Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

Computer programmers do it byte by byte.


devel / comp.protocols.time.ntp / how to privately log possible security issue in ntp 4.2.8p15

SubjectAuthor
* how to privately log possible security issue in ntp 4.2.8p15Edward McGuire
+- Re: how to privately log possible security issue in ntp 4.2.8p15Jim Pennino
`- Re: how to privately log possible security issue in ntp 4.2.8p15Dru Lavigne

1
how to privately log possible security issue in ntp 4.2.8p15

<32142b9e-395d-4950-abe3-07a3f38c1afan@googlegroups.com>

  copy mid

https://www.rocksolidbbs.com/devel/article-flat.php?id=431&group=comp.protocols.time.ntp#431

  copy link   Newsgroups: comp.protocols.time.ntp
X-Received: by 2002:a05:622a:306:b0:343:416d:76ae with SMTP id q6-20020a05622a030600b00343416d76aemr25720539qtw.337.1662062487776;
Thu, 01 Sep 2022 13:01:27 -0700 (PDT)
X-Received: by 2002:a05:6808:1508:b0:344:a3be:c582 with SMTP id
u8-20020a056808150800b00344a3bec582mr386711oiw.205.1662062487419; Thu, 01 Sep
2022 13:01:27 -0700 (PDT)
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!feed1.usenet.blueworldhosting.com!peer02.iad!feed-me.highwinds-media.com!news.highwinds-media.com!news-out.google.com!nntp.google.com!postnews.google.com!google-groups.googlegroups.com!not-for-mail
Newsgroups: comp.protocols.time.ntp
Date: Thu, 1 Sep 2022 13:01:27 -0700 (PDT)
Injection-Info: google-groups.googlegroups.com; posting-host=70.117.52.110; posting-account=99-szAoAAABeqjQXkwq9U3xS8fVveYhv
NNTP-Posting-Host: 70.117.52.110
User-Agent: G2/1.0
MIME-Version: 1.0
Message-ID: <32142b9e-395d-4950-abe3-07a3f38c1afan@googlegroups.com>
Subject: how to privately log possible security issue in ntp 4.2.8p15
From: metaed@gmail.com (Edward McGuire)
Injection-Date: Thu, 01 Sep 2022 20:01:27 +0000
Content-Type: text/plain; charset="UTF-8"
X-Received-Bytes: 1348
 by: Edward McGuire - Thu, 1 Sep 2022 20:01 UTC

Today, an email to security@ntp.org was returned 550 "user unknown".

My fallback would have been to post a cryptic bug report at bugs.ntp.org and request a private channel to give details. But on August 16 I requested bugs.ntp.org credentials and I've yet to receive a reply.

Other suggestions? Bueller?

Cheers!
Edward

Re: how to privately log possible security issue in ntp 4.2.8p15

<v2h7ui-5eu21.ln1@gonzo.specsol.net>

  copy mid

https://www.rocksolidbbs.com/devel/article-flat.php?id=432&group=comp.protocols.time.ntp#432

  copy link   Newsgroups: comp.protocols.time.ntp
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: jimp@gonzo.specsol.net (Jim Pennino)
Newsgroups: comp.protocols.time.ntp
Subject: Re: how to privately log possible security issue in ntp 4.2.8p15
Date: Thu, 1 Sep 2022 13:25:37 -0700
Organization: A noiseless patient Spider
Lines: 15
Message-ID: <v2h7ui-5eu21.ln1@gonzo.specsol.net>
References: <32142b9e-395d-4950-abe3-07a3f38c1afan@googlegroups.com>
Injection-Info: reader01.eternal-september.org; posting-host="47167a82dbc5a3a959bfc425b53dcf73";
logging-data="2402315"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18Zhdj/YlthbPAV9zHaEk5f"
User-Agent: tin/2.6.2-20220130 ("Convalmore") (Linux/5.15.0-46-lowlatency (x86_64))
Cancel-Lock: sha1:aBeiMMpx8zKVdARYAk12Iwh/cOg=
 by: Jim Pennino - Thu, 1 Sep 2022 20:25 UTC

Edward McGuire <metaed@gmail.com> wrote:
> Today, an email to security@ntp.org was returned 550 "user unknown".
>
> My fallback would have been to post a cryptic bug report at bugs.ntp.org and request a private channel to give details. But on August 16 I requested bugs.ntp.org credentials and I've yet to receive a reply.
>
> Other suggestions? Bueller?
>
> Cheers!
> Edward

Report it to CERT.

https://www.cisa.gov/report

Re: how to privately log possible security issue in ntp 4.2.8p15

<47a292a2-1867-41c5-a79d-5fed660e5fe2n@googlegroups.com>

  copy mid

https://www.rocksolidbbs.com/devel/article-flat.php?id=433&group=comp.protocols.time.ntp#433

  copy link   Newsgroups: comp.protocols.time.ntp
X-Received: by 2002:ac8:5a55:0:b0:343:72f9:7053 with SMTP id o21-20020ac85a55000000b0034372f97053mr29429186qta.518.1662155553680;
Fri, 02 Sep 2022 14:52:33 -0700 (PDT)
X-Received: by 2002:a9d:2dc2:0:b0:637:3176:cf00 with SMTP id
g60-20020a9d2dc2000000b006373176cf00mr14571845otb.296.1662155553350; Fri, 02
Sep 2022 14:52:33 -0700 (PDT)
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!feed1.usenet.blueworldhosting.com!peer03.iad!feed-me.highwinds-media.com!news.highwinds-media.com!news-out.google.com!nntp.google.com!postnews.google.com!google-groups.googlegroups.com!not-for-mail
Newsgroups: comp.protocols.time.ntp
Date: Fri, 2 Sep 2022 14:52:33 -0700 (PDT)
In-Reply-To: <32142b9e-395d-4950-abe3-07a3f38c1afan@googlegroups.com>
Injection-Info: google-groups.googlegroups.com; posting-host=137.27.39.226; posting-account=UdyZFQoAAABMgRW_5cZwQbPeLU5zWeA6
NNTP-Posting-Host: 137.27.39.226
References: <32142b9e-395d-4950-abe3-07a3f38c1afan@googlegroups.com>
User-Agent: G2/1.0
MIME-Version: 1.0
Message-ID: <47a292a2-1867-41c5-a79d-5fed660e5fe2n@googlegroups.com>
Subject: Re: how to privately log possible security issue in ntp 4.2.8p15
From: dlavigne@nwtime.org (Dru Lavigne)
Injection-Date: Fri, 02 Sep 2022 21:52:33 +0000
Content-Type: text/plain; charset="UTF-8"
X-Received-Bytes: 1722
 by: Dru Lavigne - Fri, 2 Sep 2022 21:52 UTC

On Thursday, September 1, 2022 at 4:01:28 PM UTC-4, Edward McGuire wrote:
> Today, an email to secu...@ntp.org was returned 550 "user unknown".
>
> My fallback would have been to post a cryptic bug report at bugs.ntp.org and request a private channel to give details. But on August 16 I requested bugs.ntp.org credentials and I've yet to receive a reply.
>
> Other suggestions? Bueller?
>
> Cheers!
> Edward

Thank you for the heads up, Edward. This has now been fixed and you can send the information to security@.

Cheers,

Dru Lavigne

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor