From owner-freebsd-security@FreeBSD.ORG Thu Jun 20 00:09:22 2013 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) by hub.freebsd.org (Postfix) with ESMTP id CAD391EF for ; Thu, 20 Jun 2013 00:09:22 +0000 (UTC) (envelope-from kpaasial@gmail.com) Received: from mail-qa0-x232.google.com (mail-qa0-x232.google.com [IPv6:2607:f8b0:400d:c00::232]) by mx1.freebsd.org (Postfix) with ESMTP id 9190618FC for ; Thu, 20 Jun 2013 00:09:22 +0000 (UTC) Received: by mail-qa0-f50.google.com with SMTP id l18so778198qak.2 for ; Wed, 19 Jun 2013 17:09:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=/OMXa6dSxI+s0Kx5JhFpPdP2sLxfZK+CQEUW6N8pgI4=; b=dvZeE8FdiHlAfcdAvxpMY8v3G+Xw8cbHeuaFz0gccBeVkmJwRmH4gop0rv5eZ70JPt I7diG7o446A7pg2rX4ogG0I0UneYQIM78Nq3WuN3h+YD9uWtYmn1Sl0pENuVewfCVMvD bFxVL/Ie8CIw43pi6roCBV/lRxkilPkZUXXRg4CJttLfLX0QaAkUnaKAIRpaS2DOj4jF 7zWKr8gAkwIY8fZiJltjFzaXrP/4EK/RkPCOUPmuXEpuLMJpdZKOfUK9fNjShHgjHaPB jMLVpJiXLiCn+cia5dPx25gciuuF3uQZswK6Qo2RcpHr3eMWqvvkcXyN0GfcuXi8csd3 deTw== MIME-Version: 1.0 X-Received: by 10.229.170.20 with SMTP id b20mr2082416qcz.19.1371686962136; Wed, 19 Jun 2013 17:09:22 -0700 (PDT) Received: by 10.224.182.148 with HTTP; Wed, 19 Jun 2013 17:09:22 -0700 (PDT) In-Reply-To: References: Date: Thu, 20 Jun 2013 03:09:22 +0300 Message-ID: Subject: Re: Happy Birthday FreeBSD! Now you are 20 years old and your security is the same as 20 years ago... :) From: Kimmo Paasiala To: Michael Holmes Content-Type: text/plain; charset=UTF-8 Cc: freebsd-security X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 20 Jun 2013 00:09:22 -0000 On Thu, Jun 20, 2013 at 3:04 AM, Michael Holmes wrote: > On Thu, Jun 20, 2013 at 12:57 AM, Sergio Tam wrote: >> >> Hello Hunger >> >> I am new can you clarify a question? >> I have not installed nmap. Its FreBSD insecure? >> Can you do the same? >> can you exploit freebsd without nmap? >> >> Regards. > > It's *mmap*, a POSIX standard system call for mapping memory. All > systems running affected versions of the FreeBSD kernel are > vulnerable. And it's already been fixed, see: http://www.freebsd.org/security/advisories/FreeBSD-SA-13:06.mmap.asc It's quite laughable to use 9.1-RELEASE without any of the security patches that have been issued after its release to showcase the vulnerability, it just proves that the OP is a troll, a troll who knows how to use the information to create a succesfull attack but still a troll.