Ung. Blear. Whee. Huh?
Mar. 8th, 2003 07:04 am*RRRING*
"yegods, its 4am. it MUST be a wrong number."
*kerclick* "mrrphllo?"
"Dave, its dave! I need you on the meetingplace right now. There's a sendmail attack going on now, and we need to patch our servers up to fix the latest vulnerability. That patch you did to [main test environment]? I need tht to go to production right now."
"mrarem. huh. what? i didn't patch [main test environment]"
"You didnt'? I thought you did! Okay, sorry to wake you up, can you dial in to Meetingplace? [our conferencing system]"
"uhh. yeah. k. sure. uh. gimme a few."
*click*
*stagger* *thump* "SWEET JUMPIN JESUS, it _IS_ 4am."
Of course, somewhere around here while getting something warm on and going downstaris I had the evil nightmare thought that I might have dreamed that whole sequence, and when I dialled in, no one would be there.
Alas, such was not the case. 3 hours later, we're patched up, mostly, and I've got a sendmail cf headache.
The good news - during the call, the [my company] corporate security dude did the "Why are you guys still running sendmail? We've all switched to linux boxes and Postscript"
Hot damn 8)
"yegods, its 4am. it MUST be a wrong number."
*kerclick* "mrrphllo?"
"Dave, its dave! I need you on the meetingplace right now. There's a sendmail attack going on now, and we need to patch our servers up to fix the latest vulnerability. That patch you did to [main test environment]? I need tht to go to production right now."
"mrarem. huh. what? i didn't patch [main test environment]"
"You didnt'? I thought you did! Okay, sorry to wake you up, can you dial in to Meetingplace? [our conferencing system]"
"uhh. yeah. k. sure. uh. gimme a few."
*click*
*stagger* *thump* "SWEET JUMPIN JESUS, it _IS_ 4am."
Of course, somewhere around here while getting something warm on and going downstaris I had the evil nightmare thought that I might have dreamed that whole sequence, and when I dialled in, no one would be there.
Alas, such was not the case. 3 hours later, we're patched up, mostly, and I've got a sendmail cf headache.
The good news - during the call, the [my company] corporate security dude did the "Why are you guys still running sendmail? We've all switched to linux boxes and Postscript"
Hot damn 8)
no subject
Date: 2003-03-08 06:13 am (UTC)GAH. yah.
Yes, I meant postfix ;)
sendmail delenda est
Date: 2003-03-08 10:02 am (UTC)At least it sounds like you have implicit go-ahead to give your place a sendmailectomy, which can only be good.
My current top list of shoot-on-sight programs that people insist on running for no discernable reason:
5. php-nuke
4. qpopper
3. BIND
2. majordomo 1.x
1. sendmail
It just boggles my mind that this crap is still in production use in 2003. It seems no amount of pain will cause some organizations to learn...
no subject
Date: 2003-03-08 12:00 pm (UTC)I lucked out - currently Postfix at work (maybe Exim soon), and Exim at home.
Postfix yummy
Date: 2003-03-08 09:28 pm (UTC)Glad I got to sleep through this one (though I didn't get to sleep through an iManage upgrade that kept me at work till the wee hours last night.
Ah well.
Peace Out.
Huhwhat?
Date: 2003-03-09 02:59 pm (UTC)Oh
Oh I understand, kinda.
Huhwhat?
Date: 2003-03-09 03:01 pm (UTC)Oh
Oh I understand, kinda.
Ok sendmail attack.
At least when you get an emergency call you can stay in your pajamas and usually body fluids or machinery isn't involved.
I say usually