,389 |
Calls today: | 4 |
Files: | 14,061 |
Messages: | 6,416,887 |
Posted today: | 1 |