home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!charon.amdahl.com!pacbell.com!decwrl!hal.com!olivea!pagesat!netsys!agate!dog.ee.lbl.gov!hellgate.utah.edu!fcom.cc.utah.edu!gateway.univel.com!ns.novell.com!ithaca.Eng.Sandy.Novell.COM!mmm
- From: Mark_Muhlestein@Novell.COM (Mark Muhlestein)
- Newsgroups: comp.sys.novell
- Subject: Re: Novell 3.11 security pitfalls?
- Keywords: security
- Message-ID: <C1H3u9.J2v@Novell.COM>
- Date: 26 Jan 93 18:10:56 GMT
- References: <1993Jan15.211306.15694@umr.edu> <C1FDLo.GDt@Novell.COM> <1993Jan25.233323.18095@umr.edu>
- Sender: usenet@Novell.COM (Usenet News)
- Organization: Novell, Inc.
- Lines: 50
- Nntp-Posting-Host: ithaca.eng.sandy.novell.com
-
-
- I appreciate the calm tone of this discussion, Brett. Let's try to
- get any remaining questions cleared up.
-
- Regarding the security features of future products, I think I'd best
- defer detailed discussions until the products are described through
- normal channels, but I do think you will be pleased with what we will
- be offering.
-
- On the issue of the timing of the KNOCK.EXE patch, you wrote:
-
- >As stated below,it appears to me that Novell did have a fix to the
- >KNOCK.EXE hole but did not inform people about the loophole or the fix
- >until the hole was published to the net.
- [ ... ]
- >It is my understanding that the patch was NOT released until well after
- >3.11 was out. (I was not aware of the patch being released until about
- >March or April 1992, and the server I administer was running 3.11 since
- >July 1992 or so). I therefore concluded that Novell knew about the bug
- >sometime before the release of 3.11 (June 1991 or before) but did not
- >acknowledge it and release a 3.10 patch until March or April 1992. If
- >the patch was released at the same time (or before) NetWare 3.11 was
- >released, then I am mistaken and I apologize.
-
- OK, I think we can straighten this out. The problem was found in
- December 1990, as nearly as I can determine. The 3.10 patch was
- devised within two days of the bug report, and was officially made
- available early in January, 1991. By the end of January 1991,
- thousands of downloads of the patch ("PASSFIX") had been done on
- NetWire. The 3.11 release was cut mid-February 1991, and incorporated
- the bug fix. The timing of these events was fairly close, so I can see
- why you might have been confused about this, although you are way off
- on the date of 3.10 patch.
-
- >>Again, I can't speak for Novell, but why would anyone do this?
-
- >Why? Because they can hope that no one will ever find it, and then the
- >users will never have to be told that it exists, which will make
- >NetWare look better. (A bad strategy, it would seem to me, as there
- >are plenty of hackers out there doing their best to find their way in.)
- > - Brett
-
- As I mentioned before, the problem was not discovered in-house, so
- there was never any question of avoiding telling the users. In any
- case I agree this would be a bad strategy, which is why I asked the
- question. I hope this information helps clear things up.
-
- Speaking for myself only,
-
- Mark_Muhlestein@novell.com
-