|
Re: ip restriction: msg#00316web.webmin.general
You missed my point, Vincent...If administering from someone elses machine, one doesn't have access to ssh--but a SSL capable browser is always available on any net connected PC. Besides OpenSSH has had more remote root exploits in the past year than Webmin has. Kinda blows a big gaping hole in that plan, doesn't it? Not to mention that because SSH is so much more commonly used than Webmin, it is scanned far more frequently by crackers. I recently had a client that had been running an exploitable Webmin for over three months, and the machine wasn't rooted. Another client installed a Red Hat 7.2 system with nothing but SSH running on a Friday. It was thoroughly rooted by the time I logged in on Monday. They had to reinstall and apply the errata before putting it back on the net (always recommended of course...I'm just making a point). I run both SSH and Webmin on my server, but claiming that SSH is more secure than Webmin is going to require something more than hand waving about security-orientedness. By being written in Perl, Webmin avoids several whole classes of security issue that SSH must deal with (and has proven to fail at on occasion). Panel Vincent wrote: Hi, -- Joe Cooper <joe@xxxxxxxxxxxxx> Web caching appliances and support. http://www.swelltech.com ------------------------------------------------------- Bringing you mounds of caffeinated joy >>> http://thinkgeek.com/sf <<< - Forwarded by the Webmin mailing list at webadmin-list@xxxxxxxxxxxxxxxxxxxxx To remove yourself from this list, go to http://lists.sourceforge.net/lists/listinfo/webadmin-list |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | AW: starting stopping miniserv.pl: 00316, Andreas Sumper |
|---|---|
| Next by Date: | Re: AW: starting stopping miniserv.pl: 00316, Joe Cooper |
| Previous by Thread: | RE: AW: starting stopping miniserv.pli: 00316, Ian Forsyth |
| Next by Thread: | RE: ip restriction: 00316, Les Bell |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |