Sun ships servers open to attack

Sun confirmed that it has shipped some servers in its SPARC Enterprise T5120 and T5220 lines with disk images that contain unsafe configurations that could allow remote attackers to hijack the machines.

In a security alert dated Feb. 12 but picked up by third-party security vendors only yesterday, Sun acknowledged that it sent servers out the door armed with what it called an "incorrect Solaris 10 image."

"Sun SPARC Enterprise T5120 and T5220 servers with datecode prior to BEL07480000 have been mistakenly shipped with factory settings in the pre-installed Solaris 10 OS image," Sun said in the advisory. "These settings may allow a local or remote user to be able to execute arbitrary commands with the privileges of the root (uid 0) user."

If an attacker gains root privileges on a server, he or she could modify or delete files, or introduce additional malware to pillage user account passwords or steal other confidential information.

As Symantec analyst Anthony Roe noted in a short advisory to customers of the company's DeepSight threat network, "very few details have been released for this issue." Sun's advisory only spelled out how users were to figure out whether their T5210 or T5220 servers are affected, and if so, what they should do next to lock down the machines.

Sun did not elaborate on how the improperly-configured servers slipped through final checks or quality control. The company did not return a call for comment.

The Enterprise T5120 and T5220 servers are priced starting at $14,000 and $15,000, respectively, and are powered by Sun's UltraSPARC T2 processors. Both lines come with Solaris 10 as the pre-installed operating system.

"If you are running [one of these servers], you need to review the vulnerability alert and apply the configuration changes that the vendor recommends," advised Roe.

Microsoft SharePoint taking business by storm
Microsoft's SharePoint Server is on a billion-dollar quest to potentially become the next must-have technology, offering companies tools for building everything

Researcher: Apple to weather recession better than rivals
Even though economic uncertainty is pulling U.S. computer buying plans into a nose dive, Apple's prospects remain brighter than some of its PC rivals, a researc

The company's triple-core Phenom X3 8000 series processors provide an option to
The past few years have seen some major changes in Sun hardware. The return of Andy Bechtolsheim has brought forth an impressive array of new server hardware, a

AMD introduces new Phenom chips
Advanced Micro Devices on Thursday announced new Phenom chips, including quad-core chips and its first triple-core processors for desktop PCs. The company's tri

Sun ships servers open to attack
Sunconfirmed that it has shipped some servers in its SPARC Enterprise T5120 and T5220 lines with disk images that contain unsafe configurations that could allow

Microsoft Eyes Development for Apple's iPhone
Microsoft is among the developers interested in Apple's software development kit (SDK) for the iPhone . The software giant has told news media that it is consid

Software turns smart phone into hotspot
NEW YORK - Here's a cool use for a phone that has both cellular broadband and Wi-Fi: Turn it into a mobile Wi-Fi hotspot so your friends can surf the Internet o

Who Patches Bugs Faster, Apple or Microsoft?
Apple 's teasing commercials that imply its software is safer than Microsoft 's may not quite match the facts, according to new research revealed at the Black H

Palm Adds Voice Commands For Smartphone Messaging, Browsing
Palm is adding new hands-free capabilities to its smartphones as a result of an agreement with Nuance Communications . Palm will use VSuite applications from Nu

Waste Management sues SAP over software failure
BOSTON/NEW YORK (Reuters) - Waste Management Inc (WMI.N) said it spent more than $100 million on a computer system that was supposed to help it save money, but