Distribution of the FreeBSD vulnerability database

Oliver Eikemeier eikemeier at fillmore-labs.com
Fri Feb 20 02:15:00 PST 2004


Dear hub maintainers,

I'm working on a project that notifies system adminstrators of vulnerabilities 
in installed packages, it is available as port security/portaudit. I need to 
distribute a database with a list of vulnerable ports that is daily updated. 
The database is ~ 2k in size, but I expect it to grow.

Currently I'm using public_distfiles of my freefall account and fetch from 
MASTER_SITE_LOCAL. 
This approach is suboptimal, because
- it takes long for all mirrors to get the update
- I have to refetch the whole file, since I can not simply check if an update 
 is available

I guess it would be better to distribute this file by http and have an 
additional url where I can just check the current version/md5/whatever, but I 
have absolutely no clue which load this will place on the servers.

Any advice from the experts?

Thanks
   Oliver

(sorry for the repost, I seems like my first didn't come through)


More information about the freebsd-hubs mailing list