On 28.06.2025 00:00 Uhr NovaBBS / RockSolid Security Team wrote:
If you are currently peering with any of these servers, please
disconnect immediately to protect your systems and users.
Which security impact does have an infected NNTP server to a peer?
It can generate any message and offer it to the peer. Where is the real >security problem?
--
kind regards
Marco
Send spam to 1751061600muell@stinkedores.dorfdsl.de
Marco Moock <mm@dorfdsl.de> writes:
On 28.06.2025 00:00 Uhr NovaBBS / RockSolid Security Team wrote:
If you are currently peering with any of these servers, please
disconnect immediately to protect your systems and users.
Which security impact does have an infected NNTP server to a peer?
It can generate any message and offer it to the peer. Where is the real
security problem?
If the adversary is aware of an (undisclosed) vulnerablity in the peerrCOs >NNTP implementation, they could exploit it.
In this case however the OP hasnrCOt given any detail, nor any explanation >why anyone should listen to them. If theyrCOre the operator of novabbs etc >they could just shut it down themselve. If not then they need to explain
why any of novabbsrCOs peers should pay attention.
I donrCOt peer with novabbs but I wouldnrCOt disable a peer just because of >an unauthenticated and unsupported claim on Usenet.
----
https://www.greenend.org.uk/rjk/
| Sysop: | Amessyroom |
|---|---|
| Location: | Fayetteville, NC |
| Users: | 65 |
| Nodes: | 6 (0 / 6) |
| Uptime: | 06:20:30 |
| Calls: | 862 |
| Files: | 1,311 |
| D/L today: |
921 files (14,318M bytes) |
| Messages: | 264,699 |