[44025] in SIPB IPv6
Re: Re: [help.mit.edu #2970179] Exploitable NTP server used for an
daemon@ATHENA.MIT.EDU (Mitchell E Berger)
Thu Sep 11 14:54:34 2014
Date: Thu, 11 Sep 2014 14:54:22 -0400 (EDT)
From: Mitchell E Berger <mitchb@MIT.EDU>
To: Steven Valdez <dvorak42@MIT.EDU>
cc: Alex Chernyakhovsky <achernya@MIT.EDU>,
Bill Sommerfeld <sommerfeld@hamachi.org>, sipb-machine-room@MIT.EDU,
sipbv6@MIT.EDU
In-Reply-To: <CAC2=SfEt1a3FT3nAUQEHv8yoYo7wJ8_-xODyhKj_8F31QONoTA@mail.gmail.com>
Someone should do as Steven originally asked, for both of those machines.
sipb-machine-room is an effectively open list and shouldn't be in
places it implies privilege. sipb-staff is probably wrong, too,
as the servers in question are for a specific service that has a
list. Presumably they should both be either sipbv6 or a more
restricted maintainer list, whichever the maintainers think is
correct.
Mitch
On Thu, 11 Sep 2014, Steven Valdez wrote:
> You're looking at limekiller, not limekiller-w20-ether.
>
>
>
>
> On Thu, Sep 11, 2014 at 2:00 PM, Alex Chernyakhovsky <achernya@mit.edu> wrote:
>> They're set to sipb-staff, and ttsp says they've been sipb-staff for a
>> while. I have no idea why you were contacted.
>>
>> -Alex
>>
>>
>> On Thu, Sep 11, 2014 at 1:54 PM, Bill Sommerfeld <sommerfeld@hamachi.org> wrote:
>>> FYI, looks like it's been updated.
>>>
>>> -------- Forwarded Message --------
>>> Subject: Re: [help.mit.edu #2970179] Exploitable NTP server used for an
>>> attack: 18.187.1.231
>>> Date: Thu, 11 Sep 2014 13:48:49 -0400
>>> From: Andrew Munchbach via RT <security@mit.edu>
>>> Reply-To: security@mit.edu
>>> To: wesommer@mit.edu
>>>
>>>
>>> On Sep 11, 2014, at 12:05 PM, Bill Sommerfeld via RT <security@mit.edu> wrote:
>>>
>>>> I have not had anything to do with running limekiller for many years.
>>>> I'm not sure why I'm still listed as contact. I've forwarded your
>>>> request to sipb-machine-room@mit.edu and sipbv6@mit.edu
>>>
>>> Thank you. I've updated the Moira record to indicate that
>>> sipb-machine-room@mit.edu is the owner of this hostname.
>>>
>>> Regards,
>>> Andrew
>>>
>>>
>>>
>>>
>