Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: rpc.ypupdated

Re: rpc.ypupdated

From: Martin Hamilton <martin_at_mrrl.lut.ac.uk>
Date: Sat, 16 Dec 1995 14:12:01 +0000

John Line writes:

| Er... what if the remote site's fingerd returns output which uses UCB mail's
| ~-escapes to run commands, or amend the headers and mail "interesting" files
| somewhere? [I don't think I'll stick my neck out in this forum and risk
| any suggestions about better ways to send the mail! :-)]

How about "safe_finger" ? (from the TCP wrapper distribution... ;-)

  * safe_finger - finger client wrapper that protects against nasty stuff
  * from finger servers. Use this program for automatic reverse finger
  * probes, not the raw finger command.
  *
  * Build with: cc -o safe_finger safe_finger.c
  *
  * The problem: some programs may react to stuff in the first column. Other
  * programs may get upset by thrash anywhere on a line. File systems may
  * fill up as the finger server keeps sending data. Text editors may bomb
  * out on extremely long lines. The finger server may take forever because
  * it is somehow wedged. The code below takes care of all this badness.
  *
  * Author: Wietse Venema, Eindhoven University of Technology, The Netherlands.

Cheerio,

Martin
Received on Dec 17 1995

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]