From mboxrd@z Thu Jan 1 00:00:00 1970 From: "pelzflorian (Florian Pelz)" Subject: Re: Add murmur. Date: Sun, 12 Feb 2017 18:42:42 +0100 Message-ID: References: <20170209182030.ngn2dsdfbzsmymdj@wasp> <87efz7asit.fsf@gnu.org> <20170210213959.on6psfta6jcbjv2b@wasp> <877f4x1zle.fsf@kirby.i-did-not-set--mail-host-address--so-tickle-me> <20170210221536.iv5rktzx43b6xddv@wasp> <87wpcw3iks.fsf@gnu.org> <20170211143934.oo5loexp4pbpovpk@wasp> <87y3xbwmvi.fsf@gnu.org> <20170212135319.4exfnaq3oov3p6de@wasp> <20170212140234.xno3tzpzgvndirt3@wasp> <05c09e9a-eda3-d41e-b02c-b7d52ba1a5c5@crazy-compilers.com> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:39887) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ccyAi-0001nU-5f for guix-devel@gnu.org; Sun, 12 Feb 2017 12:42:49 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ccyAf-0003sG-2c for guix-devel@gnu.org; Sun, 12 Feb 2017 12:42:48 -0500 Received: from pelzflorian.de ([5.45.111.108]:54370 helo=mail.pelzflorian.de) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1ccyAe-0003s9-PS for guix-devel@gnu.org; Sun, 12 Feb 2017 12:42:45 -0500 Received: from [192.168.178.21] (ip5f58bf63.dynamic.kabel-deutschland.de [95.88.191.99]) by mail.pelzflorian.de (Postfix) with ESMTPSA id 90C8036000D for ; Sun, 12 Feb 2017 18:42:42 +0100 (CET) In-Reply-To: <05c09e9a-eda3-d41e-b02c-b7d52ba1a5c5@crazy-compilers.com> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: guix-devel@gnu.org On 02/12/2017 06:01 PM, Hartmut Goebel wrote: > Am 12.02.2017 um 15:37 schrieb David Craven: >> I think that it is a minor >> issue at best, since anything that isn't accessible over the network or running >> with any sort of privileges is not very useful. > > I strongly disagree! > > Every piece of software available on the system may the intruder. The > server may not be running so it can not be attacked in the first place. > But if an intruder gains (unprivileged) access to the system, he might > be able to start that server software. Then he might use it for > privilege escalation (if the server software is vulnerable), as a > back-channel or for attacking further systems. > An attacker with enough privileges to run Murmur has enough privileges to install Murmur anyway (perhaps but not necessarily by using Guix). Do I misunderstand? Regards, Florian