?
Solved

is it allowed to run production server on linux kernel 2.6.34 ?

Posted on 2014-10-09
8
Medium Priority
?
283 Views
Last Modified: 2016-02-11
is it allowed to run production server for web on linux kernel 2.6.34 ?
I suspect this bug have been exploited on my server:
http://www.exploit-db.com/search/?action=search&filter_description=Linux+Kernel+2.6.34
there is an infected php script.
0
Comment
Question by:Nusrat Nuriyev
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
  • 2
8 Comments
 
LVL 7

Expert Comment

by:Stampel
ID: 40370927
Hello, yes it still can be safe to use linux kernel 2.6.34.
The exploit you reference need the attacker to have a local system account to perform this attack. (ssh access)
This is certainly not the case.
What make you think you are infected ?
0
 
LVL 62

Expert Comment

by:gheist
ID: 40371062
Kernel 2.6.34 (pure from kernel.org) is not very secure.
Do you have full version of it (uname -r)?
0
 
LVL 7

Expert Comment

by:Stampel
ID: 40371300
Whenever you use a proper firewall and your apache server is up to date
+ if you only let http port open, i doubt that this kernel would be a problem.
0
Back Up Your Microsoft Windows Server®

Back up all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

 
LVL 62

Expert Comment

by:gheist
ID: 40372298
Anybody can consume all system RAM via CVE-2012-6638, firewall or not.
Thats one I remember, plus 100 others lost in time.
If you are patching from whichever still supported source 2.6.34-(whatever number) should be very good for any purpose
0
 

Author Comment

by:Nusrat Nuriyev
ID: 40372337
Do you have full version of it (uname -r)?
2.6.34-12-desktop
uname -a
Linux opensuse 2.6.34-12-desktop #1 SMP PREEMPT 2010-06-29 02:39:08 +0200 x86_64 x86_64 x86_64 GNU/Linux  

How to patch that? maybe just update kernel? if I update it to the newest kernel could it cause any inconsistency in userspace programs behaviour? in FreeBSD I need to get updated both kernel + us + ports, what about suse?
0
 
LVL 62

Accepted Solution

by:
gheist earned 2000 total points
ID: 40372363
It is OpenSUSE 11.3 , EOL
You can update to 11.4 evergreen
Or jump to 13.1 which will be evergreen
You can upgrade OpenSUSE with 4GB full install DVD ONLY
(Why not unify your platforms on FreeBSD, or CentOS, or opensuse evergreen for instance)
0
 

Author Closing Comment

by:Nusrat Nuriyev
ID: 40391803
Well, every guy comes to the company with his own philosophy.
0
 
LVL 62

Expert Comment

by:gheist
ID: 40391866
On the pretext that it is unmaintainable at least get it to FreeBSD -RELENG releases, CentOS&Fedora to CentOS 5 or 6 or 7-latest and OpenSUSE to evergreen release thet follows installed one.
At least you & company will have good oversight what is in the server room.

If you run typical apache and tomcat on 20 servers, maybe make load-balance cluster of two linux servers and 10 applications... You gain stability, 99.9% availability and 8 systems off your hands...
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Are you sitting there reading this and wondering how to get started with Linux? It almost seems like picking the right Linux distribution is about like picking the right college or buying a new car if you read some of the article out there. Relax… l…
​Being a Managed Services Provider (MSP) has presented you  with challenges in the past— and by meeting those challenges you’ve reaped the rewards of success.  In 2014, challenges and rewards remain; but as the Internet and business environment evol…
How to Install VMware Tools in Red Hat Enterprise Linux 6.4 (RHEL 6.4) Step-by-Step Tutorial
In this video, Percona Solution Engineer Dimitri Vanoverbeke discusses why you want to use at least three nodes in a database cluster. To discuss how Percona Consulting can help with your design and architecture needs for your database and infras…
Suggested Courses

718 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question