Vulnerability Development mailing list archives

BEWARE : Possible compromission under BIND 8.2.2-P5 with Iquery probe


From: ml <ml () BLAS NET>
Date: Fri, 9 Mar 2001 20:21:20 +0100

Hi,

I have a bind. This BIND is a 8.2.2-P5 version which announces itself as being a V4 BIND.
This BIND runs under a non privileged account.

Regularly, attackers send a Iquery (as report by Snort signature) probe on it that crashes it.

It the first curiosity : V8 BIND is not sensitive to Iquery attack as far as I know !

Well, an automatic procedure detects this crash and relaunches it just after.


By now, sorry, but I was not able to dump the full trace (snort refuses t


Today, the scenario was different :
        BIND crashes as always just after the Iquery but
        somebody relaunches it just after the crash.
        AND this WITHOUT arguments -u and -g.
        That is to say, BIND was relaunched under the non-privileged account it         uses to run under :
        according to the log, it was unable to bind to port 53 !

Conclusion : I think it's possible to get a shell under BIND 8.2.2-P5 and with a Iquery probe.

Do someone be aware of such a vulnerability ?

db


Current thread: