![]() |
![]() OCAU News - Wiki - QuickLinks - Pix - Sponsors |
|
|||||||
| Notices |
|
Sign up for a free OCAU account and this ad will go away! Search our forums with Google: |
![]() |
|
|
Thread Tools |
|
|
#1 |
|
Member
Join Date: Jun 2001
Location: Brisbane
Posts: 19,937
|
http://www.theregister.co.uk/2012/04...rce_code_leak/
VMWare confirm source code was stolen and released, and it's likely more will be released. They're also downplaying the security risk to customers. This is the second large scale embarrassing security breach for an EMC company (see the RSA random seed breach last year).
__________________
Child's Play Charity |
|
|
|
| Join OCAU to remove this ad! |
|
|
#2 |
|
Member
Join Date: Mar 2007
Location: Rockhampton
Posts: 2,175
|
Just saw this on slashdot. To say this is a major fail is an understatement.
__________________
People reckon I'm too patronising (That means I treat them as if they're stupid). Over $9k in trades http://www.gentoo.org/ |
|
|
|
|
|
#3 |
|
Member
Join Date: Jan 2002
Location: Logan City, QLD
Posts: 2,756
|
My first thought is what version of the code has been taken.. Do you guys remember the Windows 2000 code release, it was only part of the full code base and not much, if anything(?) ever happened with it?
If it is an older version, I'm sure there are huge amounts of shared code between old releases and the current esx 5. What are we looking at here, backdoors to guest file systems, direct access to memory? I guess time will tell with this one..
__________________
"I don't stop eating when I'm full.. The meal isn't over when I'm full... The meal is over when I hate myself" - Louis CK. Blog |
|
|
|
|
|
#4 |
|
Member
Join Date: Jun 2001
Location: Brisbane
Posts: 19,937
|
If the source code is reviewed well enough internally, then there should be little to worry about. After all, Xen and KVM both have their source code out in the wild by design, and nobody is mass exploiting those.
Speaking for myself, the bigger worry is that this is the second successful targeted attack on an EMC company in a relatively short amount of time. My opinion of EMC and sub-companies was pretty low to begin with, and this isn't helping their reputation.
__________________
Child's Play Charity |
|
|
|
|
|
#5 |
|
Member
Join Date: Jan 2002
Location: Logan City, QLD
Posts: 2,756
|
I think I'd be concerned around their hosting/management tools, like vDirector/vCenter being exploited and rogues having ability to do funky things to your infrastructure.
__________________
"I don't stop eating when I'm full.. The meal isn't over when I'm full... The meal is over when I hate myself" - Louis CK. Blog |
|
|
|
|
|
#6 |
|
Member
Join Date: Jul 2002
Location: Tokyo, Japan
Posts: 7,936
|
ESX goes open source?
![]() These sorts of leaks are usually fun as people pick over the leak and highlight the crazy coding decisions and all the fantastic comments.
__________________
半ばは自己の幸せを、半ばは他人の幸せを http://www.leonjp.com - Rants and info about living in Japan http://forums.expatjapan.net - The Expat Japan Network! |
|
|
|
|
|
#7 | |
|
Member
Join Date: Oct 2005
Location: Coffs Harbour, NSW
Posts: 2,712
|
Quote:
That place had a company wide standard by the time i started though, this was just an old one i found :P
__________________
I has blog! |
|
|
|
|
|
|
#8 |
|
Member
Join Date: Jul 2002
Location: Tokyo, Japan
Posts: 7,936
|
I still remember the Windows 2000 source leak which was full of swearing and hilarious comments like "change this and I will kill you", and "this is $%&*ing ugly"
__________________
半ばは自己の幸せを、半ばは他人の幸せを http://www.leonjp.com - Rants and info about living in Japan http://forums.expatjapan.net - The Expat Japan Network! |
|
|
|
|
|
#9 | |
|
Member
Join Date: Jun 2001
Location: Brisbane
Posts: 19,937
|
Quote:
http://www.vidarholen.net/contents/wordcount/
__________________
Child's Play Charity |
|
|
|
|
![]() |
| Bookmarks |
|
Sign up for a free OCAU account and this ad will go away! |
| Thread Tools | |
|
|