Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A basic firewall configuration could easily prevent this even if you are running the vulnerable version


Sure, but that is equivalent to removing the vulnerable service entirely and the features it was offering. Listening on port 631 for connections from any machine is the entire purpose of cups-browsed, it's the only way to do automatic printer discovery. If we think the port should be closed, then Ubuntu and the other distros should also remove this service, at least from the default installations.


Yep SOP is to block all ports that I haven’t personally white listed on all my systems.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: