After reading that a hacker purports to have hacked into several governments' institutions' websites, in the US and other countries.
He claims to have used a zero-day exploit for Plone CMS, and to have found that some use obsolete FreeBSD versions.
For example, he stated that he found out that the fbi.gov web server is running FreeBSD 6.2.
Now my specific interest is, how much is the actual risk running obsolete FreeBSD versions?
Are there any old FreeBSD versions whose base system is so vulnerable, that a server using them today is easily or even insta-hackable like older Windows versions? (assuming the packages aside the base system are up-to-date and safe)
For example, would a FreeBSD 6.2 server be as "open door" like a Windows XP?
And, are there any custom-maintained US state versions of FreeBSD for official use?
Maybe a 6.2 kept up to date with safety patches? Maybe such like Chinese Kylin Linux?
Please note:
Sadly my previous thread has been hijacked by some guys apparently having been hurt in their national pride.
Just because I quoted Russia Times as source, and pointed at the high personal prosecution risk for the hacker as a potential reason to be hesitant to release/leak actually meaningful stuff he got during his purported breach.
If anybody has the desire to discuss about topics like "Gods own country", I kindly ask to make a separate thread and not to damage this thread by totally OT-ing it. The problem I ask about affects many countries. Thank you.
He claims to have used a zero-day exploit for Plone CMS, and to have found that some use obsolete FreeBSD versions.
For example, he stated that he found out that the fbi.gov web server is running FreeBSD 6.2.
Now my specific interest is, how much is the actual risk running obsolete FreeBSD versions?
Are there any old FreeBSD versions whose base system is so vulnerable, that a server using them today is easily or even insta-hackable like older Windows versions? (assuming the packages aside the base system are up-to-date and safe)
For example, would a FreeBSD 6.2 server be as "open door" like a Windows XP?
And, are there any custom-maintained US state versions of FreeBSD for official use?
Maybe a 6.2 kept up to date with safety patches? Maybe such like Chinese Kylin Linux?
Please note:
Sadly my previous thread has been hijacked by some guys apparently having been hurt in their national pride.
Just because I quoted Russia Times as source, and pointed at the high personal prosecution risk for the hacker as a potential reason to be hesitant to release/leak actually meaningful stuff he got during his purported breach.
If anybody has the desire to discuss about topics like "Gods own country", I kindly ask to make a separate thread and not to damage this thread by totally OT-ing it. The problem I ask about affects many countries. Thank you.