Security issue

Arno Lehmann al at its-lehmann.de
Sun Oct 26 12:48:10 CET 2008


Hi,

26.10.2008 04:56, Tim Starling wrote:
> I discovered a serious security problem with default nagios
> installations. I sent an email to nagios at nagios.org about it on
> October 22. I have not received a response.
 >
> Is there anyone here who wants to look at it?

Quite surely... if you think the issue is too serious for public 
disclosure, send mail to Ethan or Andreas, for example.

I'm also quite interested in this, but more because I think that 
Nagios itself is, by its intended use in a purely administrative 
environment without open access, not easily exploited by remote, 
unautorized users... the cgis with anonymous access and the plugins, 
of course, could easily hold security risks - but that's a different 
thing than the Nagios core. Anyway, I'm curious.

Regards,

Arno

> -- Tim Starling

-- 
Arno Lehmann
IT-Service Lehmann
Sandstr. 6, 49080 Osnabrück
www.its-lehmann.de

-------------------------------------------------------------------------
This SF.Net email is sponsored by the Moblin Your Move Developer's challenge
Build the coolest Linux based applications with Moblin SDK & win great prizes
Grand prize is a trip for two to an Open Source event anywhere in the world
http://moblin-contest.org/redirect.php?banner_id=100&url=/




More information about the Developers mailing list