Bugtraq mailing list archives
Re: 11 years of inetd default insecurity?
From: Dan Stromberg <strombrg () dcs nac uci edu>
Date: 08 Sep 2003 12:44:55 -0700
On Sun, 2003-09-07 at 18:46, Thamer Al-Harbash wrote:
On Sat, 6 Sep 2003, 3APA3A wrote:Dear bugtraq () securityfocus com, Well, we all blame Microsoft in insecure default configuration... Isn't it time to clean outdated code in Unix?This has been a known problem for quite a while. In fact D. J. Bernstein already solved it with tcpserver: http://cr.yp.to/ucspi-tcp.html If you look at the bottom he points out pretty much what you pointed out.
So DJB's program basically has a large listen queue, and goes into queue-only mode after 40 concurrent connections? If that's the case, then there's still a DOS - just fill the listen queue with so much stuff that connections aren't serviced for a long time. -- Dan Stromberg DCS/NACS/UCI <strombrg () dcs nac uci edu>
Attachment:
signature.asc
Description: This is a digitally signed message part
Current thread:
- 11 years of inetd default insecurity? 3APA3A (Sep 06)
- Re: 11 years of inetd default insecurity? Thamer Al-Harbash (Sep 08)
- Re: 11 years of inetd default insecurity? Dan Stromberg (Sep 08)
- Re: 11 years of inetd default insecurity? Andres Kroonmaa (Sep 10)
- Re: 11 years of inetd default insecurity? Dan Stromberg (Sep 08)
- Re: 11 years of inetd default insecurity? Dagmar d'Surreal (Sep 08)
- Re: 11 years of inetd default insecurity? Mike Hoskins (Sep 09)
- Re: 11 years of inetd default insecurity? Mike Tancsa (Sep 08)
- Re: 11 years of inetd default insecurity? Jonathan A. Zdziarski (Sep 10)
- Re: 11 years of inetd default insecurity? Greg A. Woods (Sep 10)
- Re: 11 years of inetd default insecurity? Jonathan A. Zdziarski (Sep 10)
- Re: 11 years of inetd default insecurity? Dan Harkless (Sep 09)
- Re: 11 years of inetd default insecurity? Darren Pilgrim (Sep 09)
- <Possible follow-ups>
- Re: 11 years of inetd default insecurity? Paul Szabo (Sep 08)
- Re[2]: 11 years of inetd default insecurity? 3APA3A (Sep 08)
(Thread continues...)
- Re: 11 years of inetd default insecurity? Thamer Al-Harbash (Sep 08)
